Re: des-die-die-die and RC4

Simon Josefsson <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
Tom Yu <[email protected]> writes:

> Simon Josefsson <[email protected]> writes:
>
>> I noticed another change in -03 though.  Instead of saying that
>> implementions and deployments SHOULD NOT "implement" the deprecated
>> ciphers the document now says they SHOULD NOT "provide" them.  What is
>> the difference?  It strikes me as "provide" is more ambigious than
>> "implement".  For example, is it OK to "provide" these ciphers as a
>> non-default and still be compliant with the SHOULD NOT?  The document
>> didn't use to allow that.  I don't recall any discussions around this
>> change.  Since we use SHOULD NOT instead of MUST NOT I believe we could
>> use the harder language of "implement" instead of "provide".
>> Implementations that wants to provide optional backwards compatibility
>> can do so as an exception to the SHOULD NOT rule and still be compliant
>> with the document.
>
> I could reword it to "implementers SHOULD NOT implement, and deployers
> SHOULD NOT deploy..." if people would prefer.

That would work for me, as would the simpler 'Kerberos implementations
and deployments SHOULD not implement/deploy ...' if you are unhappy with
the -02 variant.

> We can split hairs about whether to "provide" means to implement at
> all, versus to enable by default

I support the document being as clear as possible what is intended
rather than leaving such interpretations up to readers.

Saying that "implementations SHOULD NOT implement" makes it easy to test
whether a particular implementation has code for a particular algorithm
or not.  Saying "implementaters SHOULD NOT provide" appears weaker to
me.  I read "provide" to permit implementing but disabling by default.

I thought we had consensus on the stronger wording to "SHOULD NOT
implement" which also seems preferrable, thus this change surprised me.

/Simon
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.