Re: [saag] Pasi's AD notes for September 2008

Thomas Hardjono <thardjono@yahoo.com> Tue, 30 September 2008 18:28 UTC

Return-Path: <saag-bounces@ietf.org>
X-Original-To: saag-archive@ietf.org
Delivered-To: ietfarch-saag-archive@core3.amsl.com
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id D80403A6804; Tue, 30 Sep 2008 11:28:20 -0700 (PDT)
X-Original-To: saag@core3.amsl.com
Delivered-To: saag@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id BC2153A6BA0 for <saag@core3.amsl.com>; Tue, 30 Sep 2008 11:28:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PV2jyrFSv+dG for <saag@core3.amsl.com>; Tue, 30 Sep 2008 11:28:18 -0700 (PDT)
Received: from web31809.mail.mud.yahoo.com (web31809.mail.mud.yahoo.com [68.142.207.72]) by core3.amsl.com (Postfix) with SMTP id 2CE783A6804 for <saag@ietf.org>; Tue, 30 Sep 2008 11:28:18 -0700 (PDT)
Received: (qmail 97169 invoked by uid 60001); 30 Sep 2008 18:27:36 -0000
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=Message-ID:Received:X-Mailer:Date:From:Reply-To:Subject:To:Cc:MIME-Version:Content-Type:Content-Transfer-Encoding; b=Pa0Hwjos8oAL/e6hkfXIlXvxkB1K3NnjvdV9XJfmsqgsVxe4DnYICfz8PSWGjU8Zk/xfcSx+mCvpnlewx9rJJf/DUBYSJ5ddECueIkq39lzAAcI01sxurEJdV1A/WLC3MbV6e2fG+wUZL8zQasLO1lDgA8UyJ0hXrCKgFyyYUQg= ;
Message-ID: <224856.81582.qm@web31809.mail.mud.yahoo.com>
Received: from [65.197.200.82] by web31809.mail.mud.yahoo.com via HTTP; Tue, 30 Sep 2008 11:27:36 PDT
X-Mailer: YahooMailWebService/0.7.247.3
Date: Tue, 30 Sep 2008 11:27:36 -0700
From: Thomas Hardjono <thardjono@yahoo.com>
To: saag@ietf.org, secdir@mit.edu, Pasi.Eronen@nokia.com
MIME-Version: 1.0
Subject: Re: [saag] Pasi's AD notes for September 2008
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
Reply-To: thardjono@yahoo.com
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/pipermail/saag>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Sender: saag-bounces@ietf.org
Errors-To: saag-bounces@ietf.org


Pasi, Tim,

Apologies for asking, but I was wondering about the proposed Content Rights Management (ie. DRM) BOF. More specifically, I was wondering if the IETF is now open to discussing such a "DRM standard".

Back in 2001, Mark Baugher and myself went through two (2) BOFs proposing the creation of an IETF open standards for a DRM protocol.  If my memory serves me right the presiding ADs was Steve Bellovin and Russ Housley. The specific protocol was called PERM, and the slides can be found here:
http://hardjono.net/idrm/

At that time the outcry against this effort was deafening. I was arguing that it was better for the IETF to own such a protocol and made it it "open" (ie. not proprietary and no need to sign consortium legal paperwork). Since that time there has been a plethora of DRM related products and standards (eg. Apple, MSFT RM, OMA-download, CableLabs, 5C, etc, etc). In a sense, the IETF missed the boat on this one.

Not that I'm unsupportive, but I was wondering what is motivating the IETF to propose such a BOF again at this time :)

Thanks.

Regards.

