[saag] Re: [rfc-i] Re: Re: RFCs vs Standards
Martin Thomson <mt@lowentropy.net> Wed, 11 December 2024 03:55 UTC
Return-Path: <mt@lowentropy.net>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6027DC1CAE94 for <saag@ietfa.amsl.com>; Tue, 10 Dec 2024 19:55:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.104
X-Spam-Level:
X-Spam-Status: No, score=-2.104 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=lowentropy.net header.b="aCq1NIu2"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="MgiIusOV"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IWFazdmLqy4f for <saag@ietfa.amsl.com>; Tue, 10 Dec 2024 19:55:52 -0800 (PST)
Received: from fout-b4-smtp.messagingengine.com (fout-b4-smtp.messagingengine.com [202.12.124.147]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0A80EC180B67 for <saag@ietf.org>; Tue, 10 Dec 2024 19:55:51 -0800 (PST)
Received: from phl-compute-05.internal (phl-compute-05.phl.internal [10.202.2.45]) by mailfout.stl.internal (Postfix) with ESMTP id 8717911401FD; Tue, 10 Dec 2024 22:55:50 -0500 (EST)
Received: from phl-imap-01 ([10.202.2.91]) by phl-compute-05.internal (MEProxy); Tue, 10 Dec 2024 22:55:50 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lowentropy.net; h=cc:cc:content-transfer-encoding:content-type:content-type :date:date:from:from:in-reply-to:in-reply-to:message-id :mime-version:references:reply-to:subject:subject:to:to; s=fm2; t=1733889350; x=1733975750; bh=yYS56+KeftmaADokaHYQxVp8e7ivp1cO M7XmyUXYA88=; b=aCq1NIu2l1ienRSfn/iHGfNMoj0jYCxG/dMW7/OKK3koaSux m72MFbpoJ7iidp3rNYzEX1mbI8u8mgM2ZALnLcfipeeQXHUFM2U0U09nIOByWebc u4qvsLr4lmHdbNmWHtaCyQZ8nA4YtOP+Ej/wm0E4li1LkNzlEX0DcYAVBB+J8IWw RcUIEZN8597Hb1pcPWjC/ashepMiJNZGVWJATLqZMcJrU6VsSn6Q6EsqFORVq+t8 gE73PfkVox5vwRQkA+QMgVXhrPNvOUYku4ClVgq9GcdGrenAkyo6CKGI0OUImdIK Rhhs6ffzRxjRdSisqhlcpnMBixjk9XVQ3mjAtA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm1; t=1733889350; x= 1733975750; bh=yYS56+KeftmaADokaHYQxVp8e7ivp1cOM7XmyUXYA88=; b=M giIusOVLH1D55niRGsxqXZSeA1RvN16u01t++kPR31nuXtW2BvaITy1w0A96Jl3j nwi5qp8vvDZ0/zPSb/zY8YsZ6R/lu0wUpVVDwyrc+eBpiWg0eb8cBNgm+D5Svylm HKtMLOW+yfBJ3pSb54E2DJ3bhKwAd9QQtcPhDdGXaKHV/NxRIUpIewkDn3leixBx MZsE1kTLtsF9pWl4U3OTKihpbM+uLRbpA3vkzQvZ6RGXp56rhzFeYCB87iTtV8LI 3AEC5OiBXf/NQzGLcXhz5OjDPPcu0LzCqxrol6rUBQoE7P50c0BI6upBTHdEswNs Fq9I7aT/w9W0DOdGe3jGQ==
X-ME-Sender: <xms:RQ1ZZxZ2r57lbW5yKwUX2tCCIws4RmBMDK7SBzGLnNJV4ZFnz0yxkg> <xme:RQ1ZZ4YnC22-4LJgNoy-nOz59YGxlNL7dxCrhgcZD8rHhPSaWuGGqsVnAuwCbeHSG 1RcD9lsK88MwmP5zd8>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefuddrjeelgdeivdcutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpggftfghnshhusghstghrihgsvgdpuffr tefokffrpgfnqfghnecuuegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnth hsucdlqddutddtmdenogfuuhhsphgvtghtffhomhgrihhnucdlgeelmdenucfjughrpefo ggffhffvvefkjghfufgtgfesthejredtredttdenucfhrhhomhepfdforghrthhinhcuvf hhohhmshhonhdfuceomhhtsehlohifvghnthhrohhphidrnhgvtheqnecuggftrfgrthht vghrnhepuddvuddtheeludevleeitdeigeehteehgedtgffhvdevkeegvdekvdelgfevud fgnecuffhomhgrihhnpehgihhthhhusgdrihhonecuvehluhhsthgvrhfuihiivgeptden ucfrrghrrghmpehmrghilhhfrhhomhepmhhtsehlohifvghnthhrohhphidrnhgvthdpnh gspghrtghpthhtohepiedpmhhouggvpehsmhhtphhouhhtpdhrtghpthhtoheprhhsrghl iiesrghkrghmrghirdgtohhmpdhrtghpthhtohepsghrihgrnhdrvgdrtggrrhhpvghnth gvrhesghhmrghilhdrtghomhdprhgtphhtthhopehsrggrghesihgvthhfrdhorhhgpdhr tghpthhtoheplhgvrghrsehlvggrrhdrtghhpdhrtghpthhtoheprhhftgdqihhnthgvrh gvshhtsehrfhgtqdgvughithhorhdrohhrghdprhgtphhtthhopegtrggsohesthiiihdr ohhrgh
