[saag] Re: draft-paulwh-crypto-components-01
Eric Rescorla <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CABcZeBPNkXOcDyCaA+yF9n4Dpo=ZawJ-RiYoqqeU5pJ5ucY6KQ@mail.gmail.com> |
On Tue, Feb 18, 2025 at 6:49 AM Paul Wouters <[email protected]> wrote: > > On Mon, Feb 17, 2025 at 6:33 PM Eric Rescorla <[email protected]> wrote: > >> >> I think this is a good start. One thing I would like to see is some >> discussion of the reasons why many registries have gone to permissive >> policies, namely concerns about code point squatting, the inadequacy >> of controlling the registry as a mechanism of influencing implementor >> behavior, and the cost to the WG of evaluating new mechanisms. >> > > Can you explain "concerns about code point squatting" and how being more > relaxed prevents that? > Say you have a fairly large code point space (e.g., 16 bits) with tight restrictions (e.g., Standards Action). If you are a company that wants to deploy a new mechanism privately but at scale on the Internet and needs a code point, but doesn't feel like going through the process of getting your mechanism standardized, it's tempting to pick a high unused number and just deploy with it. But once you've deployed this makes the code point more or less unusable for others, so IETF needs to somehow avoid it. If we make it easy to register new code points (e.g., FCFS or Specification Required) then we (hopefully) encourage people to at least register so that then we have a clear picture of which code points are free and which are in use. -Ekr > >> If we don't define new policies, how could we prohibit exceptions? >> > > We will look at clarifying that. > > Paul > > _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]