Re: [Gendispatch] New Version Notification for draft-thomson-gendispatch-rfc-derivatives-00.txt
Eric Rescorla <ekr@rtfm.com> Fri, 29 September 2023 13:42 UTC
Return-Path: <ekr@rtfm.com>
X-Original-To: gendispatch@ietfa.amsl.com
Delivered-To: gendispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4904AC151092 for <gendispatch@ietfa.amsl.com>; Fri, 29 Sep 2023 06:42:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.903
X-Spam-Level:
X-Spam-Status: No, score=-1.903 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20230601.gappssmtp.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uajZfd3FW7kY for <gendispatch@ietfa.amsl.com>; Fri, 29 Sep 2023 06:42:43 -0700 (PDT)
Received: from mail-oo1-xc36.google.com (mail-oo1-xc36.google.com [IPv6:2607:f8b0:4864:20::c36]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 861DFC17EB45 for <gendispatch@ietf.org>; Fri, 29 Sep 2023 06:42:33 -0700 (PDT)
Received: by mail-oo1-xc36.google.com with SMTP id 006d021491bc7-57b635e3fd9so5959088eaf.3 for <gendispatch@ietf.org>; Fri, 29 Sep 2023 06:42:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20230601.gappssmtp.com; s=20230601; t=1695994953; x=1696599753; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=SUDVtcjdSeRyM5l2HdzUpjLCNCSidE5iNiFQepQ0vLc=; b=ba2/IsbHKPXQ1QbSq63hx0ggKtNX83WUnF6t/DS4POLCZ4PKTVCKUK9TChn/NolmAJ O0gH5AGD2jzG63BTsrNWStmSRLnlEgj5PljiUd75tDiHalXb4UyCjUvB0kzNTtD9YKaK G9oc3msbCnNwFcETAwI2AHutDPCKFPJH+3FBk5lPEYYMj6fxSe8SHrh1tfaMS5xgUiXF Jk8oaxf8Y3WQ7WfQcVOboQ7lrDBcXaCQfKIdyispLSmMg2oi/AX53ckdt6u54knRv4WW /hH6GQQV078+XQRpeW7nZD6hOpkNCBhf9Ol2X0CFc/oyoWuAEhVa7iw2WImKoibDw2dk 718g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1695994953; x=1696599753; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=SUDVtcjdSeRyM5l2HdzUpjLCNCSidE5iNiFQepQ0vLc=; b=gl0EUVoJY4p9vyeMEiXR6vWpV4ouNZqHIOwNhfNJTkdatDxsZuoI0L2QUapK2Ao9vT 7EViyGqcANEcxe2Ja6SKXdEjeCSM8gq+KgYEsJlMwgOC11UYBdmkrUjjWzUQpc8wevKf rihF5hqxq68ACUrVg2uZcI5Kd10yFqGgT5kY2RKLdmWujYTCnI5uM8h2mfBclloudqr2 IFYPvXcH2f2nVoEP87fPnntgzMbcbqDKMoyuzWGAFsqDR++j9YmZCqI9ebcfp/SfkBG5 gE5FuhLFAdFCfDUypQvQc0nWPKhYt9xXd9VZH/deXNXKjx/KuJtld6fV5XJNCz9Xl5sS ZBsg==
X-Gm-Message-State: AOJu0YyAgbz8yhb/0YWqnuwN/9p/4DAvahH2SpFPxCjT/qIrSsMluovm vXnDWjnajmixFozxap2yMc4jFNVgjFSb0K0vkoViUg==
X-Google-Smtp-Source: AGHT+IFQJsk6TcNvKQA0CZn2o+UIyh5iuzd0W0HMYfaXqlZgUop/a6nvcPNZ2JI4f6YBlvbDNX0XO9CBZacOJTRYesg=
X-Received: by 2002:a05:6358:98a2:b0:143:26ab:1ee8 with SMTP id q34-20020a05635898a200b0014326ab1ee8mr3655297rwa.28.1695994941100; Fri, 29 Sep 2023 06:42:21 -0700 (PDT)
MIME-Version: 1.0
References: <169587871859.41935.17692726615817157868@ietfa.amsl.com> <3c7a5635-6a18-445e-9483-22ebfe31e1d5@betaapp.fastmail.com> <a970d95a-fbdc-8271-bbbc-889de7c6ac87@joelhalpern.com> <CABcZeBNgdb4ZtEqVeG6D=H617UrHG9SgktmZaLG_TjKZFMVvZg@mail.gmail.com> <17e3ec59-7568-4636-09f2-f4be9cf0f0d5@joelhalpern.com> <CABcZeBNzG+Gs_GZO1pdFfEirkMGU3SQpyimy4FXy0byk3SxStg@mail.gmail.com> <17154a5c-1483-9509-4fe2-bf8aba82f2e8@joelhalpern.com> <5f6b1c1e-9054-61d0-a5ea-4a205c1eeecf@gmail.com> <0050d192-e799-4342-978c-208901a03fef@betaapp.fastmail.com> <6d322942-fba4-489d-b3bb-802ff06e87bf@lear.ch> <9FD5A234-40B5-46C8-8A6E-881C2C075FD0@mnot.net> <6bdd91d7-f061-4fc1-b671-292b19717198@lear.ch> <99a22584-3b9e-4b3b-9bb1-e5ef0c0e8c32@betaapp.fastmail.com> <3518e0eb-4974-4a28-a755-da10a2c88194@lear.ch> <442BD882-061B-4C04-9699-9AF1877190DA@mnot.net> <2786223b-fed8-4e5a-8b01-1aa1e0049f50@lear.ch> <CABcZeBN_-pnOLq3hbxnhfcQVmHmMQ4tT=nsn9jr9XUJn1H2bmQ@mail.gmail.com> <6aded56a-1e18-29e0-d58a-f72ecbcd0ab9@lear.ch>
