[saag] Re: draft update on discussion on crypto practices at IETF

Eric Rescorla <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CABcZeBMKxqc4wvJVj8Qwrky9_c5uGx-vfb4WE2rcYhuYJs1OPA@mail.gmail.com>
On Thu, Jan 23, 2025 at 3:30 AM Stephen Farrell <[email protected]>
wrote:

>
> Hiya,
>
> On 23/01/2025 01:50, Eric Rescorla wrote:
> > On Wed, Jan 22, 2025 at 1:39 PM Stephen Farrell <
> [email protected]>
> > wrote:
> >
> >>
> >> Hiya,
> >>
> >> On 22/01/2025 19:12, Paul Hoffman wrote:
> >>>> We know what SEC does
> >>   >
> >>> I disagree with that on a factual basis. In the last year, I have
> >>> had at least three people express surprise that some Security Area
> >>> registries allow Internet Drafts as references.
> >>
> >> There's a related (almost inverse) controversy as well: some
> >> people assert that having a code-point associated with an I-D
> >> means that no RFC ought later be produced.
> >>
> >
> > Hmm... I don't think I've seen anybody assert that. Can you provide
> > a reference?
>
> It's not the only one but this one [1] will do.
>
> And yes, you said "an I-D is sufficient" and not "no
> RFC should be produced" and there's more subtleties
> too (ntru not being a nist-winner) but IIRC at that
> time you and others were arguing that the relevant I-D
> ought not be AD sponsored, which to me, amounted to
> saying no RFC ought be produced because the code-point
> was allocated based on the I-D.
>

Thanks for this example, as I think it shows that you've badly
mischaracterized
my position.

To state my position clearly:
The IETF is a technical standards organization and that means its resources
ought
to be largely devoted to developing technical specifications. That doesn't
mean
that we should never publish technical specifications developed elsewhere
that aren't under IETF change control, but we should largely do so when they
serve some IETF purpose. If RFC publication is not needed for code point
registration, then code point registration is in itself (IMO), generally
not a good reason.
There might, however, be other reasons.

One reason would be that we intend to standardize the specification but that
a code point was assigned in advance for some reason, for instance, with
an early assignment, or as in this case, when it was an individual
submission.

-Ekr



> Cheers,
> S.
>
> [1]
> https://mailarchive.ietf.org/arch/msg/saag/UkdcMBXtfhjO9zhdFFYeILSHHvM/
>
> >
> > -Ekr
> >
>
>

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.