Re: [http-auth] I-D Action: draft-ietf-httpauth-scram-auth-09.txt

Martin J. Dürst <duerst@it.aoyama.ac.jp> Sat, 14 November 2015 00:59 UTC

Return-Path: <duerst@it.aoyama.ac.jp>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8A0221A883C for <http-auth@ietfa.amsl.com>; Fri, 13 Nov 2015 16:59:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.602
X-Spam-Level:
X-Spam-Status: No, score=-1.602 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xO1Q9YI3oSCK for <http-auth@ietfa.amsl.com>; Fri, 13 Nov 2015 16:59:29 -0800 (PST)
Received: from APC01-HK2-obe.outbound.protection.outlook.com (mail-hk2apc01on0119.outbound.protection.outlook.com [104.47.124.119]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E0DC01A87B2 for <http-auth@ietf.org>; Fri, 13 Nov 2015 16:59:28 -0800 (PST)
Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=duerst@it.aoyama.ac.jp;
Received: from [192.168.1.3] (60.42.129.117) by KAWPR01MB0132.jpnprd01.prod.outlook.com (10.161.27.13) with Microsoft SMTP Server (TLS) id 15.1.325.17; Sat, 14 Nov 2015 00:59:24 +0000
To: Tony Hansen <tony@att.com>, Alexey Melnikov <alexey.melnikov@isode.com>, http-auth@ietf.org
References: <20151113154417.28110.68680.idtracker@ietfa.amsl.com> <5646068C.8020602@isode.com> <56460ED6.9050304@att.com> <56462AE0.8020007@att.com>
From: "Martin J. Dürst" <duerst@it.aoyama.ac.jp>
Organization: Aoyama Gakuin University
Message-ID: <56468765.2040805@it.aoyama.ac.jp>
Date: Sat, 14 Nov 2015 09:59:17 +0900
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:38.0) Gecko/20100101 Thunderbird/38.3.0
MIME-Version: 1.0
In-Reply-To: <56462AE0.8020007@att.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Originating-IP: [60.42.129.117]
X-ClientProxiedBy: TY1PR0201CA0003.apcprd02.prod.outlook.com (25.164.90.141) To KAWPR01MB0132.jpnprd01.prod.outlook.com (25.161.27.13)
X-Microsoft-Exchange-Diagnostics: 1; KAWPR01MB0132; 2:yUHNTs30m+1TF02G+QSyPoXxy2Y1GjuDFN7gJPWvUuB0KjmFHHclbgJmyjJ7lDKQngPIWoM5C2llFa6mInSvh2zuKNTk+B1JJ9Ln43nYmJv47pqfULfgbxB575D0f7StGA5JIUAyGx4v4MwPBvy/m4WUkuJuu21oxG4+/6bN7n0=; 3:D2aFH0yaMfHjBf9bQkQsbJg8TEARafJxPXdIJkyHCE5eCrfJg000kKOUCYtUiJkZ1iU6b9k9anTVvrOz+jkG0+1YJbGVZm+9Z+W67dtSuvEmuFIk2Vh1leuoOYf1TXmDvSfQ2b2wjukhKV0h8A+pLA==; 25:UB20JI2yZTJwBb68Yv7bsZiSG/Ps2WL3lPsaukpMeeTXd+ab0hli0UOE5LX/nlqUTHvsNEPqrG3CcrgW/bXoSab3yiDJ/TaF/i54IXaR2a18/qh3n3xWLYUDINoj827vKon/EJ6AVOdx1REaSFtltG/cNXxELQ6bGw62hiV6GKrKleogQ9D4r/5qIts441pIw7T3bZiMsFt39+kGY4keMmpQUiURKuoTHJiWeOX1jXDkMOMUZ1HIrYDhGsZkP4XfCD9TBAsL75tHw4A+O3oP8A==
