Re: Document Status & WG Actions
John White <[email protected]> Wed, 25 Sep 2002 08:51:53 -0400
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <[email protected]> |
We had a discussion of this in late June after Glenn pointed out the problem. We were loath to go back and revise the questionable requirement, so the current IDXP draft refers several times to "non-repudiation of session origin." If we just change those instances to "authentication of session origin" it would seem to meet the revised requirement proposed by Mike. -John White- On Tuesday, September 24, 2002, at 07:31 PM, Mike Erlinger wrote: > Everyone > > The IESG is in the midst of reviewing our documents. Stuart and I > have been contacted by our ADs (Jeff and Steve) about some nits and > one significant issue in the Requirements ID and the IDXP ID. > > Significant Issue: > > The significant issue is "non-repudiation". Reading RFC 2828 and > paraphrasing some of Jeff and Steve's comments, non-repudiation is > not generally a property of a transport protocol. It is typically > a property of an object, i.e., you digitally sign an object. To > provide non-repudiation, you need to keep not only the original > object, but also the digital signatures, etc. Thus, non-repudiation > is not something that we should require of the transport protocol. > > Reading the Requirements ID, the ADs have wondered if what we were > after was per-source authentication. It was a long time ago and > I am not remembering the discussions. > > --------------------------------------------------------------------- > I propose the following changes: > > 1. Drop non-repudiation from the Requirements Doc and > replaced it with per-source authentication (5.6). > > 2. Ask the IDXP author to drop non-repudiation from that > document and produce a new draft. > > -------------------------------------------------------------------- > > Requirements ID Nits: > > 1. Many sub-sections did not have titles in the ToC. I have added > titles and believe this is now fixed. > > 2. The Security Considerations section did not show up as a numbered > section, and did not specifically say that Section 5 lists the security > requirements for the eventual protocols. Now fixed > > > Working Group Actions: > > In order to make appropriate dead lines for the IESG, the new drafts > need to be completed by Friday. The Nits should not be of major > concern (unless I messed up something). But if you have concern about > dropping "non-repudiation" and adding per-source authentication, > you need to quickly raise the issue on the > mailing list. Silence on the mailing list will indicate agreement with > the changes. > > > > There will be a new version of the Requirements ID with the above > changes posted this evening. > > > mike > > -- > Mike Erlinger, Professor and Chair Computer Science > www: http://www.cs.hmc.edu/~mike > email: [email protected] > smail: Computer Science Dept., Harvey Mudd College, > 301 E. 12th Street, Claremont, CA, 91711 > 909-621-8912, FAX: 909-607-8364 >