[Cbor] Re: I-D Action: draft-ietf-cbor-cde-04.txt
Carsten Bormann <cabo@tzi.org> Wed, 24 July 2024 20:52 UTC
From: Carsten Bormann <cabo@tzi.org>
Date: Wed, 24 Jul 2024 22:51:54 +0200
To: Anders Rundgren <anders.rundgren.net@gmail.com>
CC: CBOR <cbor@ietf.org>
Thank you. That language should be consistent in a useful way. Now [Inconsistent language about what to do when checks fail · Issue #18 · cbor-wg/draft-ietf-cbor-cde](https://github.com/cbor-wg/draft-ietf-cbor-cde/issues/18) On 24. Jul 2024, at 20:48, Anders Rundgren <anders.rundgren.net@gmail.com> wrote: > > This is slightly confusing. In the first section you "need to check the encoding and reject" and in the second section you "MUST follow/check" but nothing is said what to do when there is a mismatch. > > Since the appendix is non-normative, my interpretation is that the handling of non-compliant CDE is up to each implementer to specify. The appendix provides a checklist. It indeed doesn’t say what should be done when a check fails. Section 4 briefly discusses the security considerations of not checking, but not of checking and then ignoring the check. This probably needs an editorial improvement, such as a definition of “checking". Grüße, Carsten
