[Gen-art] Re: Gen-ART review of: draft-ietf-secsh-gsskeyex-10.txt

Sam Hartman <hartmans-ietf@mit.edu> Mon, 29 August 2005 22:45 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1E9sO1-0000FA-Rc; Mon, 29 Aug 2005 18:45:53 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1E9oFi-00017p-3F for gen-art@megatron.ietf.org; Mon, 29 Aug 2005 14:21:02 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA25279 for <gen-art@ietf.org>; Mon, 29 Aug 2005 14:21:00 -0400 (EDT)
Received: from carter-zimmerman.mit.edu ([18.18.3.197]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1E9oH5-0008Rp-94 for gen-art@ietf.org; Mon, 29 Aug 2005 14:22:28 -0400
Received: by carter-zimmerman.mit.edu (Postfix, from userid 8042) id EE70FE004B; Mon, 29 Aug 2005 14:20:51 -0400 (EDT)
To: Bill Sommerfeld <sommerfeld@sun.com>
References: <F222151D3323874393F83102D614E055082633@CORPUSMX20A.corp.emc.com> <1125338383.453.29.camel@thunk>
From: Sam Hartman <hartmans-ietf@mit.edu>
Date: Mon, 29 Aug 2005 14:20:51 -0400
In-Reply-To: <1125338383.453.29.camel@thunk> (Bill Sommerfeld's message of "Mon, 29 Aug 2005 13:59:44 -0400")
Message-ID: <tslzmr0eha4.fsf@cz.mit.edu>
User-Agent: Gnus/5.1006 (Gnus v5.10.6) Emacs/21.3 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 52e1467c2184c31006318542db5614d5
X-Mailman-Approved-At: Mon, 29 Aug 2005 18:45:52 -0400
Cc: galb@vandyke.com, jsalowey@cisco.com, jhutz+@cmu.edu, gen-art@ietf.org, welch@mcs.anl.gov, Black_David@emc.com
Subject: [Gen-art] Re: Gen-ART review of: draft-ietf-secsh-gsskeyex-10.txt
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/gen-art>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
Sender: gen-art-bounces@ietf.org
Errors-To: gen-art-bounces@ietf.org

>>>>> "Bill" == Bill Sommerfeld <sommerfeld@sun.com> writes:

    Bill> On Sat, 2005-08-27 at 22:52, Black_David@emc.com wrote:
    >> I found one nit that needs attention.  Section 3.2 of the draft
    >> uses UTF-8 for a "user name" string but doesn't say what the
    >> applicable Unicode character usage and normalization
    >> (stringprep) requirements are.  I believe that this problem is
    >> already addressed via use of the SASL stringprep profile in the
    >> SSH-USERAUTH draft, so a sentence pointing out the (obvious)
    >> fact that "user name" is an SSH user name, and hence is subject
    >> to the SSH-USERAUTH draft's requirements on SSH user names,
    >> including appropriate use of stringprep should suffice.

    Bill> This has been a matter of substantial discussion both in
    Bill> secure shell and in sasl.

    Bill> I may be partly mangling fine details of the consensus
    Bill> result, but after sasl came up with a stringprep,
    Bill> significant concerns surfaced which led to a revised
    Bill> approach: username stringprep really belongs on the ssh
    Bill> server side, which makes it purely a local matter between
    Bill> the server and whatever user account database is consulted
    Bill> by the server.

    Bill> The client prepares the username in UTF-8 format without
    Bill> need for any normalization.  The server (which is a client
    Bill> of the notional user account database) applies the
    Bill> stringprep or other canonicalization required to match the
    Bill> encoding conventions of that database.

Well, mostly.  We recommend to server implementers that they do
stringprep and normalization and if they have no better profile to
use, use saslprep.

I think copying the text from the userauth draft would be reasonable.


_______________________________________________
Gen-art mailing list
Gen-art@ietf.org
https://www1.ietf.org/mailman/listinfo/gen-art