[saag] Re: draft-paulwh-crypto-components-01
John Mattsson <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <GVXPR07MB967843F8655C4E25CAF5597489F62@GVXPR07MB9678.eurprd07.prod.outlook.com> |
Does any IANA registry have such a column? All registries I can think is mostly about implementation requirements, which is very different from use. Recommendations for interoperability is very different from security recommendations. Stating that an implementation requirement implies recommendation to use is not true and dangerous. Please remove this. As Simon says, JOSE relies on Expert Review, COSE relies on IETF Review, and IPsec does not have a column and relies on separate RFCs for implementation requirements. John From: Simon Josefsson <[email protected]> Date: Thursday, 6 February 2025 at 09:12 To: Paul Hoffman <[email protected]> Cc: [email protected] <[email protected]> Subject: [saag] Re: draft-paulwh-crypto-components-01 The document says: 3.4. Recommendations in IANA Registries Some IANA registries for specific cryptographic protocols have a column with a name such as "status" or "recommended" that indicates whether the the IETF recommends that a cryptographic component be used in that protocol. The definition of the column should ... Decisions on setting the values in these columns to anything other than "MAY" require a standards track RFC. That is, Independent Stream and IRTF RFCs cannot set or change the values in such a table in an IANA registry. I disagree with the last paragraph, and believe this is not consistent with how IANA registries has worked, works today, or should work. IANA registries are usually set up by some RFC which describes which rules are to be used. For example, IETF Review, Expert Review, etc. The paragraph above attempts to overrule all such carefully written instructions and registration rules. I think doing so is a bad idea, and suggest that you remove this paragraph from this document. Removing the paragraph leave the registration policy to be decided by whatever document set up the IANA registry, typically some Working Group via some RFC. /Simon _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]