Hi Eric,

On Tue, Jun 06, 2017 at 10:50:01AM -0700, Eric Rescorla wrote:
> ----------------------------------------------------------------------
> COMMENT:
> ----------------------------------------------------------------------
> 
> I am having a little trouble reading Appendix A.
> 
> If I understand correctly, the idea is:
> 
> - In version N, you have a behavior X
> - In version N+1, you introduce a setting S with default value S=X
> - In version N+2 you change the default to S=!X
> 
> However, the text says that "installations upgraded from release N+1
> will adhere to the previous insecure behavior"
> 
> Do you need to say that in N+1, you save the value S=X so that in N+1,
> it continues to apply?

If in N+1 you save S=X, then in N+2, if S is defined as X, behaviour X
will apply. If S is not defined, or defined otherwise (like with a fresh
install, not an upgrade), you will have !X behaviour.

It kind of depends on the implementation and configuration paradigm
whether this advice can be applicable, hence why we flagged it as "This
appendix is non-normative."

Kind regards,

Job

_______________________________________________
GROW mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/grow

Reply via email to