RE: baseline CPIM security

Dave Crocker <[email protected]>
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
At 08:57 PM 10/3/2002 -0400, Peterson, Jon wrote:
>There are various degrees of interoperability that we might encourage
>through CPIM - but clearly there would be no need for MSGFMT or the DateTime
>RFC or PIDF if our intention wasn't that CPIM-compliant protocols would use
>these common objects.

a gateway specification needs a canonical form.  indeed, gateways that are 
designed for extensibility usually implement a canonical internal form and 
then map to and from it.

that was the intent behind the original effort on CPIM, as I understood it 
at the time.  the larger and longer-term likelihood of propagating change 
out to the participating systems was thought to be just 
that.  likelihood.  not requirement.

anything that is imposed as a change to a participating system -- such as a 
requirement that can only be satisfied by the direct cooperation of the 
originator or the recipient system -- ensures that CPIM can have 
essentially no utility as a gateway mechanism and must, instead, be 
strictly competitive with existing IM services.

Competition was explicitly not the goal.  Interconnect was the goal.  I 
guess that has changed.


>Gateways have no use for something like PIDF

see the above observation about the role of canonical form in a gateway.


>  - PIDF is
>designed to be tunneled through gateways. Now we're merely discussing the
>addition of security properties to these tunneled objects that we've already

"merely discussing the addition" is what is called a slippery slope, and 
this working group has slipped down it quite a distance.

take a look at the timeline of this working group.  there is no "merely" 
for anything that is added.

d/

----------
Dave Crocker <mailto:[email protected]>
TribalWise, Inc. <http://www.tribalwise.com>
tel +1.408.246.8253; fax +1.408.850.1850




  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.