Re: [Gen-art] Genart last call review of draft-ietf-sipcore-sip-token-authnz-12

Linda Dunbar <linda.dunbar@futurewei.com> Tue, 14 April 2020 18:41 UTC

Return-Path: <linda.dunbar@futurewei.com>
X-Original-To: gen-art@ietfa.amsl.com
Delivered-To: gen-art@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EAB0E3A09E9 for <gen-art@ietfa.amsl.com>; Tue, 14 Apr 2020 11:41:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.09
X-Spam-Level:
X-Spam-Status: No, score=-2.09 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, T_SPF_PERMERROR=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=futurewei.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id teoeNsl7UoZQ for <gen-art@ietfa.amsl.com>; Tue, 14 Apr 2020 11:41:51 -0700 (PDT)
Received: from NAM12-DM6-obe.outbound.protection.outlook.com (mail-dm6nam12on2111.outbound.protection.outlook.com [40.107.243.111]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7C15D3A09DB for <gen-art@ietf.org>; Tue, 14 Apr 2020 11:41:51 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=GKJAesImmNhLbiKYuvGNUwYQe0+45lFtbmU8qOi1X3je9H1u4mrXkL532mxWfVBKTAVd6st0DSrhsKtblvV27SBJdLeZm4LiPltxALzOllCD/+C3CQycdBKj1xvKjJ/mFHZzoab8T9a6G5HEwiPBTqdCgbcstCuAEAs67y/xwrF/PE/kAKWGnVVz7HU7Pwq+MZ5grfyfsLgSqzZx4of60JEN5tm4h5AvegVxwwHe/oOx/eVZAOcwyF0sg7SHYInTtQRLqyYJ6fIIk8DWrfIL5dqiYTyV/COTM3/ZuE4ttpk2xBhuKK3QylZTh0H81GYA9b6sjrmOpDcckAv7lWuHpQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Q/NFpRXBJZQY9IpcS3m+mAs5S3LUiDT6PKWOiasFZ3w=; b=GgAsEvQjCph1sIorrfwrwfwLHSEMbxGaTARztJlMt2011huizccaO83yWAdX07fnaJrVWQC2zCOGRT+VzOpIfYzACvxljv4+7P1g4d89n/bQ49MiYFAoz4fQF0PcTrvScgfWi/VN69yOMgHdf5JzBsQgCecggTaDL6zzFAC65RYGm1aZRbEfMQ52Z1YH8gE10dgSLGN1kjtv5hrc5NbCJ/suoU5XclPHVBzfqyn7mUizoJb0THBHmBgonqtzmzNepfqH7wczvMDQX5yiYmvfNFoZF83yKtf+qzYYSueg7M+uWdTbzHQtivcD80eTelKc8+17SwpWuq50d1WeNHSmSw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=futurewei.com; dmarc=pass action=none header.from=futurewei.com; dkim=pass header.d=futurewei.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Futurewei.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Q/NFpRXBJZQY9IpcS3m+mAs5S3LUiDT6PKWOiasFZ3w=; b=kxgNcQBIm+tX15V3kbXQyKPgPMSmtS/EFNLEeaclbLUexgHm9yRPXpK3ha77fhzBj/CQDbRlBBtAPVc6OP37qLnZbrZnUQeyDK/6ukhzAPSKDDH1NJWCfomocz95rzz8vNjRbhxOk857S2SuzLLPDh9G3FbSdy/p5pP227v7rAI=
Received: from MWHPR1301MB2096.namprd13.prod.outlook.com (2603:10b6:301:34::35) by MWHPR1301MB2032.namprd13.prod.outlook.com (2603:10b6:301:35::33) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2921.24; Tue, 14 Apr 2020 18:41:48 +0000
Received: from MWHPR1301MB2096.namprd13.prod.outlook.com ([fe80::b929:3442:e7cd:9ddf]) by MWHPR1301MB2096.namprd13.prod.outlook.com ([fe80::b929:3442:e7cd:9ddf%6]) with mapi id 15.20.2921.021; Tue, 14 Apr 2020 18:41:48 +0000
From: Linda Dunbar <linda.dunbar@futurewei.com>
To: Christer Holmberg <christer.holmberg@ericsson.com>, "gen-art@ietf.org" <gen-art@ietf.org>
Thread-Topic: [Gen-art] Genart last call review of draft-ietf-sipcore-sip-token-authnz-12
Thread-Index: AQHWEfOC85wyoLv0j0Wa8sNouhXtnqh4rQGAgAALqRA=
Date: Tue, 14 Apr 2020 18:41:48 +0000
Message-ID: <MWHPR1301MB2096E6DEDEFF6FE2BC5385A785DA0@MWHPR1301MB2096.namprd13.prod.outlook.com>
References: <158682405513.12380.9514894653338982196@ietfa.amsl.com> <EF441940-8620-4081-8A3F-2003A48E574D@ericsson.com>
In-Reply-To: <EF441940-8620-4081-8A3F-2003A48E574D@ericsson.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=linda.dunbar@futurewei.com;
x-originating-ip: [72.180.73.64]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 8dc8f08e-93b7-440b-5548-08d7e0a37d88
x-ms-traffictypediagnostic: MWHPR1301MB2032:
x-microsoft-antispam-prvs: <MWHPR1301MB203224BDFDCC8AA19C28306585DA0@MWHPR1301MB2032.namprd13.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8273;
x-forefront-prvs: 0373D94D15
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MWHPR1301MB2096.namprd13.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(10019020)(4636009)(39840400004)(396003)(346002)(376002)(136003)(366004)(478600001)(44832011)(186003)(8676002)(7696005)(64756008)(66556008)(76116006)(81156014)(53546011)(66446008)(26005)(52536014)(66946007)(6506007)(66476007)(33656002)(316002)(8936002)(55016002)(9686003)(5660300002)(71200400001)(2906002)(110136005)(86362001); DIR:OUT; SFP:1102;
received-spf: None (protection.outlook.com: futurewei.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: bR6DCyhJ3F2XTT9ry9vtJCqX7Df4OnSDk0j3tLYqTaLsJF4K8EIRZ3frmK+16c2KOLsQ5Lj16LDyK1BMPNOMBxfHoenwwaSrqUtaz2HszAgCmwRtr4kMHQHQx0l8MZ92zw+Zb+DeYHJvgRslk5D/VeTYlR73jJqndvmMDuM0HIwA6BtwBJ7PStu+DqcldAE0QUjBn431hn4L4XXJH0q/DHFQAZUOBcQondfruFfm4KiUqXkNKdq/VQp7JbBCR0BEiBy6dXIx10ZDjyhkIFf/8YBA0VIcE1G1hVmKvWbQGnzqov+jgSkWCDTU3BH0AiYrs1/I9r0QZY/ibUajUSXxoxc5Ji29dyxX/+bmK2z93GW/PZwys8oam9I+lSRVE3ls1Z06khcnQXGVATEKrzyrSEOfgpiFEkz5CpP/HnOeJlVw1KR1ycSX9vE3UWSf/Q0I
x-ms-exchange-antispam-messagedata: Szk49pnyZzFymBgU8S94y+hCkV0I1SpxcUerYxGfGJ3h1RMmNFMexucN2+XM+0kQVm/b4XJgVCPp7A6lJFzlXVHsjl/K6PnjTve1MbAwTT43unM4xiYMriiGUr8q3Dfn90hzOCHZGEPQ91fQjZRTBA==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: Futurewei.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8dc8f08e-93b7-440b-5548-08d7e0a37d88
X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Apr 2020 18:41:48.5213 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 0fee8ff2-a3b2-4018-9c75-3a1d5591fedc
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: pWikFK4Q/RSM456puEWPDnxdyf1gtbIcx9qT+PavXtfFRvMrptDstSq5f/dTEpYu/zmnaMWoTwkfovr4z0y+EQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR1301MB2032
Archived-At: <https://mailarchive.ietf.org/arch/msg/gen-art/2n9u-U_9ZpjfWwd69YvzGk3NEF0>
Subject: Re: [Gen-art] Genart last call review of draft-ietf-sipcore-sip-token-authnz-12
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/gen-art/>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Apr 2020 18:41:53 -0000

