Re: baseline CPIM security
Dave Crocker <[email protected]>
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
At 02:01 PM 10/8/2002 -0400, John D. Ramsdell wrote: >want to do is send digitally signed messages and presence information >between IMPP-compliant systems. Is that too much to ask? For a single, homogeneous service, no it is not too much to ask. For an interconnected set of independent services, it is not too much to ask, but it is too much to require. Imposing a common end-to-end format, is an example of being too much. And it clearly violates that intent of CPIM as stated in the current documentation. For example, see the Introduction: > Service behavior is described abstractly in terms of operations > invoked between the consumer and provider of a service. Accordingly, > each IM service must specify how this behavior is mapped onto its own > protocol interactions. The choice of strategy is a local matter, > providing that there is a clear relation between the abstract > behaviors of the service (as specified in this memo) and how it is > faithfully realized by a particular IM service. d/ ---------- Dave Crocker <mailto:[email protected]> TribalWise, Inc. <http://www.tribalwise.com> tel +1.408.246.8253; fax +1.408.850.1850 [reminder: [email protected] for non-technical discussions, please]