Re: [TLS] RFC 2817 proposed standard status revocation?

Eric Rescorla <ekr@networkresonance.com> Mon, 11 December 2006 00:14 UTC

Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1GtYny-0005b5-AH; Sun, 10 Dec 2006 19:14:02 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1GtYnx-0005az-Fy for tls@lists.ietf.org; Sun, 10 Dec 2006 19:14:01 -0500
Received: from laser.networkresonance.com ([198.144.196.2]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1GtYnw-0001eD-4K for tls@lists.ietf.org; Sun, 10 Dec 2006 19:14:01 -0500
Received: from networkresonance.com (raman.networkresonance.com [198.144.196.3]) by laser.networkresonance.com (Postfix) with ESMTP id 68AC25C01E; Sun, 10 Dec 2006 16:17:09 -0800 (PST)
To: Peter Williams <home_pw@msn.com>
Subject: Re: [TLS] RFC 2817 proposed standard status revocation?
In-reply-to: Your message of "Sun, 10 Dec 2006 15:38:41 PST." <BAY103-W4874DCE1374D4BD2A344492D10@phx.gbl>
X-Mailer: MH-E 7.4.3; nmh 1.2; XEmacs 21.4 (patch 19)
Date: Sun, 10 Dec 2006 16:13:59 -0800
From: Eric Rescorla <ekr@networkresonance.com>
Message-Id: <20061211001709.68AC25C01E@laser.networkresonance.com>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 5a9a1bd6c2d06a21d748b7d0070ddcb8
Cc: Benjamin Black <ben@layer8.net>, tls@lists.ietf.org
X-BeenThere: tls@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/tls>
List-Post: <mailto:tls@lists.ietf.org>
List-Help: <mailto:tls-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@lists.ietf.org?subject=subscribe>
Errors-To: tls-bounces@lists.ietf.org

Peter, please do something about putting line feeds into your
messages. As-is it's very hard to read them.

Peter Williams <home_pw@msn.com> wrote:
> Within an IETF WG structure, operating under modern rules:
>  
> 1. I have not called for TLS to be removed from the standards track:
> only for the WG to perhaps "stop"...and let what we have become the
> standard. 10 years is quite long enough, given precious little of the
> core has changed in those 10 years, and we have been through 4
> versions already. I don't expect to see this recommendation adopted,
> tho, knowing well those who operate the IETF Security Area. Arguably,
> the horizontalization of TLS via the IETF-era activities into (1) the
> EAP arena

This was not an activity of the TLS WG.

> (2) into non-PKI ciphersuites

I think this was worth doing.

> (3) SAML extensions

This was not an activity of the TLS WG.

> (4) and
> even into HTTP1.1 Update

This work was done quite some time ago.


> are all worthwhile per se, and more such
> value could be expected to be forthcoming from this WG.

I'm general sympathetic to the argument that the TLS WG should be
conservative about what work it takes on. Indeed, the motivation
for the recent revisions of TLS has been almost exclusively to
correct security flaws (real or perceived) in the TLS core.


> As someone who berated IPSEC technology and adoption rates for years
> (Yea! Go SSL! Its simple! And, it works well, today!) I'm leading the
> debate, in light of what is happening: perhaps its time to move on
> from the former positions I took during the stopgap period - where the
> only goal was GET ADOPTION, by any and all means. Perhaps we need to
> reflect think what the fuller community's interests needs really are,
> FOR THE FORMAL ISSUANCE OF INTERNET STANDARD STATUS to TLS-related
> RFCs: given IPv6 (and therefore IPSEC) infrastructure maturity levels
> are improving at a smart click.
>  
> Perhaps I really ought to express this in the security area forum, not
> TLS WG?

This would be an appropriate issue to raise in a different forum.
I would suggest saag@mit.edu or ietf@ietf.org

-Ekr

_______________________________________________
TLS mailing list
TLS@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls