[saag] Re: Review of draft-paulwh-crypto-components-03
Watson Ladd <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CACsn0ckn6nhCiMsx1E2ohc-wMGbqX9L5=GhJO-d76EanXfu8BQ@mail.gmail.com> |
On Fri, Feb 28, 2025 at 7:58 AM Paul Wouters <[email protected]> wrote: > > > On Thu, Feb 27, 2025 at 8:42 PM Watson Ladd <[email protected]> wrote: >> >> Dear SAAG, >> >> I am very confused by the draft vs. the rest of the conversations >> we've had about it, and crypto in general. I think the draft needs to >> take a sharper line to get the message across clearly that you don't >> need an RFC to use a new primitive in an IETF protocol, just a >> registration and should explain the reasons why a document might still >> be useful/what working groups should consider doing themselves. > > > I would be happy to see this, as I think it is a key point of the document. Do you believe > adding a sentence into the Abstract or Introduction could address your point? How about in the Abstract "This explains why RFCs are not required to use a new component an in an IETF protocol". I think we'd also need a paragraph/sentence somewhere at the bottom of section 2 after we're done explaining the identifiers recapitulating that. As for why we would still write RFCs describing cryptography I can think of a few reasons where the other documents might not be widely accessible, there might be some changes to the higher level protocol required that need broader review, or it's broadly used so RFC documentation is worthwhile. I'm sure others can think of more. > > >> >> It also seems to imply you can do protocols that use cryptography without >> thinking about cryptography > > > What text makes you think this? The way the distinction is drawn between protocol engineering and cryptography engineering, as well as the idea that components include protocols. TLS 1.3 would not have been possible without integrating cryptographic concerns into every step of the design. > > Paul -- Astra mortemque praestare gradatim _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]