/thomas/

--- On Tue, 9/30/08, Pasi.Eronen@nokia.com <Pasi.Eronen@nokia.com> wrote:

> From: Pasi.Eronen@nokia.com <Pasi.Eronen@nokia.com>
> Subject: [saag] Pasi's AD notes for September 2008
> To: saag@ietf.org, secdir@mit.edu
> Date: Tuesday, September 30, 2008, 3:21 AM
> Hi all,
> 
> Here's again a short status update about what things
> are going on 
> from my point-of-view. If you notice anything that
> doesn't look
> right, let me know -- miscommunication and mix-ups do
> happen.
> 
> Best regards,
> Pasi
> 
> MISC NOTES
> 
> - There have been two security-related BoF requests for
> IETF73:
>   OAuth (in the applications area), and Content Rights
> Management
>   (in the security area). For the latter, Tim and I have
> recommended 
>   having a bar BoF first. 
> - SecDir mailing list is in the process of being moved from
> mit.edu 
>   to ietf.org servers.
> - I've spent some time this month on tools development
> and IESG
>   process improvements -- nothing is ready yet, but
> hopefully soon..
> 
> WORKING GROUPS
> 
> DKIM
> - draft-ietf-dkim-ssp: in Publication Requested, waiting
> for 
>   me to read it.
> - Waiting for WG to send list of RFC errata IDs the WG
> agrees on.
> 
> EMU
> - draft-ietf-emu-gpsk: in AD Evaluation -- waiting for
> revised 
>   ID that reflects the new WG consensus on MAC length/key
> size 
>   issue before going to IETF last call (since 2008-08-25)
> - A liaison statement reply was sent to ITU-T SG 17
> regarding X.1034, 
>   "Guidelines on EAP-based authentication and key
> management in a 
>   data communication network".
> - IESG appointed Joe Salowey as the designated expert for
> IANA 
>   allocation of EAP Type Codes
> - (not WG item) draft-arkko-eap-aka-kdf ís now in IETF
> Last Call
> 
> IPSECME
> - Lots of emails that I need to read (but haven't done
> so yet)
> - (not wearing AD hat) I sent my "things that need to
> be looked at" 
>   list about IKEv2bis to the mailing list; I need to check
> that   
>   they got entered in the issue tracker, too.
> 
> ISMS
> - It seems the discussion has largely converged; I'm
> waiting for
>   revised IDs to read and review.
> 
> KEYPROV
> - I sent more comments regarding PSKC; I need to read the
> replies
>   and participate in discussion.
> - I need to review and comment DSKPP, too.
>   
> SASL
> - I replied to Frank Ellermann's appeal about WG
> chairs' handling 
>   of draft-ietf-sasl-crammd5.
> - Waiting for charter update text from the chairs (>6
> months)
> 
> SYSLOG
> - draft-ietf-syslog-transport-tls: a revised version
> addressing
>   Chris Newman's DISCUSS should be posted in a couple
> of days.
> - draft-ietf-syslog-sign: there has been a bunch of replies
> to my
>   AD evaluation comments that I need to read and process,
> but I 
>   haven't done so yet.
> 
> TLS
> - (not WG item) draft-rescorla-tls-suiteb is now in IETF
> Last Call.
> - (not WG item) draft-hajjeh-tls-identity-protection: IESG
> reviewed
>   this independent submission to the RFC Editor, and
> recommended
>   not publishing it.
> 
> OTHER DOCUMENTS
> 
> - draft-ietf-capwap-*: I've been working with Pat and
> others,
>   and I think we're done (except that agreed text needs
> to be   
>   edited in, and some editorial nits fixed).
> - draft-ietf-avt-rtcpssm: no news; waiting for Joerg to
> explore
>   "feedback debug" messages.
> - draft-santesson-digestbind: I read this and sent comments
> to
>   Stefan.
> - PKCS #1/RFC 3447 update: waiting for James Randall to
> post an
>   update including the various errata.
> - draft-mattsson-srtp-store-and-forward: I've promised
> to read 
>   this and send comments, but haven't done so yet.
> - draft-ietf-mpls-mpls-and-gmpls-security-framework:
> I've promised 
>   to read this once there's a new version.
> - "Security roadmap for routing protocols":
