ietf
[Top] [All Lists]

Re: [dane] PGP security models, was Summary of IETF LC for draft-ietf-dane-openpgpkey

2015-09-23 10:37:11
On 9/23/2015 8:29 AM, Sam Hartman wrote:
I tend to agree with John and others who have
suggested the document should be more clear about its assumptions.


Assumptions, models, details, etc., with operational and risk implications.

The document has a number of places that need considerable elaboration
of these.

In the case of the trust model, the document is, apparently, introducing
an entirely new 'model'.

As has been noted, the challenge of local-part handling is another,
surprisingly-basic component to the mechanism that needs careful -- and
complete -- handling in the spec, if the spec is to be a full protocol
specification.

And so on.

d/

-- 
Dave Crocker
Brandenburg InternetWorking
bbiw.net

<Prev in Thread] Current Thread [Next in Thread>