In-Reply-To: <6aded56a-1e18-29e0-d58a-f72ecbcd0ab9@lear.ch>
From: Eric Rescorla <ekr@rtfm.com>
Date: Fri, 29 Sep 2023 06:41:44 -0700
Message-ID: <CABcZeBOafTVSuA02AdpHvbBVsdEdSzhJ0-2gg=xhiA2Js6QB2Q@mail.gmail.com>
To: Eliot Lear <lear@lear.ch>
Cc: Mark Nottingham <mnot=40mnot.net@dmarc.ietf.org>, Martin Thomson <mt@lowentropy.net>, gendispatch@ietf.org
Content-Type: multipart/alternative; boundary="000000000000016f3c06067f9812"
Archived-At: <https://mailarchive.ietf.org/arch/msg/gendispatch/CoAfm2F7p2fg1rUzoDKEf2Iiows>
Subject: Re: [Gendispatch] New Version Notification for draft-thomson-gendispatch-rfc-derivatives-00.txt
X-BeenThere: gendispatch@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: General Area Dispatch <gendispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gendispatch>, <mailto:gendispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/gendispatch/>
List-Post: <mailto:gendispatch@ietf.org>
List-Help: <mailto:gendispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gendispatch>, <mailto:gendispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Sep 2023 13:42:48 -0000
On Fri, Sep 29, 2023 at 6:22 AM Eliot Lear <lear@lear.ch> wrote: > Hi Eric, > On 29.09.2023 15:11, Eric Rescorla wrote: > > Well, I'm no longer at Mozilla, but seeing as you mention Firefox, I can > tell you that when I was this scenario wasn't anywhere near the top of my > concerns around European regulation. Rather, it was ill-advised > requirements in the name of security (e.g. QWACs). In fact, while I had > concerns about CRA, it was not about standards forking but rather about the > security disclosure and process requirements ( > https://blog.mozilla.org/netpolicy/2023/07/13/european-parliaments-version-of-the-cra-threatens-cybersecurity-and-open-source-development/ > ). > > And it *shouldn't* be a concern, so long as we maintain control of our > works. You are proposing to release control of our works. > I'm proposing to release control of the words they are written in. I don't think that's the main content of our works. Rather, that's the PDUs and the protocol semantics (which, as an aside, is why it's possible to write compatible implementations of specifications largely without reference to the RFCs but rather by looking at protocol traces and other implementations). > > > If another jurisdiction replicates Europe's model and then diverges, we >> have can end up in one of two scenarios- one bad and the other worse: >> >> - Bad: different code points, but a local requirement to use a >> particular standard; meaning no common algorithm selection. >> - Worse: same code point but different meaning. >> >> We can and have seriously limited both of these threats through our >> copyrights. If we give up on that we are asking for chaos. >> > I don't find this at all persuasive. ETSI is perfectly capable of writing > their own versions of specifications when they choose to, or, alternately > providing diffs against ours (again, see QWACs), and with any code points > they choose. If the only thing preventing this is copyright, then that's > not going to do much > > Ok, let's agree to disagree. > Well, we can do that, but I wish you would engage with the specific example I provided above, which I think is directly on point and (again, when I was at