IPP Mail Archive: Re: IPP> Re: ADM - Draft minutes [client security issues]

Re: IPP> Re: ADM - Draft minutes [client security issues]

Keith Moore (moore@cs.utk.edu)
Thu, 18 Dec 1997 09:44:22 -0500

> The IETF ADs are just plain WRONG about this
> one! Security should be a customer purchasing choice, not a "cost of
> doing business using Internet 'standards track' protocols"! If IPP
> actually does supplant LPR in the enterprise network (as we all hope)
> MOST of the printers and clients will be configured WITHOUT security.

We respectfully disagree. Internet standards specify requirements
for interoperability over the entire Internet, not just in an
enterprise network. Many enterprise networks also need security.

Be assured that the requirement for strong, mandatory, interoperable
authentication will not be changed.

> Both ISO and IETF security standards have consistently mandated that
> "data confidentiality" (often shortened to "privacy") may ONLY be
> supported when BOTH "data integrity" (eg, hash matching) and "data
> authentication" (eg, certficate exchange) are used concurrently.
>
> Therefore, I suggest that we rename "secure" to "private" and clarify
> that, in any IPP protocol mapping, the IPP term "private" SHALL mean
> "mutual authentication, data integrity, and data confidentiality".

this is fine w/me.

Keith