I fully agree with the responses so far.

Over the years, I have had the pleasure of working with Deb in a number of working groups, as a technical contributor, and also in my role as co-chair of the OAuth working group. Throughout these interactions, I have found her to be knowledgeable, fair, thoughtful, and focused on helping the working groups make progress.

I am puzzled that a statement of support like this is necessary at all. Deb has a long record of service and contributions to the IETF. The IETF depends on people who are willing to invest significant time and effort in serving the community.

Ciao
Hannes


Am 16.07.2026 um 13:34 schrieb Thomas Fossati:
I fully agree with everything you’ve said, Kathleen, both regarding
Deb - who is fantastic and whose integrity can only be questioned by
those who don’t know her or are acting in bad faith - and, more
generally, regarding the repeated and increasing aggression seen on
mailing lists (and elsewhere), which poisons the atmosphere and
discourages participation.
At times it seems to me that we are reaching the limits of the open
society model that the IETF has adopted for itself, and I cannot see
what measures we could take to restore the community to an acceptable
state.
The reality is that our model relies on everyone adhering to
fundamental, albeit unwritten, meta-rules.  Which breaks the moment a
sufficient number of people fail to follow (or succeed to manipulate)
them.
cheers!

On Thu, Jul 16, 2026 at 12:54 PM Kathleen Moriarty
<[email protected]> wrote:
I’m disappointed to read that any defense for Deb is even felt necessary. Deb 
over the years has been a helpful community member, contributing her knowledge 
and expertise. In many cases, she was the one to stand up in an IETF room to 
provide insights and was essentially the last word as she was correct and level 
headed in each of those instances.

I’ll have to go look at other threads as it seems the focus here is in the 
wrong place.

There has been a proliferation of attacks on individuals of late and it’s 
counterproductive. I was on the receiving end as have many on sets of certain 
lists. End result is that people are walking away from the IETF. My own 
response was to pause my interactions on the mailing list and see that many on 
one mailing list refrain from interacting with aggressors on the list. It’s 
great to see everyone speaking up for Deb as she’s amazing and has dedicated a 
number of years to serving the IETF and she is more than qualified.

I’d like to see some action where more could be done on the accuser. These 
types of interactions are harmful to the community. And while there needs to be 
a process for appeals, it seems there’s quite a bit of abuse lately.

Best regards,
Kathleen

On Thu, Jul 16, 2026 at 5:35 AM Dennis 
Jackson<[email protected]> wrote:
I have only interacted with Deb in the past couple of years, but those 
interactions have consistently demonstrated her integrity, fairness, and 
willingness to engage with challenging but important issues.

The lazy ad-hominem attacks which have characterized recent discussions have no 
place in the IETF community and reflect far more poorly on those making them 
than on their intended targets.

We owe our ADs, and Deb in particular, a great deal of gratitude for the time & 
energy they sacrifice to keep the IETF running.

Best,
Dennis

On 15/07/2026 19:49, Deb Cooley wrote:


For the record:  I have been a Security Area Director since March 2024, that is 
2 years and a couple of months.


There have been previous inquiries into my ability to perform the duties of 
Security Area Director  via the SSHM working group, and as part of complaints 
against the TLS chairs/AD.  Those have been responded to by the IESG, the 
artifacts are below:


https://mailarchive.ietf.org/arch/msg/ssh/7KRZCX_bvZWUOG50HqDg_KVT77c/

https://datatracker.ietf.org/group/iesg/appeals/ (see artifacts 125/126, as 
well as 128/129)


In addition to the artifacts above, I suggest that there might be people for 
whom I have worked with that could give an opinion on my work ethic and conduct 
for the last 2 plus years.


The recourse for anyone who doesn’t believe this is a sufficient response is 
free to take a look at [RFC 8713, Section 
7](https://www.rfc-editor.org/info/rfc8713/#section-7).


Just a couple of minor points:

1.  Retirement means that I don't work for NSA anymore.  I earn no salary.

2.  Retired does not mean the same as 'defected'.

3.  My bio is accurate see 
here:https://datatracker.ietf.org/person/Deb%20Cooley. 37+ years of service in 
Cybersecurity which used to be Information Assurance, which used to be 
Information Security, which used to be COMSEC.

4.  If you read RFC 9151, read all of it.  Section 6 and 7 have MAY 
requirements which improve interoperability.  Note that the draft was published 
in February 2021 when Adrian Farrel was the ISE.  It was reviewed by a 
noteworthy set of reviewers including the late Jim Schaad.



Deb Cooley
Sec AD

_______________________________________________
TLS mailing list [email protected]
To unsubscribe send an email [email protected]

_______________________________________________
TLS mailing list [email protected]
To unsubscribe send an email [email protected]
_______________________________________________
TLS mailing list [email protected]
To unsubscribe send an email [email protected]

-- Thomas _______________________________________________ TLS mailing list -- [email protected] To unsubscribe send an email to [email protected]
_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to