Re: [art] Ben Campbell's No Objection on draft-ietf-appsawg-file-scheme-15: (with COMMENT)

Matthew Kerwin <matthew.kerwin@qut.edu.au> Thu, 15 December 2016 06:10 UTC

Return-Path: <matthew.kerwin@qut.edu.au>
X-Original-To: art@ietfa.amsl.com
Delivered-To: art@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BD3211295A5; Wed, 14 Dec 2016 22:10:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.922
X-Spam-Level:
X-Spam-Status: No, score=-1.922 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IT55ZPRQweR7; Wed, 14 Dec 2016 22:10:01 -0800 (PST)
Received: from NAM02-SN1-obe.outbound.protection.outlook.com (mail-sn1nam02on0045.outbound.protection.outlook.com [104.47.36.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 03656129614; Wed, 14 Dec 2016 22:10:00 -0800 (PST)
Received: from MWHPR01MB2670.prod.exchangelabs.com (10.172.165.8) by MWHPR01MB2669.prod.exchangelabs.com (10.172.165.7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.771.8; Thu, 15 Dec 2016 06:09:58 +0000
Received: from MWHPR01MB2670.prod.exchangelabs.com ([10.172.165.8]) by MWHPR01MB2670.prod.exchangelabs.com ([10.172.165.8]) with mapi id 15.01.0771.014; Thu, 15 Dec 2016 06:09:58 +0000
From: Matthew Kerwin <matthew.kerwin@qut.edu.au>
To: Ben Campbell <ben@nostrum.com>, The IESG <iesg@ietf.org>
Thread-Topic: Ben Campbell's No Objection on draft-ietf-appsawg-file-scheme-15: (with COMMENT)
Thread-Index: AQHSVk5nlQztRpOFjEWvmWJSnq5yU6EIfiCA
Date: Thu, 15 Dec 2016 06:09:57 +0000
Message-ID: <MWHPR01MB2670298C94232DD1FC183BE5BE9D0@MWHPR01MB2670.prod.exchangelabs.com>
References: <148174978359.16872.6615576098350625978.idtracker@ietfa.amsl.com>
In-Reply-To: <148174978359.16872.6615576098350625978.idtracker@ietfa.amsl.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=matthew.kerwin@qut.edu.au;
x-originating-ip: [131.181.125.63]
x-ms-office365-filtering-correlation-id: c0e79800-7c3e-4158-1b86-08d424b0ff43
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001);SRVR:MWHPR01MB2669;
x-microsoft-exchange-diagnostics: 1; MWHPR01MB2669; 7:ek7Rly3X3OdNl0Z4hZeyOgqaH5bbAvVYmHCW9WmZBsXnSEavCSOUIEY4nc8lCj0Q9FGsD9bP79QREO4CIxToK5j+zSNMW4bvHs8pPc182Ed8R91CYZ6Kupve5+fudPQ3PLrc/m2sSPPWWieTZnEefbKPQXrefLUSHLzgrbmWhIn+5iiB7yoziLinVdoeA98jesWNxXen6zSwaL5E8MIEtLqVKRP8QQC4MpkInLJ4splPzx3Ske4B7fylBM27R+S222gQhXvOpRxp957BG/WDr4Ak2kGMmQUAqdPMKtgSkGVpjc9YGmOYD2hBK5Mr38Q3P+ijtfpNIy/FOFeSzvcQGGCvcAhjCei8HPhjj5NUgeB57AKLBveTKeqXrvotZ5cqxrqPNemz3Sr68pVt/Z4z6+rFwRRdsop/E1H3iIA4QyioVM2UQwVgnZ4OG0Q5a0sdheFWvFU4CXzQHpbFLQZCzg==
x-microsoft-antispam-prvs: <MWHPR01MB26697D2CC798D8077ABE20D8BE9D0@MWHPR01MB2669.prod.exchangelabs.com>
x-exchange-antispam-report-test: UriScan:(192374486261705);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(102415395)(6040375)(2401047)(8121501046)(5005006)(10201501046)(3002001)(6041248)(20161123564025)(20161123562025)(20161123560025)(20161123555025)(6072148)(6042181); SRVR:MWHPR01MB2669; BCL:0; PCL:0; RULEID:; SRVR:MWHPR01MB2669;
x-forefront-prvs: 0157DEB61B
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(6009001)(7916002)(199003)(189002)(51444003)(68736007)(189998001)(8676002)(3280700002)(81166006)(42882006)(6436002)(97736004)(3846002)(102836003)(230783001)(7736002)(122556002)(9686002)(3660700001)(305945005)(5001770100001)(86362001)(66066001)(6116002)(74316002)(81156014)(76176999)(7696004)(50986999)(2906002)(2950100002)(38730400001)(4326007)(229853002)(106116001)(99936001)(8936002)(54356999)(106356001)(92566002)(5660300001)(33656002)(105586002)(101416001)(88552002)(74482002)(77096006)(2900100001)(6506006)(25786008); DIR:OUT; SFP:1101; SCL:1; SRVR:MWHPR01MB2669; H:MWHPR01MB2670.prod.exchangelabs.com; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en;
received-spf: None (protection.outlook.com: qut.edu.au does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="SHA1"; boundary="----=_NextPart_000_0141_01D256ED.ACF0B620"
MIME-Version: 1.0
X-OriginatorOrg: qut.edu.au
X-MS-Exchange-CrossTenant-originalarrivaltime: 15 Dec 2016 06:09:57.8612 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: dc0b52a3-68c5-44f7-881d-9383d8850b96
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR01MB2669
Archived-At: <https://mailarchive.ietf.org/arch/msg/art/CAUtbXanlvNSarSH11kAEVCmb_8>
Cc: "appsawg-chairs@ietf.org" <appsawg-chairs@ietf.org>, "dcrocker@bbiw.net" <dcrocker@bbiw.net>, "draft-ietf-appsawg-file-scheme@ietf.org" <draft-ietf-appsawg-file-scheme@ietf.org>, "art@ietf.org" <art@ietf.org>
Subject: Re: [art] Ben Campbell's No Objection on draft-ietf-appsawg-file-scheme-15: (with COMMENT)
X-BeenThere: art@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Applications and Real-Time Area Discussion <art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/art>, <mailto:art-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/art/>
List-Post: <mailto:art@ietf.org>
List-Help: <mailto:art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/art>, <mailto:art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 15 Dec 2016 06:10:05 -0000

Hi Ben,

From: Ben Campbell [mailto:ben@nostrum.com] 
Sent: Thursday, 15 December 2016 07:10
>
> - Section 5: "Implementers MUST research" and "Care MUST be taken"
> both seem like requirements on people, not on implementations.
> Furthermore, "research" and "taking of care" are vague in terms of
> expected results.
> Can these be recast into concrete expectations of implementation
> behavior?

I understand what you're asking, and why, but I don't know if it's within my wordsmithing capabilities.  If I changed the RFC2119 normative keywords to regular English words I think that would make the problem go away; would the resulting text be enough for security considerations?

The "MUST research" paragraph comes almost verbatim from RFC3986, Section 7.5, but that says "should" instead of "MUST" -- I'd be happy to move back in that direction here.

Cheers
-- 
Matthew Kerwin
Senior Web Developer, Queensland University of Technology
Enterprise Information Services (EIS) – Application Services, Library Services
Level 2, KG-SYN | GPO Box 2434 | Brisbane, Qld Australia 4001
CRICOS No 00213J