RE: baseline CPIM security

Dave Crocker <[email protected]>
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
At 07:59 PM 10/3/2002 -0400, Peterson, Jon wrote:

>While no specific understanding of CPIM's requirements was ever formalized
>in our charter, to date I have worked under the assumption that the
>requirements of RFC2779 apply to CPIM

How can a gateway between heterogeneous systems impose any "end to end" 
requirements.  The job of a gateway is to translate between heterogeneities.


>- in the sense that two CPIM-compliant
>protocols communicating with one another through a CPIM gateway must meet
>the requirements of RFC2779.

At which point, CPIM is no longer a gateway spec.  It is a spec for a 
single, entire, participating system.  It is exactly the inability to 
develop an 'entire system' that motivated the focus on a gateway system 
that produced the original CPIM specification.


>Personally, I believe this is a desirable requirement

That must be the mistake I am making.  I thought the dominant goal was 
practicality, not just desirability.  That is, I thought that the "desire" 
was to provide a specification that would permit interfacing to systems, 
rather than require replacing them.


>We should probably have consensus on the requirements before delving 
>further into the mechanism.

Yes that would be nice.  Again, my mistake probably is that I thought that 
we had consensus some years ago that CPIM was to be a gateway 
spec.  Instead it appears that it has returned to the pre-CPIM, original 
goal of producing the One True IM protocol.

d/


----------
Dave Crocker <mailto:[email protected]>
TribalWise, Inc. <http://www.tribalwise.com>
tel +1.408.246.8253; fax +1.408.850.1850




  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.