[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: LAST CALL: draft-ietf-pkix-cmc-05.txt



Robert,

	Wow!  You have surfaced something I have long worried about, and I
bet a lot of other folks have also.  
	Are we sliding down the slippery ISO slope or are we already at the
bottom with em?!  *Interoperability* aggressively not defined; I-Ds
progressed to Proposed RFC with the hope that they might turn out to work in
an *interoperable environment*; implementers that say *trust us, it's
interoperable* so progress to Draft RFC, then to Standard; no formal peer
review of interoperability claims prior to standards-track advancement; no
formal, independent, third-party evaluation of interoperability claims prior
to standards-track advancement ... .  
	And, like you ask, does any of this matter?  But, Bob, it simply
MUST matter to someone.  Hmm, let me think now, there must be someone it
matters to, er...oh yes, I've got it:  it's the customer!

Bill

> ----------
> From: 	Robert Moskowitz[SMTP:rgm-sec@htt-consult.com]
> Sent: 	Friday, July 30, 1999 10:15 AM
> To: 	Flanigan, Bill; ietf-pkix@imc.org
> Subject: 	RE: LAST CALL: draft-ietf-pkix-cmc-05.txt
> 
[snip]

Steve, rightly pointed out
that the IETF/IESG have historically NOT defined what interop means; they
leave it to the vendors.

[snip]

> Now no cheating here.  
> 
[snip]

> Now put on a co-chair and/or AD hat.  How do you tell when a handful of
> vendors come to you and say "we interop", that they did.  Or does any of
> this really matter?
> 
> 
> 
> Robert Moskowitz
> ICSA
> Security Interest EMail: rgm-sec@htt-consult.com
>