IESG discuss: Security review (issue comparison-ladder-49)

This is issue comparison-ladder-49 tracked at
http://www.w3.org/International/iri-edit/Overview.html#comparison-ladder-49.

This covers the main part of Russ Housley's IESG comment, which
was the result of a security review of the IRI draft (see
https://datatracker.ietf.org/public/pidtracker.cgi?command=print_ballot&ballot_id=737&filename=draft-duerst-iri).

After a few iterations involving Russ, Paul, Michel, and myself,
the conclusion we reached was that it would be best to more or
less copy section 6 (Normalization and Comparison) from
http://www.ietf.org/internet-drafts/draft-fielding-uri-rfc2396bis-07.txt
rather than just point to it, to replace Section 5 in the IRI draft.

I'm copying the authors of RFC 2396bis and Tim Bray (the original
author of the Normalization and Comparison section) just in case.

The reason for a more-or-less full copy was that although the structure
of the ladder is mostly the same, there are differences that are not
necessarily easy to handle by simple reference, and Russ and Paul
wanted to make sure readers didn't take shortcuts and then get
something wrong.

Michel did most work on the actual new text, and I have integrated
it into the draft. To figure out what has been done, the best way
may be to look at the following two side-by-side diffs:
- Diff between Section 6 of the URI spec and Section 5 of the IRI spec:
   http://www.w3.org/International/iri-edit/normdiff.html.
- Diff between -10.txt and the new draft:
   http://www.w3.org/International/iri-edit/diff-duerst-iri-last-draft.html
(wide screen recommended for viewing).


Regards,    Martin. 

Received on Monday, 29 November 2004 22:58:51 UTC