Re: Fourth Last Call: draft-housley-tls-authz-extns

Bernard Aboba <bernard_aboba@hotmail.com> Tue, 10 February 2009 06:54 UTC

Return-Path: <bernard_aboba@hotmail.com>
X-Original-To: ietf@core3.amsl.com
Delivered-To: ietf@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 00AE03A695A for <ietf@core3.amsl.com>; Mon, 9 Feb 2009 22:54:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.396
X-Spam-Level:
X-Spam-Status: No, score=-2.396 tagged_above=-999 required=5 tests=[AWL=0.202, BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0WXmILL5KSfn for <ietf@core3.amsl.com>; Mon, 9 Feb 2009 22:54:16 -0800 (PST)
Received: from blu0-omc2-s25.blu0.hotmail.com (blu0-omc2-s25.blu0.hotmail.com [65.55.111.100]) by core3.amsl.com (Postfix) with ESMTP id 9ECFA3A6877 for <ietf@ietf.org>; Mon, 9 Feb 2009 22:54:16 -0800 (PST)
Received: from BLU137-W27 ([65.55.111.71]) by blu0-omc2-s25.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959); Mon, 9 Feb 2009 22:54:19 -0800
Message-ID: <BLU137-W27FCB3F561FD83F168E51693BD0@phx.gbl>
Content-Type: multipart/alternative; boundary="_bbb75e0b-d74d-4068-add5-fcfb180e6b15_"
X-Originating-IP: [24.19.160.53]
From: Bernard Aboba <bernard_aboba@hotmail.com>
To: ietf@ietf.org
Subject: Re: Fourth Last Call: draft-housley-tls-authz-extns
Date: Mon, 09 Feb 2009 22:54:19 -0800
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 10 Feb 2009 06:54:19.0804 (UTC) FILETIME=[65C64DC0:01C98B4C]
X-Mailman-Approved-At: Tue, 10 Feb 2009 16:51:29 -0800
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Feb 2009 06:54:18 -0000

I do not support publication of this document as a Proposed Standard, for
several reasons:

a.  I believe that the subject of this document (TLS authorization) is of
fundamental importance to a number of IETF WGs, and therefore it should
not be handled via AD-sponsorship, but rather within a WG.  If the TLS 
WG does not wish to deal with the document, then the IETF should
consider formation of a new WG to deal with this and other TLS extensions. 

b.  This document has become a lightening rod for attacks on the integrity
of the IETF and IESG.  Rather than ignoring the concerns that have been
raised, I believe that the IETF needs to tackle them head on, by initiating
reforms in the areas of affiliation disclosure and conflict of interest within
the IESG.  Given the current controversy, approving this document could
be interpretted as a lack of concern about those issues.  

c. I'm not convinced that the latest Redphone IPR disclosure represents
a substantive rather than a cosmetic change from previous disclosures. 
> -----Original Message-----
> From: ietf-announce-bounces at ietf.org 
> [mailto:ietf-announce-bounces at ietf.org] On Behalf Of The IESG
> Sent: 14 January 2009 16:18
> To: IETF-Announce
> Subject: Fourth Last Call: draft-housley-tls-authz-extns
> 
> On June 27, 2006, the IESG approved "Transport Layer Security 
> (TLS) Authorization Extensions," 
> (draft-housley-tls-authz-extns) as a proposed standard. On 
> November 29, 2006, Redphone Security (with whom Mark Brown, a 
> co-author of the draft is affiliated) filed IETF IPR disclosure 767. 
> 
> Because of the timing of the IPR Disclosure, the IESG 
> withdrew its approval of draft-housley-tls-authz-extns.  A 
> second IETF Last Call was initiated to determine whether the 
> IETF community still had consensus to publish  
> draft-housley-tls-authz-extns as a proposed standard given 
> the IPR claimed.  Consensus to publish as a standards track 
> document was not demonstrated, and the document was withdrawn 
> from IESG consideration.
> 
> A third IETF Last Call was initiated to determine whether the 
> IETF community had consensus to publish 
> draft-housley-tls-authz-extns as an experimental track RFC 
> with knowledge of the IPR disclosure from Redphone Security.  
> Consensus to publish as experimental was not demonstrated; a 
> substantial segment of the community objected to publication 
> on any track in light of the IPR terms.
> 
> Since the third Last Call, RedPhone Security filed IETF IPR 
> disclosure 1026.  This disclosure statement asserts in part 
> that "the techniques for sending and receiving authorizations 
> defined in TLS Authorizations Extensions (version 
> draft-housley-tls-authz-extns-07.txt) do not infringe upon 
> RedPhone Security's intellectual property rights".  The full 
> text of IPR disclosure 1026 is available at:
> 
> 	https://datatracker.ietf.org/ipr/1026/
> 
> This Last Call is intended to determine whether the IETF 
> community had consensus to publish  
> draft-housley-tls-authz-extns as a proposed standard given 
> IPR Disclosure 1026.
> 
> The IESG is considering approving this draft as a standards 
> track RFC. The IESG solicits final comments on whether the 
> IETF community has consensus to publish 
> draft-housley-tls-authz-extns as a proposed standard. 
> Comments can be sent to ietf at ietf.org or exceptionally to 
> iesg at ietf.org. Comments should be sent by 2009-02-11.
> 
> A URL of this Internet-Draft is:
> http://www.ietf.org/internet-drafts/draft-housley-tls-authz-extns-07.txt