RE: baseline CPIM security
"Peterson, Jon" <[email protected]>
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
I don't think I agree with your interpretation of the direction of the IMPP WG. There are various degrees of interoperability that we might encourage through CPIM - but clearly there would be no need for MSGFMT or the DateTime RFC or PIDF if our intention wasn't that CPIM-compliant protocols would use these common objects. Gateways have no use for something like PIDF - PIDF is designed to be tunneled through gateways. Now we're merely discussing the addition of security properties to these tunneled objects that we've already defined and agreed on, and suddenly we're running into problems? You could argue that our whole approach has been wrong-headed - but it is what we've been doing here for the last year and change, and it does provide much more credible interoperability than alternatives that do not rely on tunneled objects, especially with regard to security properties. The introduction to draft-ietf-impp-cpim speaks to "the philosophy that there must be no loss of information between IM systems". I think that states a goal of strong interoperability. Jon Peterson NeuStar, Inc. > -----Original Message----- > From: Dave Crocker [mailto:[email protected]] > Sent: Thursday, October 03, 2002 5:12 PM > To: Peterson, Jon > Cc: 'Beckmann Mark ICM MP P PS 4 SAL 2'; '[email protected]' > Subject: RE: baseline CPIM security > [snip] > > >- in the sense that two CPIM-compliant > >protocols communicating with one another through a CPIM gateway must meet > >the requirements of RFC2779. > > At which point, CPIM is no longer a gateway spec. It is a spec for a > single, entire, participating system. It is exactly the inability to > develop an 'entire system' that motivated the focus on a gateway system > that produced the original CPIM specification. > [reminder: [email protected] for non-technical discussions, please]