X-ME-Proxy: <xmx:RQ1ZZz-QKg6zYnodqHUSfdE3QS0tQ4qn1uNCN7et755ww44w16BIRQ> <xmx:RQ1ZZ_pwrybPdVBzp6SwOXAmyPZpiJPSMbNLbYNyJnHHUGWXDua3IQ> <xmx:RQ1ZZ8p670arHfk6uXbES3GcwMMXcW2AFMdSABDWaSo-CSlNx-W8Eg> <xmx:RQ1ZZ1RgZztW_WgmaQDyBAFIzPjkSldV8kNtI6TNMq2GN5oWeQ8oqg> <xmx:Rg1ZZxAxp1NSsZUelmMhwZYJQAuUwLbBJt6_G4F_0Ro0ooMPt3kOUhLC>
Feedback-ID: ic129442d:Fastmail
Received: by mailuser.phl.internal (Postfix, from userid 501) id 72CC23360079; Tue, 10 Dec 2024 22:55:49 -0500 (EST)
X-Mailer: MessagingEngine.com Webmail Interface
MIME-Version: 1.0
Date: Wed, 11 Dec 2024 14:55:29 +1100
From: Martin Thomson <mt@lowentropy.net>
To: Brian E Carpenter <brian.e.carpenter@gmail.com>, "Salz, Rich" <rsalz@akamai.com>, Eliot Lear <lear@lear.ch>, Carsten Bormann <cabo@tzi.org>
Message-Id: <1e865600-6d1d-498f-b4b3-36325c3c8867@betaapp.fastmail.com>
In-Reply-To: <6b7ee63e-f0a9-43f1-bfbd-3f305306fc59@gmail.com>
References: <BE95E617-C929-43BA-BB40-41E189A8158B@akamai.com> <3029EB03-6E7A-47CB-9682-F511CB51EE17@akamai.com> <10065.1732826193@obiwan.sandelman.ca> <CACsn0cmWVeFdJ3dzMj5SV4XpJF4rssULtfQ1moeefoq-Evhk=g@mail.gmail.com> <CAGL5yWb=tLvMOYFKT3ffVbcy7BAD=i4B0VHEUdkvwRvZ3X3Bsw@mail.gmail.com> <m2mshh4v8l.wl-randy@psg.com> <CABcZeBMjxNbBMYU2p3_a8-5VCExgmY-7XLof7die05YOEX-38A@mail.gmail.com> <70419651-6443-4393-9ca1-8a1c98a68db0@cs.tcd.ie> <CABcZeBNtBRxi5zSf9OvUip2AtyVD6Wt9+kQESuUzo-=Kur9+ZQ@mail.gmail.com> <fac981d9-2fe9-4a84-8af1-845acd72af58@cs.tcd.ie> <14124.1733073164@obiwan.sandelman.ca> <d52ee080-814b-46fd-9e0f-41349941eeac@cs.tcd.ie> <GVXPR07MB9678DF2C14EA44B28C3DA372893D2@GVXPR07MB9678.eurprd07.prod.outlook.com> <F304B6BA-6969-4C62-A217-88E76F82CDC2@tzi.org> <C74E3E9D-E892-48B4-87BE-CD634081AA23@akamai.com> <030FD3D1-8BC9-4C92-84EE-9CD18F451E73@tzi.org> <5249aa71-52c2-4f20-b2ae-62eaf75c82b7@lear.ch> <F54D57D6-F1DF-43A5-A437-7CD2AA4B181A@akamai.com> <6b7ee63e-f0a9-43f1-bfbd-3f305306fc59@gmail.com>
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
Message-ID-Hash: MJCDEWAH2UCPYAXBDK7TU3PMDSO5V74O
X-Message-ID-Hash: MJCDEWAH2UCPYAXBDK7TU3PMDSO5V74O
X-MailFrom: mt@lowentropy.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-saag.ietf.org-0; header-match-saag.ietf.org-1; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "rfc-interest@rfc-editor.org" <rfc-interest@rfc-editor.org>, IETF SAAG <saag@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [saag] Re: [rfc-i] Re: Re: RFCs vs Standards
List-Id: Security Area Advisory Group <saag.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/IsO8OcxCRrdmc1jnkdl855IFkvU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Owner: <mailto:saag-owner@ietf.org>
List-Post: <mailto:saag@ietf.org>
List-Subscribe: <mailto:saag-join@ietf.org>
List-Unsubscribe: <mailto:saag-leave@ietf.org>
On Wed, Dec 11, 2024, at 12:22, Brian E Carpenter wrote: > I don't think we can do this until Section 2.2 of RFC 2026 has been > fairly comprehensively rewritten. Paul and I proposed exactly that, in the draft you cited. An attempt was made to align the statements and documentation with reality, as opposed to the stories we make up about people not deploying code based on I-Ds: https://martinthomson.github.io/no-expiry/draft-thomson-gendispatch-no-expiry.html#section-2.1 We did not propose that the scary note Rich mentioned be removed or altered. Of course it will be ignored, just as it