Re: [saag] Comment added to draft-gutmann-scep history

Patrick McManus <pmcmanus@mozilla.com> Sun, 15 July 2018 13:10 UTC

Return-Path: <pmcmanus@mozilla.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0ADC2130E21; Sun, 15 Jul 2018 06:10:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.234
X-Spam-Level:
X-Spam-Status: No, score=-1.234 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, SPF_SOFTFAIL=0.665] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oC-5fazk9IYb; Sun, 15 Jul 2018 06:10:55 -0700 (PDT)
Received: from linode64.ducksong.com (linode6only.ducksong.com [IPv6:2600:3c02::f03c:91ff:fe6e:e8da]) by ietfa.amsl.com (Postfix) with ESMTP id 104A5130DEC; Sun, 15 Jul 2018 06:10:55 -0700 (PDT)
Received: from mail-oi0-f49.google.com (mail-oi0-f49.google.com [209.85.218.49]) by linode64.ducksong.com (Postfix) with ESMTPSA id CBA523A032; Sun, 15 Jul 2018 09:10:53 -0400 (EDT)
Received: by mail-oi0-f49.google.com with SMTP id i12-v6so70105514oik.2; Sun, 15 Jul 2018 06:10:53 -0700 (PDT)
X-Gm-Message-State: AOUpUlGsWPG+UOy1torKMj51de5y0C2ubEajUbLPf+RGqbjwiFp7kUUX T5agrAiyriwqdPnMGkfIOzKPkvLWZ3WOcAsQB8k=
X-Google-Smtp-Source: AAOMgpdGBQufWthvpD3j6ipxceJ5SL40Ap+7CM+HWat0J1plbtbxG7DLIq/33jk0nV7iNXz/6kb7ot60Qfd1WLY/E7E=
X-Received: by 2002:aca:5f0a:: with SMTP id t10-v6mr13364787oib.337.1531660253525; Sun, 15 Jul 2018 06:10:53 -0700 (PDT)
MIME-Version: 1.0
Received: by 2002:a4a:8a22:0:0:0:0:0 with HTTP; Sun, 15 Jul 2018 06:10:52 -0700 (PDT)
In-Reply-To: <1531626396613.5059@cs.auckland.ac.nz>
References: <152231658869.24008.11321959845877039592.idtracker@ietfa.amsl.com> <1522887334433.4490@cs.auckland.ac.nz> <1525092187804.38190@cs.auckland.ac.nz> <bcb96609-a4fd-faf6-cf07-12b9f1fe7df0@isode.com> <1531471734017.88813@cs.auckland.ac.nz> <1531537625942.57273@cs.auckland.ac.nz> <20180714151547.GG59001@mit.edu> <CAOdDvNqdJtwPshdPsJK20Hseq4K=Dv59=mrY0-EzK5pw_aQNQQ@mail.gmail.com> <1531626396613.5059@cs.auckland.ac.nz>
From: Patrick McManus <pmcmanus@mozilla.com>
Date: Sun, 15 Jul 2018 09:10:52 -0400
X-Gmail-Original-Message-ID: <CAOdDvNoGE=FyyujGJjFFJYDQvLjgtm8tjcKH5H2HBctweL3q1w@mail.gmail.com>
Message-ID: <CAOdDvNoGE=FyyujGJjFFJYDQvLjgtm8tjcKH5H2HBctweL3q1w@mail.gmail.com>
To: Peter Gutmann <pgut001@cs.auckland.ac.nz>
Cc: Patrick McManus <pmcmanus@mozilla.com>, Benjamin Kaduk <kaduk@mit.edu>, "draft-gutmann-scep@ietf.org" <draft-gutmann-scep@ietf.org>, "saag@ietf.org" <saag@ietf.org>
Content-Type: multipart/alternative; boundary="00000000000053ff080571097118"
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/XTwmzW4uxZS9knDwI4YyOhN-NZc>
Subject: Re: [saag] Comment added to draft-gutmann-scep history
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 15 Jul 2018 13:10:57 -0000

I'm sorry I don't have any other approach to offer - github and the mailing
list are the normal mechanisms. Github works quite well for our working
group. If you'd like to substitute for a discussion thread I would
suggesting opening an issue rather than a PR (or perhaps in addition to).

in extremis you could of course mail the author or chair directly rather
than participating in the WG. That of course doesn't really scale.




On Sat, Jul 14, 2018 at 11:46 PM, Peter Gutmann <pgut001@cs.auckland.ac.nz>
wrote:

> Patrick McManus <pmcmanus@mozilla.com> writes:
>
> >Its a work in progress and would certainly benefit from review and
> comments:
> >
> >github as easy place to leave feedback and suggested edits:
> >https://github.com/httpwg/http-extensions
>
> Is there a preferred forum specifically for discussing this document rather
> than the high-volume HTTP list?  In terms of github, I've never been
> convinced
> that a PR is the best substitute for a discussion list thread...
>
> I've got some specific suggestions about wording around the (mis-)use of
> GET,
> which early versions of SCEP did (and some still do
> *cough*Microsoft*cough*),
> creating non-idempotent GET requests containing multiple kB of
> base64-encoded
> binary gunk.  SCEP has provided a good litmus test for how many ways this
> breaks in the presence of proxies, caches, and a wide range of server
> types,
> being able to reference 56bis on this would mean I could remove a pile of
> text
> from the draft.
>
> Peter.
>