Re: IPP Firmware Update Extensions v1.0 - recommendations for "Security and Privacy" and "Implementation Considerations" sections
wamwagner--- via ipp <[email protected]> Mon, 25 May 2026 20:49:55 +0000
| Newsgroups | gmane.ietf.ipp |
|---|---|
| Message-ID | <CH3PR22MB4443F3AAE5B7107FE189A4DAAF0A2@CH3PR22MB4443.namprd22.prod.outlook.com> |
--===============2842267538651732835==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_CH3PR22MB4443F3AAE5B7107FE189A4DAAF0A2CH3PR22MB4443namp_"
--_000_CH3PR22MB4443F3AAE5B7107FE189A4DAAF0A2CH3PR22MB4443namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Smith et al,
There are some things that perhaps cannot be specified, but might be appro=
priate under implementation considerations. These reflect my apprehension w=
ith regard to machines doing their own thing, and might not be considered n=
ecessary by others, but suggest the following:
1.
If the new firmware update is successful, there should be some clear indica=
tion that a device has firmware and some way a user can get some informatio=
n about the new firmware. [I have had successful computer updates that hav=
e, perhaps inadvertently, affected functionality. ]
2.
If a new firmware update fails because of transmission problems or errors, =
the device can clear itself and retry, but for only a limited number of tim=
es, after which there should be an indication to the user that new firmware=
update attempt failed because of download problems. The user may have the =
option of allowing an automatic reattempt or initiating a reattempt (perh=
aps after resolving communication issues.) In either case the device should=
resume normal operation with the previous un-updated firmware.
3.
If a new firmware update fails because of security issues, or questions abo=
ut the validity of the update package, the device should resume normal oper=
ation with the previous un-updated firmware and there should be clear indic=
ation of the failure to the user. It may be desirable to give the user th=
e ability to postpone update attempts until the issue is resolved and new f=
irmware update re-enabled.
4.
It a problem occurs in the attempt to execute the new firmware:
*
There must be a clear indication to the user both of the failure and the cu=
rrent state of the device.
*
If possible, the device should be returned to full operation with the previ=
ous firmware.
*
If (b) is not possible, the device should be left in a mode which would all=
ow analyses and perhaps operational recovery by remote maintenance efforts.
Thanks,
Bill Wagner
________________________________
From: ipp <[email protected]> on behalf of Kennedy, Smith (Wireless & IPP=
Standards) via ipp <[email protected]>
Sent: Thursday, May 21, 2026 4:32 PM
To: PWG IPP WG Reflector <[email protected]>
Cc: Kennedy, Smith (Wireless & IPP Standards) <[email protected]>
Subject: [IPP] IPP Firmware Update Extensions v1.0 - recommendations for "S=
ecurity and Privacy" and "Implementation Considerations" sections
Hi there,
For IPP Firmware Update Extensions v1.0, does anybody have any recommendati=
ons for items to list in the "Security and Privacy" and "Implementation Con=
siderations" sections? I'd like to get that before I produce my next draft,=
which will be ready for our IPP WG meeting June 18.
Cheers,
Smith
/**
Smith Kennedy
HP Inc.
