[kitten] New Version Notification for draft-kaduk-kitten-gss-loop-02.txt (fwd)

Benjamin Kaduk <kaduk@MIT.EDU> Tue, 14 January 2014 21:55 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E8361AE2AC for <kitten@ietfa.amsl.com>; Tue, 14 Jan 2014 13:55:24 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.139
X-Spam-Level:
X-Spam-Status: No, score=-3.139 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.538, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id g9X0naBbSDIm for <kitten@ietfa.amsl.com>; Tue, 14 Jan 2014 13:55:23 -0800 (PST)
Received: from dmz-mailsec-scanner-1.mit.edu (dmz-mailsec-scanner-1.mit.edu [18.9.25.12]) by ietfa.amsl.com (Postfix) with ESMTP id F361C1AE230 for <kitten@ietf.org>; Tue, 14 Jan 2014 13:55:22 -0800 (PST)
X-AuditID: 1209190c-f794a6d000000c27-39-52d5b23fc8c1
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-1.mit.edu (Symantec Messaging Gateway) with SMTP id 0E.1D.03111.F32B5D25; Tue, 14 Jan 2014 16:55:11 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id s0ELtA2b005991 for <kitten@ietf.org>; Tue, 14 Jan 2014 16:55:11 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id s0ELt9bi026663 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Tue, 14 Jan 2014 16:55:10 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id s0ELt9Vx011721; Tue, 14 Jan 2014 16:55:09 -0500 (EST)
Date: Tue, 14 Jan 2014 16:55:08 -0500
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
Message-ID: <alpine.GSO.1.10.1401141648420.27579@multics.mit.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"; format="flowed"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrHIsWRmVeSWpSXmKPExsUixCmqrGu/6WqQwbFX0hZHN69icWD0WLLk J1MAYxSXTUpqTmZZapG+XQJXxqnjD9gKnopWzPzr08B4VrCLkZNDQsBEYu2PPWwQtpjEhXvr gWwuDiGB2UwSlzo6WCGc44wS++e+ZoZwbjBJfF7yGqqsgVHi6LTdLF2MHBwsAtoSjx/qg4xi E1CRmPlmI9hYEQFhid1b3zGD2MICARLHjr4Ci/MKOEpsb7/BCmKLCuhIrN4/hQUiLihxcuYT MJtZwFLi3J/rbBMY+WYhSc1CklrAyLSKUTYlt0o3NzEzpzg1Wbc4OTEvL7VI11AvN7NELzWl dBMjOJgkeXYwvjmodIhRgINRiYc3IOpqkBBrYllxZe4hRkkOJiVR3hNrgUJ8SfkplRmJxRnx RaU5qcWHGCU4mJVEeOXrgXK8KYmVValF+TApaQ4WJXHemxz2QUIC6YklqdmpqQWpRTBZGQ4O JQnehI1AjYJFqempFWmZOSUIaSYOTpDhPEDDu0BqeIsLEnOLM9Mh8qcYFaXEeetBEgIgiYzS PLheWLS/YhQHekWYNx2kigeYKOC6XwENZgIaHFwBNrgkESEl1cA4kyFAg3Oq2IOpXic2z353 NGmHe13Ay9hyDva/K1f/2G3BbGyu+LSQdfu/3lQby44ZRl4G37e6LHvyQffxa9YD3YW6cxU2 LHsmrzgpOMz2y1H1pLy0bga+zm+cx8LtJLeu/dETauWt2vDw8vxDK5JenwyYbK+x7vbpL4Eu yYFLblR/nPBuWZGlEktxRqKhFnNRcSIAELP8CtECAAA=
Subject: [kitten] New Version Notification for draft-kaduk-kitten-gss-loop-02.txt (fwd)
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Jan 2014 21:55:24 -0000

I made some minor edits to the body text and trimmed down the sample code 
to be more consistent with Greg's suggestions.  I think Greg wants the 
sample code trimmed even further (i.e., to not have anything in the bodies 
of the {send,receive}_token functions, and possibly not have them at all, 
but I prefer to be more concrete.

Is it reasonable to adopt this document as a working-group draft at this 
time?

I am becoming more convinced that we should have Java sample code as well 
as C, but due to some computer issues I don't have a java development 
environment available at the moment.  My Java is also quite rusty, so if 
someone else wants to chip in, that would be great.

Finally, the C sample code has a comment (in two places, actually):
/* It is safe to call gss_release_buffer twice on the same buffer. */
This could potentially be misleading, as I believe our conclusion was that 
2743/2744 do not explicitly require this to be safe.  However, we believe 
that it is safe in all known implementations, and that an implementation 
where it was not safe would be very difficult to use correctly.  Is it 
reasonable to leave this comment in place under the reasoning that it is 
describing the assumptions made by the sample code (as opposed to 
describing the behavior mandated by the specification)?

Thanks,

Ben

---------- Forwarded message ----------
Date: Tue, 14 Jan 2014 13:27:45 -0800
From: internet-drafts@ietf.org
To: Benjamin Kaduk <kaduk@mit.edu>, Benjamin Kaduk <kaduk@mit.edu>
Subject: New Version Notification for draft-kaduk-kitten-gss-loop-02.txt


A new version of I-D, draft-kaduk-kitten-gss-loop-02.txt
has been successfully submitted by Benjamin Kaduk and posted to the
IETF repository.

Name:		draft-kaduk-kitten-gss-loop
Revision:	02
Title:		Structure of the GSS Negotiation Loop
Document date:	2014-01-14
Group:		Individual Submission
Pages:		17
URL:            http://www.ietf.org/internet-drafts/draft-kaduk-kitten-gss-loop-02.txt
Status:         https://datatracker.ietf.org/doc/draft-kaduk-kitten-gss-loop/
Htmlized:       http://tools.ietf.org/html/draft-kaduk-kitten-gss-loop-02
Diff:           http://www.ietf.org/rfcdiff?url2=draft-kaduk-kitten-gss-loop-02

Abstract:
    This document specifies the generic structure of the negotiation loop
    to establish a GSS security context between initiator and acceptor.
    The control flow of the loop is indicated for both parties, including
    error conditions, and indications are given for where application-
    specific behavior must be specified.




Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat