ietf
[Top] [All Lists]

Re: Security for various IETF services

2014-04-03 18:55:38
At 11:40 PM +0000 4/3/14, Fred Baker (fred) wrote:

In view of recent issues in TurkTelecom and Indosat, it seems like the simplest reason would be to ensure that data putatively obtained from the IETF would in fact be obtained from the IETF.

Would this be met by allowing access using protocols where server certificates are sent, rather than requiring it? You can't force anyone to verify a server certificate or to do a good job if they try, so why force them to take a certificate?

--
Randall Gellens
Opinions are personal;    facts are suspect;    I speak for myself only
-------------- Randomly selected tag: ---------------
If the employees come first, then they are happy. A motivated
employee treats the customer well. The customer is happy so they
keep coming back, which pleases the shareholders.  It's not one of
the enduring Green mysteries of all time, it is just the way it
works.       --Herb Kelleher, Southwest Airlines CEO, 1994