Re: Gen-art last call review : draft-ietf-geopriv-deref-protocol-03
Robert Sparks <[email protected]> Thu, 3 Nov 2011 15:54:28 -0500
| Newsgroups | gmane.ietf.gen-art,gmane.ietf.geopriv |
|---|---|
| Message-ID | <[email protected]> |
I'll add that as an RFC editor note and more this into IESG evaluation. Thanks! RjS On Nov 2, 2011, at 5:18 PM, Thomson, Martin wrote: > On 2011-11-03 at 08:15:01, Robert Sparks wrote: >> (Including the geopriv list on this reply). >> >> Martin - there's one change you made that I think you need to adjust. >> In response to Elwyn's suggestion about Appendix A, Req 9 below, >> you've added some 2119 text to that appendix which isn't right. Is >> there a place you can say what you want to say in the body of the document? > > Yeah, and that was stupid of me. > > The security considerations already contains a statement to this effect: > > Location URIs MUST only be disclosed to authorized Location > Recipients. > > As for the 2119 language, a reference to the above statement should do: > > OLD: > In order to comply with these rules, a Location Recipient > MUST NOT redistribute a location URI without express > permission. Depending on the access control model, the > location URI might be secret (see Section 3.3 of > [RFC5808]). > NEW: > For location URIs that are use possession as a component of > authorization, the protecting the secrecy of the URI is > necessary in order to comply with this requirement (see > Section 6). > > --Martin