Re: Gen-art last call review : draft-ietf-geopriv-deref-protocol-03

Robert Sparks <[email protected]> Thu, 3 Nov 2011 15:54:28 -0500
Newsgroups gmane.ietf.gen-art,gmane.ietf.geopriv
Message-ID <[email protected]>
I'll add that as an RFC editor note and more this into IESG evaluation.

Thanks!

RjS

On Nov 2, 2011, at 5:18 PM, Thomson, Martin wrote:

> On 2011-11-03 at 08:15:01, Robert Sparks wrote:
>> (Including the geopriv list on this reply).
>> 
>> Martin - there's one change you made that I think you need to adjust.
>> In response to Elwyn's suggestion about Appendix A, Req 9 below, 
>> you've added some 2119 text to that appendix which isn't right. Is 
>> there a place you can say what you want to say in the body of the document?
> 
> Yeah, and that was stupid of me.
> 
> The security considerations already contains a statement to this effect:
> 
>   Location URIs MUST only be disclosed to authorized Location
>   Recipients.  
> 
> As for the 2119 language, a reference to the above statement should do:
> 
> OLD:
>   In order to comply with these rules, a Location Recipient	
>   MUST NOT redistribute a location URI without express	
>   permission. Depending on the access control model, the	
>   location URI might be secret (see Section 3.3 of	
>   [RFC5808]).
> NEW:
>   For location URIs that are use possession as a component of
>   authorization, the protecting the secrecy of the URI is
>   necessary in order to comply with this requirement (see
>   Section 6).
> 
> --Martin