[saag] Re: draft update on discussion on crypto practices at IETF
Christian Huitema <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
On 1/22/2025 10:37 AM, Salz, Rich wrote: >> I think finding consensus in the Security Area on this is extremely important, given that we already are using them in our registries. > Yes, we are already using I-D's in some SEC registries. Establishing IETF consensus is more important. We know what SEC does and most people are okay with that so I agree this section does not belong. > > You will find it easier to make progress if this was just a survey of what's being done, rather than making recommendations. I think the potential value is not just "a survey of what people do", but also, as much as possible, a survey of why they do it the way they do. For example, why some WG opted for a rather loose registration policy after having experimented with a stricter one. I was also a bit surprised by the recommendation on OIDs. OIDs allow pretty much everybody to get a codepoint, without coordinating with the IETF. Other WG outside the security area do something similar using domain names or URL -- that's pretty common for example in XML based application protocols. Obviously, Paul and Paul believe that's a bad idea. Rather than merely recommending to just stop the practice, it would be nice to develop the observed downsides. And maybe potential remedies, such as separating code point allocation, which could well be loose, versus code point registration, which could be conditioned to the presence of a specification, and code point recommendation, which could be conditioned to some kind of consensus. -- Christian Huitema _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]