has always been, but we were looking to make a surgical change so it didn't seem worth the effort. We can further recommend changes to that note if there is appetite for change. The main problem is the strong reaction from several people about the change. The archives of no-draft-expiry@ietf.org tell a pretty grim tale of how this institution is incapable of implementing the most trivial change. We also have draft-levine-iduse in the mix (which uses different words, but basically makes exactly the same proposal).
- [saag] FW: New Version Notification for draft-rsa… Salz, Rich
- [saag] Re: New Version Notification for draft-rsa… Salz, Rich
- [saag] Re: FW: New Version Notification for draft… Simon Josefsson
- [saag] Re: New Version Notification for draft-rsa… Simon Josefsson
- [saag] Re: New Version Notification for draft-rsa… Salz, Rich
- [saag] Re: New Version Notification for draft-rsa… Tero Kivinen
- [saag] Re: New Version Notification for draft-rsa… Damien Miller
- [saag] Re: New Version Notification for draft-rsa… Simon Josefsson
- [saag] Re: New Version Notification for draft-rsa… Tero Kivinen
- [saag] Re: New Version Notification for draft-rsa… Paul Wouters
- [saag] Re: New Version Notification for draft-rsa… Michael Richardson
- [saag] Re: New Version Notification for draft-rsa… Salz, Rich
- [saag] Re: New Version Notification for draft-rsa… Stephen Farrell
- [saag] Re: New Version Notification for draft-rsa… Peter Gutmann
- [saag] Re: New Version Notification for draft-rsa… Michael Richardson
- [saag] Re: New Version Notification for draft-rsa… Peter Gutmann
- [saag] Re: New Version Notification for draft-rsa… Salz, Rich
- [saag] Re: New Version Notification for draft-rsa… Paul Wouters
- [saag] Re: New Version Notification for draft-rsa… Michael Richardson
- [saag] Re: New Version Notification for draft-rsa… Watson Ladd
- [saag] Re: New Version Notification for draft-rsa… Paul Wouters
- [saag] Re: New Version Notification for draft-rsa… Paul Wouters
- [saag] Re: New Version Notification for draft-rsa… Paul Wouters
- [saag] Re: New Version Notification for draft-rsa… D. J. Bernstein
- [saag] Re: New Version Notification for draft-rsa… Salz, Rich
- [saag] Re: New Version Notification for draft-rsa… Eliot Lear
- [saag] Re: New Version Notification for draft-rsa… Paul Wouters
- [saag] Re: New Version Notification for draft-rsa… Watson Ladd
- [saag] Re: New Version Notification for draft-rsa… Eliot Lear
- [saag] Re: New Version Notification for draft-rsa… Eliot Lear
- [saag] Re: New Version Notification for draft-rsa… Watson Ladd
- [saag] Re: New Version Notification for draft-rsa… D. J. Bernstein
- [saag] Re: New Version Notification for draft-rsa… Paul Wouters
- [saag] Re: New Version Notification for draft-rsa… Paul Wouters
- [saag] Re: New Version Notification for draft-rsa… Randy Bush
- [saag] Re: New Version Notification for draft-rsa… Michael Jones
- [saag] Re: New Version Notification for draft-rsa… Randy Bush
- [saag] Re: New Version Notification for draft-rsa… Eliot Lear
- [saag] Re: New Version Notification for draft-rsa… Alan DeKok
- [saag] Re: New Version Notification for draft-rsa… D. J. Bernstein
- [saag] Re: New Version Notification for draft-rsa… Damien Miller
- [saag] Re: New Version Notification for draft-rsa… Eric Rescorla
- [saag] Re: New Version Notification for draft-rsa… Stephen Farrell
- [saag] Side-comment: SSH issues (was: New Version… Peter Gutmann
