On Feb 17, 2010, at 12:50 AM, Thomson, Martin wrote:
>
>
>>> If this IP address matches the source IP address of the HELD
>>> location request, the location request can be authorized under the
>>> LCP policy (see Section 5.1); otherwise, the request MUST have been
>>> authorized as a third-party request.
>>
>> It seems a bit odd to place a normative requirement on something that
>> happened in the past ("MUST have been"). It's not clear that you need
>> to be normative at all since you're talking about an authorization
>> check that already happened. Here's a suggestion:
>>
>> If this IP address matches the source IP address of the HELD
>> location request, the location request can be authorized under the
>> LCP policy (see Section 5.1). Otherwise, the request must be treated
>> as a third-party request.
>
> Again, a good point. So few people have the ability to change the
> past.
>
> Are we back to using lowercase "must" for any particular reason? Is
> there a particular reason that you didn't choose to use "MUST"?
The first sentence of the paragraph says, "The AAA server consults
network policy and if the request is permitted, . . .." So I don't
really know that it makes sense to later be normative about the
decision that the server has to make, since it already checked if the
request was permitted. Does that make sense?
_______________________________________________
Geopriv mailing list
Geopriv@ietf.org
https://www.ietf.org/mailman/listinfo/geopriv