[Gen-art] Re: Gen-ART review of: draft-ietf-secsh-gsskeyex-10.txt

Bill Sommerfeld <sommerfeld@sun.com> Mon, 29 August 2005 22:46 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1E9sOm-0000Ta-LC; Mon, 29 Aug 2005 18:46:40 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1E9nvQ-0004eB-TY for gen-art@megatron.ietf.org; Mon, 29 Aug 2005 14:00:05 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA24071 for <gen-art@ietf.org>; Mon, 29 Aug 2005 14:00:03 -0400 (EDT)
Received: from brmea-mail-3.sun.com ([192.18.98.34]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1E9nwl-0007mr-CG for gen-art@ietf.org; Mon, 29 Aug 2005 14:01:30 -0400
Received: from eastmail2bur.East.Sun.COM ([129.148.13.40]) by brmea-mail-3.sun.com (8.12.10/8.12.9) with ESMTP id j7THxkDB020103; Mon, 29 Aug 2005 11:59:47 -0600 (MDT)
Received: from thunk.east.sun.com (thunk.East.Sun.COM [129.148.174.66]) by eastmail2bur.East.Sun.COM (8.12.10+Sun/8.12.10/ENSMAIL,v2.2) with ESMTP id j7THxjWB002336; Mon, 29 Aug 2005 13:59:45 -0400 (EDT)
Received: from 127.0.0.1 (localhost [127.0.0.1]) by thunk.east.sun.com (8.13.4+Sun/8.13.4) with ESMTP id j7THxiZX000548; Mon, 29 Aug 2005 13:59:44 -0400 (EDT)
From: Bill Sommerfeld <sommerfeld@sun.com>
To: Black_David@emc.com
In-Reply-To: <F222151D3323874393F83102D614E055082633@CORPUSMX20A.corp.emc.com>
References: <F222151D3323874393F83102D614E055082633@CORPUSMX20A.corp.emc.com>
Content-Type: text/plain
Message-Id: <1125338383.453.29.camel@thunk>
Mime-Version: 1.0
X-Mailer: Ximian Evolution 1.4.6.319
Date: Mon, 29 Aug 2005 13:59:44 -0400
Content-Transfer-Encoding: 7bit
X-Spam-Score: 0.0 (/)
X-Scan-Signature: ea4ac80f790299f943f0a53be7e1a21a
Content-Transfer-Encoding: 7bit
X-Mailman-Approved-At: Mon, 29 Aug 2005 18:46:40 -0400
Cc: galb@vandyke.com, jsalowey@cisco.com, jhutz+@cmu.edu, welch@mcs.anl.gov, gen-art@ietf.org, Sam Hartman <hartmans-ietf@mit.edu>
Subject: [Gen-art] Re: Gen-ART review of: draft-ietf-secsh-gsskeyex-10.txt
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/gen-art>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
Sender: gen-art-bounces@ietf.org
Errors-To: gen-art-bounces@ietf.org

On Sat, 2005-08-27 at 22:52, Black_David@emc.com wrote:
> I found one nit that needs attention.  Section 3.2 of the draft uses
> UTF-8 for a "user name" string but doesn't say what the applicable
> Unicode character usage and normalization (stringprep) requirements are.
> I believe that this problem is already addressed via use of the SASL
> stringprep profile in the SSH-USERAUTH draft, so a sentence pointing
> out the (obvious) fact that "user name" is an SSH user name, and
> hence is subject to the SSH-USERAUTH draft's requirements on SSH user
> names, including appropriate use of stringprep should suffice.

This has been a matter of substantial discussion both in secure shell
and in sasl.

I may be partly mangling fine details of the consensus result, but after
sasl came up with a stringprep, significant concerns surfaced which led
to a revised approach: username stringprep really belongs on the ssh
server side, which makes it purely a local matter between the server and
whatever user account database is consulted by the server.

The client prepares the username in UTF-8 format without need for any
normalization.  The server (which is a client of the notional user
account database) applies the stringprep or other canonicalization
required to match the encoding conventions of that database.

							- Bill






_______________________________________________
Gen-art mailing list
Gen-art@ietf.org
https://www1.ietf.org/mailman/listinfo/gen-art