Re: des-die-die-die -- "implement" vs "provide", and default behavior

Jeffrey Hutzelman <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
On Mon, 2012-02-20 at 16:20 -0500, Tom Yu wrote:
> Simon (and perhaps others) interpret "provide" so that an implementor
> can implement functionality while not providing it, by disabling the
> functionality by default.  I interpret "provide" in this context to
> mean making available in any way, even if the implementor disables it
> by default.  I've replaced "implementations and deployments SHOULD NOT
> provide..." with "implementations and deployments SHOULD NOT implement
> or deploy..." in my copy to avoid any further confusion with "provide".
> 
> I believe that we have consensus that the "SHOULD NOT" applies to
> making the weak crypto available at all in an implementation, even if
> the default configuration disables the weak crypto.

Yes; I believe we have a preexisting consensus on the language which was
in -02.  This certainly was not an issue that was raised during the
first WGLC.


>   I think that at
> this time, practical implementations that need to provide backward
> compatibility will probably implement the weak crypto and disable it
> by default.
> 
> I think it would help the document move more quickly if we continue to
> say nothing about default behavior (even though it might be
> interesting or helpful to do so), because I'm not sure we can quickly
> reach consensus on whether an implementation "SHOULD NOT" or "MUST
> NOT" enable weak crypto by default if implements it.
> 
> Simon and Chairs, does the above seem reasonable?

Sam is on vacation at the moment.

Reverting to the language in -02, which used "SHOULD NOT implement", is
reasonable.  As Sam already mentioned, doing anything else requires an
explicit consensus for the change.  That includes...

- Adding deployment advice
- Adding advice about default behavior

Anyone want to speak up on these points?

-- Jeff

_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.