> I've promised to read
>   and comment this once Gregory sends something.
>   
> DISCUSSES (active -- something happened within last month)
> 
> - draft-ietf-capwap-protocol-binding-ieee80211: text
> agreed,
>   waiting for authors to submit a revised ID [since
> 2008-09-26]
> - draft-ietf-lemonade-msgevent: waiting for authors to
> submit
>   a revised ID [since 2008-09-08]
> - draft-ietf-mip6-whyauthdataoption: waiting for authors to
> submit 
>   a revised ID [since 2008-09-08]
> - draft-ietf-mipshop-mstp-solution: the authors have
> replied to  
>   my comments; I need to read the replies [since
> 2008-09-26]
> - draft-ietf-nfsv4-rpcsec-gss-v2: waiting for authors to
>   reply to my comments [since 2008-09-25]
> - draft-ietf-sieve-refuse-reject: waiting for authors to
> reply
>   to my comments [since 2008-09-11]
> - draft-ietf-sipping-race-examples: waiting for document
> shepherd
>   or Jon to comment the "Updates" issue [since
> 2008-09-26]
> - draft-ietf-v6ops-addcon: the changes in version -10 were
> sent
>   to 6MAN WG for review; I'll clear once this has
> happened 
>   [expected to happen on 2008-10-01]
> - draft-mraihi-inch-thraud: version -07 addressed almost
> all of 
>   my comments; waiting for authors to send RFC Editor Note
> text
>   fixing the IANA issue, too [since 2008-09-02]
> 
> DISCUSSES (stalled -- I haven't heard anything from the
> authors 
> or document shepherd for over one month)
> 
> - draft-cain-post-inch-phishingextns: waiting for authors
> to reply 
>   to my comments or submit a revised ID [since 2008-08-28]
> - draft-cam-winget-eap-fast-provisioning: waiting for
> authors to 
>   reply to my comments or submit a revised ID [since
> 2008-08-28]
> - draft-hautakorpi-sipping-uri-list-handling-refused: text
> agreed, 
>   waiting for authors to submit a revised ID [since
> 2008-07-03]
> - draft-ietf-enum-experiences: talked briefly with Jon
> Peterson 
>   in Dublin -- waiting to hear more from the authors and/or
> Jon
>   [since 2008-07-31]
> - draft-ietf-pce-pcep: new version -15 addressed some
> comments from
>   other ADs; some discussions about my comments has
> occured;
>   waiting for proposed text or revised ID [since
> 2008-06-16]
> - draft-ietf-pwe3-pw-atm-mib: waiting for authors to reply
> to
>   my comments or submit a revised ID [since 2008-07-02]
> - draft-zhou-emu-fast-gtc: changes probably agreed, waiting
> for authors
>   to submit a revised ID to see exact text [since
> 2008-08-28]
> 
> DISCUSSES (presumed dead -- I haven't heard anything
> from the authors
> or document shepherd for over three months)
> 
> - draft-ietf-bfd-base: waiting for authors to reply to my 
>   comments or submit a revised ID [since 2008-06-05]
> - draft-ietf-bfd-multihop: waiting for authors to reply to 
>   my comments or submit a revised ID [since 2008-06-05]
> - draft-ietf-bfd-v4v6-1hop: waiting for authors to reply to
> 
>   my comments or submit a revised ID [since 2008-06-05]
> - draft-ietf-shim6-proto: waiting for Erik to propose
> something 
>   to solve IPsec interaction issue [since 2008-06-18]
> - draft-ietf-simple-imdn: waiting for authors to reply to
> my 
>   comments or submit a revised ID [since 2008-05-14]
> - draft-ietf-sipping-sbc-funcs: new version (-06) addressed
>   all comments except one; text agreed for the remaining
> one,
>   waiting for RFC editor note or revised ID [since
> 2008-06-17]
> - draft-ietf-tsvwg-emergency-rsvp: this document has large 
>   number of discusses/abstains; waiting for Magnus to
> figure
>   out next steps [since 2008-06-03]
> 
> --end--
> _______________________________________________
> saag mailing list
> saag@ietf.org
> https://www.ietf.org/mailman/listinfo/saag




_______________________________________________
saag mailing list
saag@ietf.org
https://www.ietf.org/mailman/listinfo/saag