*/
--_000_CH3PR22MB4443F3AAE5B7107FE189A4DAAF0A2CH3PR22MB4443namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
Smith et al,</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
There are some things that perhaps cannot be specified, but might be =
appropriate under implementation considerations. These reflect my apprehens=
ion with regard to machines doing their own thing, and might not be conside=
red necessary by others, but suggest
the following:</div>
<ol start=3D"1" data-editing-info=3D"{"applyListStyleFromLevel":f=
alse,"orderedStyleType":1}" style=3D"margin-top: 0px; margin-bott=
om: 0px; list-style-type: decimal;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); margin=
-top: 0px; margin-bottom: 0px;">
<div class=3D"elementToProof" role=3D"presentation">If the new firmware upd=
ate is successful, there should be some clear indication that a device=
has firmware and some way a user can get some information about the new fi=
rmware. [I have had successful computer
updates that have, perhaps inadvertently, affected functionality. ]</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); m=
argin-top: 0px; margin-bottom: 0px;">
<div class=3D"elementToProof" role=3D"presentation">If a new firmware updat=
e fails because of transmission problems or errors, the device can clear it=
self and retry, but for only a limited number of times, after which there s=
hould be an indication to the user that
new firmware update attempt failed because of download problems. The user =
may have the option of allowing an automatic reattempt or initi=
ating a reattempt (perhaps after resolving communication issues.) In either=
case the device should resume normal operation
with the previous un-updated firmware.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); m=
argin-top: 0px; margin-bottom: 0px;">
<div class=3D"elementToProof" role=3D"presentation">If a new firmware updat=
e fails because of security issues, or questions about the validity of the =
update package, the device should resume normal operation with the previous=
un-updated firmware and there should
be clear indication of the failure to the user. It may be desirable =
to give the user the ability to postpone update attempts until the is=
sue is resolved and new firmware update re-enabled.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); m=
argin-top: 0px; margin-bottom: 0px;">
<div class=3D"elementToProof" role=3D"presentation">It a problem occurs in =
the attempt to execute the new firmware:</div>
</li><ol start=3D"1" data-editing-info=3D"{"applyListStyleFromLevel&qu=
ot;:true}" style=3D"margin-top: 0px; margin-bottom: 0px; list-style-type: l=
ower-alpha;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); margin=
-top: 0px; margin-bottom: 0px;">
<div class=3D"elementToProof" role=3D"presentation">There must be a clear i=
ndication to the user both of the failure and the current state of the devi=
ce.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); m=
argin-top: 0px; margin-bottom: 0px;">
<div class=3D"elementToProof" role=3D"presentation">If possible, the device=
should be returned to full operation with the previous firmware.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); m=
argin-top: 0px; margin-bottom: 0px;">
<div class=3D"elementToProof" role=3D"presentation">If (b) is not possible,=
the device should be left in a mode which would allow analyses and perhaps=
operational recovery by remote maintenance efforts.</div>
</li></ol>
</ol>
<div class=3D"elementToProof" style=3D"margin-top: 0px; margin-bottom: 0px;=
font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helv=
etica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks,</div>
<div class=3D"elementToProof" style=3D"margin-top: 0px; margin-bottom: 0px;=
font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helv=
etica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Bill Wagner</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style=3D"display: inline-block; width: 98%;">
<div id=3D"divRplyFwdMsg">
<div style=3D"direction: ltr; font-family: Calibri, sans-serif; font-size: =
11pt; color: rgb(0, 0, 0);">
<b>From:</b> ipp <[email protected]> on behalf of Kennedy, Smi=
th (Wireless & IPP Standards) via ipp <[email protected]><br>
<b>Sent:</b> Thursday, May 21, 2026 4:32 PM<br>
<b>To:</b> PWG IPP WG Reflector <[email protected]><br>
<b>Cc:</b> Kennedy, Smith (Wireless & IPP Standards) <smith.ken=
[email protected]><br>
<b>Subject:</b> [IPP] IPP Firmware Update Extensions v1.0 - recommenda=
tions for "Security and Privacy" and "Implementation Conside=
rations" sections</div>
<div style=3D"direction: ltr;"> </div>
</div>
<div>Hi there,</div>
<div><br>
</div>
<div>For IPP Firmware Update Extensions v1.0, does anybody have any recomme=
ndations for items to list in the "Security and Privacy" and &quo=
t;Implementation Considerations" sections? I'd like to get that before=
I produce my next draft, which will be ready for our
IPP WG meeting June 18.</div>
<div><br>
</div>
<div>Cheers, </div>
<div><br>
</div>
<div>Smith<br>
<br>
/**<br>
Smith Kennedy<br>
HP Inc.<br>
*/</div>
<div><br>
</div>
</body>
</html>
--_000_CH3PR22MB4443F3AAE5B7107FE189A4DAAF0A2CH3PR22MB4443namp_--
--===============2842267538651732835==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
ipp mailing list
[email protected]
https://www.pwg.org/mailman/listinfo/ipp
--===============2842267538651732835==--