[saag] Re: draft-paulwh-crypto-components-01

"Salz, Rich" <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
Let's first agree on what "Good" looks like.  I think what Paul wrote is exactly what good looks like, because RECOMMENDED indicates a high level of vetting.  So.  Why am I wrong (it happens all the time, but why THIS time? ;-)

We have a very bad history of agreeing about what GOOD looks like for cryptographic algorithms. The CFRG tore itself apart when picking curves and EC signature formats, and years later some people will still not come back. The recently-formed SSHM working group nearly died before it got started because of similar conflicts. There are notable groups within the IETF who believe that the IETF (pick one) {should just follow NIST | should ignore NIST | is already in thrall to NIST}. Those groups are highly unlikely to agree.

I still believe this document is flawed because it mixes in a survey of practices, which is highly useful, and recommendations. That last part is problematic, particularly in terms of process because one of the co-authors is a Security AD, who is about to start the last year of his second, and presumably final, term.

As a nit, and as Simon has pointed out in his messages, there is no rationale offered for why to centralize practice, as opposed to leaving things as they currently are.

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.