Re: [jose] #161 Password Considerations - Proposed Text

"Jim Schaad" <ietf@augustcellars.com> Mon, 11 November 2013 02:49 UTC

Return-Path: <ietf@augustcellars.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE17F11E81E1 for <jose@ietfa.amsl.com>; Sun, 10 Nov 2013 18:49:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level:
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[AWL=0.001, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dKhP9KlZJx0R for <jose@ietfa.amsl.com>; Sun, 10 Nov 2013 18:49:01 -0800 (PST)
Received: from smtp2.pacifier.net (smtp2.pacifier.net [64.255.237.172]) by ietfa.amsl.com (Postfix) with ESMTP id 55EED11E81E3 for <jose@ietf.org>; Sun, 10 Nov 2013 18:49:01 -0800 (PST)
Received: from Philemon (winery.augustcellars.com [206.212.239.129]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: jimsch@nwlink.com) by smtp2.pacifier.net (Postfix) with ESMTPSA id 04B8F2C9F8; Sun, 10 Nov 2013 18:49:00 -0800 (PST)
From: Jim Schaad <ietf@augustcellars.com>
To: "'Manger, James H'" <James.H.Manger@team.telstra.com>, 'Mike Jones' <Michael.Jones@microsoft.com>, "'Matt Miller (mamille2)'" <mamille2@cisco.com>, jose@ietf.org
References: <4E5336EC-417E-45A8-9F58-952BBA668C25@cisco.com> <255B9BB34FB7D647A506DC292726F6E11536158D20@WSMSG3153V.srv.dir.telstra.com> <4E1F6AAD24975D4BA5B168042967394377E734AE@TK5EX14MBXC287.redmond.corp.microsoft.com> <255B9BB34FB7D647A506DC292726F6E115362B7ADA@WSMSG3153V.srv.dir.telstra.com>
In-Reply-To: <255B9BB34FB7D647A506DC292726F6E115362B7ADA@WSMSG3153V.srv.dir.telstra.com>
Date: Sun, 10 Nov 2013 18:47:36 -0800
Message-ID: <0a1001cede88$62aff3e0$280fdba0$@augustcellars.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQDfhKuZTDX7FCszKsUa1CQ/OLFkKQKmbkFpAVzVlEwCihm+WpvJnBag
Content-Language: en-us
Subject: Re: [jose] #161 Password Considerations - Proposed Text
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/jose>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Nov 2013 02:49:08 -0000

> -----Original Message-----
> From: jose-bounces@ietf.org [mailto:jose-bounces@ietf.org] On Behalf Of
> Manger, James H
> Sent: Sunday, November 10, 2013 4:36 PM
> To: Mike Jones; Matt Miller (mamille2); <jose@ietf.org>
> Subject: Re: [jose] #161 Password Considerations - Proposed Text
> 
> > ----------
> > From: Mike Jones [mailto:Michael.Jones@microsoft.com]
> >
> > I believe that the following text addresses the encoding issue that
> > James raised:
> >
> > 	  The PBES2 password input is an octet sequence;
> > 	  if the password to be used is represented as a text string
> > 	  rather than an octet sequence, the UTF-8 encoding of the text
string
> > 	  SHOULD be used as the octet sequence.
> >
> > If you'd like to see any changes made to it, please propose specific
> > edits.
> >
> > (The SASLPREP text is already present in the Internationalization
> > Considerations section.)
> >
> > 				Thanks,
> > 				-- Mike
> 
> 
> At least change SHOULD to MUST.

If it is not changed then there needs to be a lot of description about why
this is not a MUST.  If this is the case then it would be logical that two
different implementations could do different decisions and never
interoperate.

I would say that we should make a normative reference to the
draft-melnikov-precis-saslprepbis as well.  If not then we will probably get
hit by the ADs.

Jim

> 
> --
> James Manger
> _______________________________________________
> jose mailing list
> jose@ietf.org
> https://www.ietf.org/mailman/listinfo/jose