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:KAWPR01MB0132;
X-Microsoft-Antispam-PRVS: <KAWPR01MB013202685453066F41398398CA100@KAWPR01MB0132.jpnprd01.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(2401047)(5005006)(520078)(8121501046)(10201501046)(3002001); SRVR:KAWPR01MB0132; BCL:0; PCL:0; RULEID:; SRVR:KAWPR01MB0132;
X-Microsoft-Exchange-Diagnostics: 1; KAWPR01MB0132; 4:KCZXD6cuzSKKETWkU5FWakaqudiOMnH3QuPlP8kY2iUoGDzlGBDriV3q44yN2xtQMBA77NZiKIoe4GTDshD99oTm2qacXBkCFd3qsYcZUXrOLfd46odj1oqW/1NI0MOGt/XhmvTcB+JYU/T60xxOGPOX+E4DZ2M6G47vwLsPFeK7amHiSVjECSuT1wBwBTJqUa8n7THDSRDNr47zeL/Y9QN/SXlziVWNg+v+kjJ2wh4UbOzrowteVGy2nUKeM7422nO0kztsZsQUWGt10/fYojnSB05mrdy1lbR11jKdkIOp+ZF5GfFiz7nYJ9qs/WbicEQ9/Dhu/1GM+EPVSiKkVwt4yS0uIBX8411VINePMn1iNaNHG/QQz8uFD8vhbCST
X-Forefront-PRVS: 07607ED19A
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(6009001)(6049001)(24454002)(479174004)(189002)(199003)(92566002)(101416001)(81156007)(23676002)(230700001)(93886004)(230783001)(65956001)(66066001)(86362001)(117156001)(74482002)(59896002)(47776003)(99136001)(64126003)(50466002)(54356999)(2950100001)(117636001)(77096005)(106356001)(5001960100002)(65816999)(5004730100002)(4001350100001)(5007970100001)(5008740100001)(87976001)(83506001)(105586002)(122386002)(107886002)(42186005)(50986999)(40100003)(87266999)(5001770100001)(189998001)(76176999)(65806001)(97736004)(5001920100001)(586003); DIR:OUT; SFP:1102; SCL:1; SRVR:KAWPR01MB0132; H:[192.168.1.3]; FPR:; SPF:None; PTR:InfoNoRecords; MX:3; A:0; LANG:en;
Received-SPF: None (protection.outlook.com: it.aoyama.ac.jp does not designate permitted sender hosts)
X-Microsoft-Exchange-Diagnostics: 1;KAWPR01MB0132;23:skNHO6bcKtARV2m+v0f4nOeOfQaaE7rb5ObvauDNaLC99KxJboNXn7gMmVYs59FNwVTBoXAwKWkPHaWxGGwaSb+szSySyrcKJq/nR399NPZarlWAtGe01/lDmScXg4C5di/gTzx3vNYKWpzDVLHIeeZQUstPMFFrrkAtcFpuqn8UQLp/5vx6kX8vtV6vAzA5n0xyExymECdhqxEt9bkrr3lh92KSiVqDee3gIEXfjTKBb5Qnom0/F0t+0SmFK/FvakGLS9XCqAamgQWgTckonO1yEEFIcS65pKrp8NhpxvSglB26mJ4EMruSVzLRnJqRJH7i0vH31hTIt3WolgLeS92aVHR+XmVaxVkuSIF/RJkYKESFCERS+i26qeVz2+Rm2urwM8yPBywkNeD87XYjAaweZrK5fKqJO1JQgwAgn1EQjnkskTZN1qQj/jS963a/JjxlKCjaav3do9bdsWSTlU38E0SpOZsO3nrrKJ4EO7Q4+nu9aGqNkexvpwodzRQyRvmPUdWNj5EYKs1Ko4MBgSv0PuuLF1bqQPfqzKJ1AdWPyZAfsIcrKQFEMwzP5RNj4wG7mY4V8UJEIquRyXOoVtqnpcVJsjLS/TxFzOYxp+lKLt+iKe2UikSzjorMU5My0uu6QkqCzmCPATTkxyKox4uzPNuXpvhiVXgUY4DwJUAVbjRpKxBka73/iK61MUmGb22JkvvByyRSP+Q1MEOIxqidio/vcjZ1bsS7AQJhUeKQbIb6DvWxwI5Sum17X4ChniyhG9by5Rj7XQv7XFypwJYZvEyUaABJ+au+9mf24f6t9weuo/xAf1m+oHg/0TKOAM20xqLLgslQKjD0jRfWFEhN0l4ltTH266rJiF9VVESpcNrWOee6bPUEBs00SV/30kWHhTyGph0Az0lyUSPgraHuYKr6ysQL9+GvD/VCltxE1FxpwOQk3xrZ5Elh4Mr886iFExCkJr0x0eJkf2LJ6T0jOUEBRjU99EIsTqLB+5biSv6SrteanqIpU2MaxVKpQoIK5BqPQLR9FmIAvXpMQtmRqXH2seI4OxUQJmOriD3IT/UCcqgGTnfmP4+fOlrBkd6PhiOn6iFFUOrsBc5pOvWxQQr2pM7MbLMn3lB2EATblvRtIGsb4hMzg+Z8UixR1kSKukT6IDc13WCGI9Yk9tCGIah9pHhb4cIxyy5lJOBEHJx0TjRv3a/aVw3uXuXCmXgltAAEVjojFAdJsbfALjE+eGhzZlhLKB+tOSkl/na9FpKSJqsrCVl7YIE3Gjx+AiFUfmcO+PzF8bbgKlNvsDRngpf8XuRLH8rRWnaPxH4=
X-Microsoft-Exchange-Diagnostics: 1; KAWPR01MB0132; 5:ryYSt7L7Hzs3+/zzjNgEcVXLji0v8ILZHszfZQ90j/hHIEV9Ejy9TdFtFhfMhKD6HUo7zpEcLOz4Sgr/V7hngpt5OutoxzivTjNvSt9J4JZdrr19fhB5Sj21hDIn/oh1nOQEO69xRslGiT3H4L9TCg==; 24:Xi6GJd9tbk7vPawubztxRxcfxGBTbPTWoJM3uCDRnMdV9BEUgYZQCwqLeIZ8eIk/q1EF1tdFpPiAQeHajTvZSW2lB4rmuxL6iEDAuNbUiSU=; 20:B0SYFfBZdtd+OZx8QTwJHCBs3WA1+zouu99yYl5hRoDIbrCdA/uLrE+bBH2xzmuoJ3t4gVyfDqr4BD5NfUeONg==
SpamDiagnosticOutput: 1:23
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: it.aoyama.ac.jp
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 14 Nov 2015 00:59:24.5925 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: KAWPR01MB0132
Archived-At: <http://mailarchive.ietf.org/arch/msg/http-auth/DSlXqrMj_1RlpOaDB-MmYAzA2fM>
Subject: Re: [http-auth] I-D Action: draft-ietf-httpauth-scram-auth-09.txt
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/http-auth/>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 14 Nov 2015 00:59:31 -0000

I think further wording improvement is needed.

On 2015/11/14 03:24, Tony Hansen wrote:

>           Note that version of SCRAM doesn't support HTTP channel
>           bindings, so this header always starts with "n"; otherwise the
>           message is invalid and authentication MUST fail.

The second word, "that", seems to do double duty, both in "Note that" 
and "that version of SCRAM". This doesn't parse. Possible solutions:

           Note that this version of SCRAM doesn't support HTTP channel
           bindings, so this header always starts with "n"; otherwise the
           message is invalid and authentication MUST fail.
or

           Note that SCRAM-SHA-256 doesn't support HTTP channel
           bindings, so this header always starts with "n"; otherwise the
           message is invalid and authentication MUST fail.

Regards,   Martin.