[saag] Re: [EXT] Interests on Initiating the standardiza tion work related to "Zero Trust"?

Paul Hoffman <[email protected]> Tue, 23 Dec 2025 08:27:20 -0800
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
On 23 Dec 2025, at 6:37, Richard Barnes wrote:

> Clearing up marketing-tainted terminology is not a good use of the IETF.
> At this point "Zero Trust" is largely unrecoverable.

A strong +1 to what Richard says. In fact, if you look at the early drafts and slides from the proponents, they don't mean "zero", they mean "very little": this is a giant red flag for IETF work.

> And in any case, all Zero Trust has ever meant AFAICT is for corporate
> networks to finally embrace things that have been standard in IETF
> protocols for a long time: Authorization and access control, ubiquitous
> encryption, etc.

Looking at the materials, "finally embrace" is too strong here: "embrace more strongly" is the only achievable goal.

> If there's some protocol work to do here, let's do it.  But from the
> documents posted up-thread, this seems like territory that is already
> well-covered by existing standards.

A different take would be: if there are industry trade associations or other SDOs that want to take on this work, and the result of their work is "but we need extensions to IETF standards to make this work", we should cheerfully work with them on that. But we don't have to help them with the wandering in the weeds.

--Paul Hoffman

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]