Re: [kitten] I-D Action: draft-ietf-kitten-pkinit-freshness-04.txt

Michiko Short <michikos@microsoft.com> Mon, 21 March 2016 22:33 UTC

Return-Path: <michikos@microsoft.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 508A412D10E for <kitten@ietfa.amsl.com>; Mon, 21 Mar 2016 15:33:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.003
X-Spam-Level:
X-Spam-Status: No, score=-2.003 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oq5ucPG5orsl for <kitten@ietfa.amsl.com>; Mon, 21 Mar 2016 15:33:22 -0700 (PDT)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2on0140.outbound.protection.outlook.com [65.55.169.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CA8D112D135 for <kitten@ietf.org>; Mon, 21 Mar 2016 15:33:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:To:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=tG5Usyl8/EhWluLLqHKFAjXTacz5YmKeNnvVIR3U6C8=; b=oKjs16P1DsOhOkoCktxPVy54y/IL9FSFUpSGpHWkbVF8l+hQG9aS0rG44OEFsYLWQ/bnv7y08Y5nen9funLFgldKjCXiSujNrsUhPza4bZ0UmjHKq7/u1KICL3OjlgJSDRLy3CmufZo72K5ByMW4/oBb5ZOPW/5Tc50Ny4wi5R4=
Received: from BY1PR03MB1417.namprd03.prod.outlook.com (10.162.127.147) by BN3PR03MB2257.namprd03.prod.outlook.com (10.166.74.18) with Microsoft SMTP Server (TLS) id 15.1.434.16; Mon, 21 Mar 2016 22:33:18 +0000
Received: from BY1PR03MB1417.namprd03.prod.outlook.com ([10.162.127.147]) by BY1PR03MB1417.namprd03.prod.outlook.com ([10.162.127.147]) with mapi id 15.01.0434.021; Mon, 21 Mar 2016 22:33:17 +0000
From: Michiko Short <michikos@microsoft.com>
To: Seth Moore <sethmo@microsoft.com>, Greg Hudson <ghudson@mit.edu>, "kitten@ietf.org" <kitten@ietf.org>
Thread-Topic: [kitten] I-D Action: draft-ietf-kitten-pkinit-freshness-04.txt
Thread-Index: AQHRg5lMzahi3ZDUlUWCTNh7AZqQFp9kLvOAgAAn44CAACU+cA==
Date: Mon, 21 Mar 2016 22:33:16 +0000
Message-ID: <BY1PR03MB141707537FBCC40D52E2877DD08F0@BY1PR03MB1417.namprd03.prod.outlook.com>
References: <20160321174343.31977.39539.idtracker@ietfa.amsl.com> <56F035EF.1030304@mit.edu> <CO2PR03MB22627F7222F6EF5F3EECD005C98F0@CO2PR03MB2262.namprd03.prod.outlook.com>
In-Reply-To: <CO2PR03MB22627F7222F6EF5F3EECD005C98F0@CO2PR03MB2262.namprd03.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: microsoft.com; dkim=none (message not signed) header.d=none;microsoft.com; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [2001:4898:80e8:7::409]
x-ms-office365-filtering-correlation-id: 65ce81a5-1d16-4920-336d-08d351d8cc34
x-microsoft-exchange-diagnostics: 1; BN3PR03MB2257; 5:A2Zb4Dc1HZWYIotz9+yCO3wpZZe/NoRSdiuwF4L0g95zANBVEAhzQyAmP+CTXoSPhLIMRCS7K73ywKYpETeftQSy4Jm9suUUeWQLBhd/3l4nUcM3v4AueyWHfR3pWkRGfi3PyG/Z8SJyYQuTR81+rw==; 24:832wlS9ZHQSe9w4qIB3MxyHnJ1x96GvITbPLlciS9Dh+0SiQGulBIMlvKknZ2YUKEyY2MMpHTRMSoasGbd+Hu08llep88hwK7Z9Y1bUrbI4=
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BN3PR03MB2257;
x-microsoft-antispam-prvs: <BN3PR03MB22578826579F4866463A1861D08F0@BN3PR03MB2257.namprd03.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(61425038)(601004)(2401047)(8121501046)(5005006)(3002001)(10201501046)(61426038)(61427038); SRVR:BN3PR03MB2257; BCL:0; PCL:0; RULEID:; SRVR:BN3PR03MB2257;
x-forefront-prvs: 0888B1D284
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(164054003)(377454003)(13464003)(5008740100001)(92566002)(5003600100002)(230783001)(54356999)(2561002)(2421001)(77096005)(19580395003)(87936001)(81166005)(76176999)(74316001)(2171001)(86362001)(86612001)(8990500004)(76576001)(15975445007)(2950100001)(122556002)(107886002)(50986999)(99286002)(5001770100001)(5004730100002)(33656002)(189998001)(10090500001)(10400500002)(3280700002)(10290500002)(6116002)(5002640100001)(2900100001)(106116001)(102836003)(1220700001)(2906002)(2501003)(19580405001)(3660700001)(5005710100001)(1096002)(586003); DIR:OUT; SFP:1102; SCL:1; SRVR:BN3PR03MB2257; H:BY1PR03MB1417.namprd03.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 21 Mar 2016 22:33:16.7786 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN3PR03MB2257
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/AHgmeDfsAYS_cBKQHBg7uLOXxWM>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-pkinit-freshness-04.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Mar 2016 22:33:24 -0000

Published version 5 with that fix.

-----Original Message-----
From: Kitten [mailto:kitten-bounces@ietf.org] On Behalf Of Seth Moore
Sent: Monday, March 21, 2016 1:20 PM
To: Greg Hudson <ghudson@mit.edu>; kitten@ietf.org
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-pkinit-freshness-04.txt

Thanks, Greg.

I think the RFC reference mix up was due to 6113 discussing retry (Section 2). The actual error is, indeed, defined in 4120  (7.5.9).

Cheers,
Seth

-----Original Message-----
From: Kitten [mailto:kitten-bounces@ietf.org] On Behalf Of Greg Hudson
Sent: Monday, March 21, 2016 10:57 AM
To: kitten@ietf.org
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-pkinit-freshness-04.txt

In section 2.4, I think the cross-reference for KDC_ERR_PREAUTH_FAILED should be RFC 4120; although RFC 6113 elaborates on its use, the initial definition is still in 4120.

Other than that small editorial issue, my two comments to -03 are addressed.

_______________________________________________
Kitten mailing list
Kitten@ietf.org
https://na01.safelinks.protection.outlook.com/?url=https%3a%2f%2fwww.ietf.org%2fmailman%2flistinfo%2fkitten&data=01%7c01%7cmichikos%40microsoft.com%7cb5e550e620d143d7a9cb08d351c638cd%7c72f988bf86f141af91ab2d7cd011db47%7c1&sdata=AhUkMRzx8gVSJ8k%2f9ctr7%2bA6H329ksir3B%2bl9vFOGbA%3d

_______________________________________________
Kitten mailing list
Kitten@ietf.org
https://na01.safelinks.protection.outlook.com/?url=https%3a%2f%2fwww.ietf.org%2fmailman%2flistinfo%2fkitten&data=01%7c01%7cmichikos%40microsoft.com%7cb5e550e620d143d7a9cb08d351c638cd%7c72f988bf86f141af91ab2d7cd011db47%7c1&sdata=AhUkMRzx8gVSJ8k%2f9ctr7%2bA6H329ksir3B%2bl9vFOGbA%3d