IPP Mail Archive: Re: IPP> Minutes of IPP Weekly Conference call - Nove. 12, 1997

Re: IPP> Minutes of IPP Weekly Conference call - Nove. 12, 1997

Tom Hastings (hastings@cp10.es.xerox.com)
Thu, 13 Nov 1997 17:10:19 PST

Let me try to explain what we meant by:
6) An administrator must be able to configure the security options.

Support of http 1.1 is MANDATORY and implementation of TLS/SSL is OPTIONAL.

But some customers may want to have a secure-only printer.

Therefore, an implementor MUST NOT build a secure-only printer, but
MUST allow the administrator (the customer) to be able to configure
the Printer to be secure-only.

Its like requiring TV manufacturers who choose to make a color TV
set to make sure that that color set also accepts black and white.
We are not allowing color-only sets.

Does this help?

Tom

At 08:19 11/13/1997 PST, Jay Martin wrote:
>Roger K Debry wrote:
>
>> Xavier Riley discussed his email outlining two approaches to handling
>> security for IPP. There was a lot of good discussion on this topic with
>> the following agreement:
>>
>> [...snip...]
>>
>> 6) An administrator must be able to configure the security options.
>
>What exactly is the significance of this statement? That is, what
>kinds of thoughts were offered during the telecom regarding expected
>methods for "configuring" the "security options"?
>
>This is not a challenge, but rather a request for clarification. It
>would seem obvious (to some, anyway) that of course the administrator
>must be able to configure a target element. But why mention this fact
>in a list in which the other items are far more detailed?
>
> ...jay
>
>----------------------------------------------------------------------
>-- JK Martin | Email: jkm@underscore.com --
>-- Underscore, Inc. | Voice: (603) 889-7000 --
>-- 41C Sagamore Park Road | Fax: (603) 889-2699 --
>-- Hudson, NH 03051-4915 | Web: http://www.underscore.com --
>----------------------------------------------------------------------
>
>