[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: LAST CALL: draft-ietf-pkix-cmc-05.txt



At 04:17 PM 7/28/99 -0400, Flanigan, Bill wrote:

>(or better yet, proactively resist the temptation
>and pressure to move on to the standards track until two implementers
>swear--and digitally sign it--they have achieved interop)

Now figure out what that means for 2549, Bill.  Steve, rightly pointed out
that the IETF/IESG have historically NOT defined what interop means; they
leave it to the vendors.

Now no cheating here.  We can't have everyone use the same ANS.1 parser
library.  Got to have 2 independent implementations of those (remember what
happened with AH and ESP with the RSA and Cylink libraries; actually it was
SHA1 and D-H).  We also cannot have everyone use same RSA algorithm library.  

Now put on a co-chair and/or AD hat.  How do you tell when a handful of
vendors come to you and say "we interop", that they did.  Or does any of
this really matter?



Robert Moskowitz
ICSA
Security Interest EMail: rgm-sec@htt-consult.com