[media-types] Re: [MEDIAMAN] From charter: Security ch ecklist
Alexey Melnikov <[email protected]>
| Newsgroups | gmane.ietf.types |
|---|---|
| Message-ID | <[email protected]> |
On 17/07/2025 22:23, Harald Alvestrand wrote:
> On 7/17/25 16:03, Alexey Melnikov wrote:
>> Hi Harald,
>>
>> On 17/07/2025 10:04, Harald Alvestrand wrote:
>>> Our charter has the following item on it:
>>>
>>> Publish a reviewer’s checklist about Security Considerations in
>>> media type applications, either as an RFC or a wiki page.
>>>
>>>
>>> This would seem to overlap somewhat with section 2.8 of 6838bis
>>> ("Security"), but at chartering time, it was probably thought of as
>>> something distinct.
>>>
>>> Should we pursue this, or ask to have the milestone removed from our
>>> charter?
>>
>> IANA already has a checklist, but not many people know about it:
>> <https://www.iana.org/form/media-types>. And yes, there is some
>> overlap with section 2.8 of 6838bis.
>>
>> I think we should keep the milestone, as we already have a good base
>> for it. I don't think the milestone requires us to have a separate
>> RFC for this.
>>
>>
>> Best Regards,
>>
>> Alexey
>
> I'm not certain whether the "security considerations" of the IANA form
> is a checklist that is usable for the reviewer as-is; it is aimed at
> the registrant, not the reviewer. But on this point, the expert really
> is the reviewer.
I tend to think they are the same. We probably can have different
versions oriented at experts and registrant, but I expect that they
would be very similar.
_______________________________________________
media-types mailing list -- [email protected]
To unsubscribe send an email to [email protected]