Christer, 

Thank you for the quick response. Your updated wording are much more clear. 

Linda

-----Original Message-----
From: Christer Holmberg <christer.holmberg@ericsson.com> 
Sent: Tuesday, April 14, 2020 9:25 AM
To: Linda Dunbar <linda.dunbar@futurewei.com>; gen-art@ietf.org
Subject: Re: [Gen-art] Genart last call review of draft-ietf-sipcore-sip-token-authnz-12

Hi Linda,

Thank You for the review! Please see inline.

>    Section 1.4.1: the first paragraph is very confusing. The steps after the
>    figure is much clear on what to be done. It is better to delete the the
>    sub-phrase "... where the registrar informs the UAC about the authorization ...
>    ". The actual step is actually the UAC sends the request to Registrar and get
>    the response .. as described in the steps after the Figure.
  
The purpose of the first sentence is to highlight the difference between 1.4.1 and 1.4.2: In 1.4.1 we describe the case where Registrars informs the UAC about the AS, while in 1.4.2 we describe the case where the AS is preconfigured in the UAC.

However, I do agree that the sentence is very long and confusing. Perhaps we could remove the "in a 401 response to the REGISTER request" part? 

---

>    Section 2.1.2 the paragraph before the last one (Page 8), I can' parse the
>    sentence. What do you want to say?

I assume you mean Section 2.1.1?

>    "If the UAC receives a 401/407 response with multiple WWWAuthenticate/
>    Proxy-Authenticate header fields, providing challenges
>    using different authentication schemes for the same realm, the UAC
>    provides credentials for one or more of the schemes that it supports,
>    based on local policy."
  
We want to say that, if the UAC receives multiple challenges, with different authentication  schemes, for the same realm, the UAC picks one (and provides credentials) based on local policy.

Would it be more clear if we said something like:

"....for the same realm, the UAC selects one or more of the provided schemes (based on local policy) and provides credentials for those schemes."

---
  
>    Section 2.1.3: What is AOR?

Address-of-Record.

We will enhance the abbreviation, and add a reference to RFC 3261.

---

Regards,

Christer