Mozilla) was by far the biggest concern I had about local variants of specifications (see https://educatedguesswork.org/posts/eidas-article45/ for more details). Here, we have a set of specifications which everyone agrees are managed by the IETF, namely PKIX, TLS, and HTTP(S). The EU wishes to levy a new set of requirements that browsers accept a variant type of certificate that attests not to (or not only to, depending on the variant) the domain name of the endpoint but rather to their legal identity (a "Qualified Website Authentication Certificate"). When ETSI was called upon to provide the supporting specifications for QWACs, they didn't write their own copies of RFC 5280, etc. but just published their own documents that extend the IETF RFCs. As noted, this is *also* what ETSI did for eTS. I suppose you could argue that they did it this way because they weren't allowed to just copy RFC 5280 and make their own changes, but that would be an incredibly inefficient approach.The goal here is to leverage the existing ecosystem with some tweaks not to create a parallel ecosystem, because once you've done the latter, you actually own it and have to maintain it. The effort of doing that would far outweigh the one time cost of producing a compatible specification with different words. -Ekr > Eliot >
- Re: [Gendispatch] New Version Notification for dr… Eliot Lear
- Re: [Gendispatch] New Version Notification for dr… Eric Rescorla
- Re: [Gendispatch] New Version Notification for dr… Martin Thomson
- Re: [Gendispatch] New Version Notification for dr… Eliot Lear
- Re: [Gendispatch] New Version Notification for dr… Eliot Lear
- Re: [Gendispatch] New Version Notification for dr… Eric Rescorla
- Re: [Gendispatch] New Version Notification for dr… Joel Halpern
- Re: [Gendispatch] New Version Notification for dr… Eric Rescorla
- Re: [Gendispatch] New Version Notification for dr… Joel Halpern
- Re: [Gendispatch] New Version Notification for dr… Eric Rescorla
- Re: [Gendispatch] New Version Notification for dr… Paul Wouters
- Re: [Gendispatch] New Version Notification for dr… Joel Halpern
- Re: [Gendispatch] New Version Notification for dr… Salz, Rich
- Re: [Gendispatch] New Version Notification for dr… John Scudder
- Re: [Gendispatch] New Version Notification for dr… Martin Thomson
- Re: [Gendispatch] New Version Notification for dr… Eliot Lear
- Re: [Gendispatch] New Version Notification for dr… Mark Nottingham
- Re: [Gendispatch] New Version Notification for dr… Eliot Lear
- Re: [Gendispatch] New Version Notification for dr… Martin Thomson
- Re: [Gendispatch] New Version Notification for dr… Eliot Lear
- Re: [Gendispatch] New Version Notification for dr… Mark Nottingham
- Re: [Gendispatch] New Version Notification for dr… Eliot Lear
- Re: [Gendispatch] New Version Notification for dr… Martin Vigoureux
- Re: [Gendispatch] New Version Notification for dr… Eric Rescorla
- Re: [Gendispatch] New Version Notification for dr… Eliot Lear
- Re: [Gendispatch] New Version Notification for dr… Eric Rescorla
- Re: [Gendispatch] New Version Notification for dr… Eliot Lear
- Re: [Gendispatch] New Version Notification for dr… Joel Halpern
- Re: [Gendispatch] New Version Notification for dr… Brian E Carpenter
- Re: [Gendispatch] New Version Notification for dr… Brian E Carpenter
- Re: [Gendispatch] [Ext] Re: New Version Notificat… David Huberman
- Re: [Gendispatch] [Ext] Re: New Version Notificat… Brian E Carpenter