Re: Time to Review IANA SSH Registries Policies?

"Jeffrey T. Hutzelman" <jhutz-D+Gtc/[email protected]> Thu, 4 Feb 2021 22:12:40 +0000
Newsgroups gmane.ietf.curdle,gmane.ietf.secsh
Message-ID <[email protected]>
I'm not specifically opposed to this, but many of ssh's registries are for string identifiers (e.g. algorithm names) where there is a straightforward mechanism for individual implementors to define unique, interoperable identifiers without going through the registry (specifically, identifiers of the form name@domain are permitted, as assigned by the owner of that domain).


Certain values, such as message numbers, are small, and thus scarce. The current policy for these is Standards Action, which IMHO is appropriate giving the size of the available namespace as well as the core protocol functions they serve. For the most part, it is intended that new values for these codes would be allocated only as part of a revision of the base protocol suite, rather than in an extension.


That said, there are some other attributes (particularly, disconnect reasons, channel open failure reasons, and extended channel data types) for which significant namespace is managed under the IETF Review policy, with a small portion set aside for private use. It does seem like it would be reasonable to update these to use Expert Review instead. The ultimate question, then, is whether it is worth the (admittedly small) effort.


-- Jeff


________________________________
From: Sean Turner <[email protected]>
Sent: Thursday, February 4, 2021 00:51
To: SSH List
Cc: Curdle List
Subject: Re: Time to Review IANA SSH Registries Policies?


Apologies I should have also sent this message to the SSH list.

Cheers,
spt

> On Feb 3, 2021, at 14:51, Sean Turner <[email protected]> wrote:
>
> Hi! The IANA registries for SSH were established long ago when the fashion was to require an RFC to set any value (see https://datatracker.ietf.org/doc/rfc8126/ for definitions of the various registry rules). IPsec, TLS, and others initially did the same thing, but have since backed down the high bar and gone to expert review for many if not all of their registries. Is there interest in reviewing the SSH registries to see if it makes sense to move them to expert review (or some other level)?
>
> This would likely result in setting up a pool of experts and providing them with some instructions, but that’s been done before for other registries.
>
> spt

_______________________________________________
Curdle mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/curdle