- [saag] Re: New Version Notification for draft-rsa… Eric Rescorla
- [saag] Re: New Version Notification for draft-rsa… Stephen Farrell
- [saag] Re: New Version Notification for draft-rsa… Simon Josefsson
- [saag] Re: New Version Notification for draft-rsa… Simon Josefsson
- [saag] RFCs vs Standards Michael Richardson
- [saag] Re: New Version Notification for draft-rsa… D. J. Bernstein
- [saag] Re: New Version Notification for draft-rsa… Eric Rescorla
- [saag] Re: RFCs vs Standards Stephen Farrell
- [saag] Re: RFCs vs Standards John Mattsson
- [saag] Re: New Version Notification for draft-rsa… Eliot Lear
- [saag] Re: New Version Notification for draft-rsa… Peter Gutmann
- [saag] Re: RFCs vs Standards Carsten Bormann
- [saag] Re: [rfc-i] Re: RFCs vs Standards Salz, Rich
- [saag] Re: [rfc-i] RFCs vs Standards Carsten Bormann
- [saag] Re: [rfc-i] RFCs vs Standards Eliot Lear
- [saag] Re: [rfc-i] RFCs vs Standards Salz, Rich
- [saag] Re: [rfc-i] RFCs vs Standards Tim Bray
- [saag] Re: [rfc-i] RFCs vs Standards StJohns, Michael
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards Brian E Carpenter
- [saag] Re: New Version Notification for draft-rsa… Eliot Lear
- [saag] Re: New Version Notification for draft-rsa… Paul Wouters
- [saag] Re: [rfc-i] RFCs vs Standards Eric Rescorla
- [saag] Re: [rfc-i] Re: RFCs vs Standards Brian E Carpenter
- [saag] Re: [rfc-i] RFCs vs Standards Carsten Bormann
- [saag] Re: [rfc-i] RFCs vs Standards Eric Rescorla
- [saag] Re: New Version Notification for draft-rsa… Peter Gutmann
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards Joel Halpern
- [saag] Re: [rfc-i] RFCs vs Standards Behcet Sarikaya
- [saag] Re: New Version Notification for draft-rsa… Eric Rescorla
- [saag] Re: [rfc-i] Re: RFCs vs Standards Brian E Carpenter
- [saag] Re: New Version Notification for draft-rsa… Eliot Lear
- [saag] Re: [rfc-i] RFCs vs Standards Salz, Rich
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards Salz, Rich
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards Martin Thomson
- [saag] Re: [rfc-i] RFCs vs Standards Michael Richardson
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards Alan DeKok
- [saag] Re: [rfc-i] RFCs vs Standards Carsten Bormann
- [saag] Re: [rfc-i] RFCs vs Standards Salz, Rich
- [saag] Re: [rfc-i] Re: RFCs vs Standards Watson Ladd
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards Simon Josefsson
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards S Moonesamy
- [saag] Re: [rfc-i] RFCs vs Standards Eliot Lear
- [saag] Re: [rfc-i] RFCs vs Standards Eric Rescorla
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards Eric Rescorla
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards Joel Halpern
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards John Mattsson
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards Randy Bush
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards Carsten Bormann
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards Randy Bush
- [saag] Re: [rfc-i] Re: Re: RFCs vs Standards Carsten Bormann
- [saag] Re: [rfc-i] Re: Re: Re: Re: RFCs vs Standa… Phillip Hallam-Baker
- [saag] Re: [rfc-i] Re: Re: Re: Re: RFCs vs Standa… Eric Rescorla
- [saag] Re: [rfc-i] Re: Re: Re: Re: RFCs vs Standa… Tero Kivinen
- [saag] Re: [rfc-i] Re: Re: Re: Re: Re: RFCs vs St… touch@strayalpha.com
- [saag] Re: [rfc-i] Re: Re: Re: Re: RFCs vs Standa… Phillip Hallam-Baker