IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Time to Review IANA SSH Registries Policies?



I'm not specifically opposed to this, but many of ssh's registries are for string identifiers (e.g. algorithm names) where there is a straightforward mechanism for individual implementors to define unique, interoperable identifiers without going through the registry (specifically, identifiers of the form name@domain are permitted, as assigned by the owner of that domain).


Certain values, such as message numbers, are small, and thus scarce. The current policy for these is Standards Action, which IMHO is appropriate giving the size of the available namespace as well as the core protocol functions they serve. For the most part, it is intended that new values for these codes would be allocated only as part of a revision of the base protocol suite, rather than in an extension.


That said, there are some other attributes (particularly, disconnect reasons, channel open failure reasons, and extended channel data types) for which significant namespace is managed under the IETF Review policy, with a small portion set aside for private use. It does seem like it would be reasonable to update these to use Expert Review instead. The ultimate question, then, is whether it is worth the (admittedly small) effort.


-- Jeff



From: Sean Turner <sean%sn3rd.com@localhost>
Sent: Thursday, February 4, 2021 00:51
To: SSH List
Cc: Curdle List
Subject: Re: Time to Review IANA SSH Registries Policies?


Apologies I should have also sent this message to the SSH list.

Cheers,
spt

> On Feb 3, 2021, at 14:51, Sean Turner <sean%sn3rd.com@localhost> wrote:
>
> Hi! The IANA registries for SSH were established long ago when the fashion was to require an RFC to set any value (see https://datatracker.ietf.org/doc/rfc8126/ for definitions of the various registry rules). IPsec, TLS, and others initially did the same thing, but have since backed down the high bar and gone to expert review for many if not all of their registries. Is there interest in reviewing the SSH registries to see if it makes sense to move them to expert review (or some other level)?
>
> This would likely result in setting up a pool of experts and providing them with some instructions, but that’s been done before for other registries.
>
> spt



Home | Main Index | Thread Index | Old Index