In an Internet Engineering Task Force specification, requirement words can carry defined meanings. RFC 2119 explains the words. RFC 8174 clarifies that their special meanings apply when they appear in all capitals. Lowercase words keep their ordinary English meanings.
MUST sets a firm requirement
MUST means an absolute requirement of the specification. MUST NOT means an absolute prohibition. REQUIRED and SHALL have the same defined meaning as MUST; SHALL NOT has the same meaning as MUST NOT. Read the surrounding text and the document’s requirement level as well. RFC 2119 says that level affects the force of these words. RFC 2119
SHOULD allows a reasoned exception
SHOULD expresses a recommendation that may have a valid exception in a particular circumstance. Before choosing another course, the reader must understand and carefully weigh the full implications. That is a substantial decision. A useful record would name the circumstance, explain why following the recommendation is unsuitable, and describe the likely effects of the alternative. RFC 2119
SHOULD NOT works in the other direction. The discouraged behavior may sometimes be acceptable or useful, but its implications and the particular case need careful consideration before it is implemented. RFC 2119
MAY leaves a choice
MAY means an item is optional. Implementations can make different choices about including it. RFC 2119 also says each must be prepared to interoperate with an implementation that makes the other choice, apart from the feature the option provides. Optionality therefore still calls for attention to how the two implementations work together. RFC 2119
These words deserve care
RFC 2119 tells specification authors to use these terms sparingly, where they serve interoperability or limit potentially harmful behavior. It also warns that the security effects of departing from a requirement or recommendation can be subtle. The label is a starting point for reading the surrounding conditions and consequences. RFC 2119
What to do
- Check whether the specification uses the capitalized words with their defined meanings. RFC 8174
- Read each requirement with its conditions and the document’s requirement level. RFC 2119
- For a SHOULD exception, write down the particular reason and weigh the effects before acting. RFC 2119
- For a MAY option, check how implementations with different choices will interoperate. RFC 2119

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.