Re: draft-ietf-kitten-rfc2853bis-02 review

Seema Malkani <Seema.Malkani@Sun.COM> Wed, 07 February 2007 00:21 UTC

Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1HEaZR-0001DJ-1U; Tue, 06 Feb 2007 19:21:57 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HEaZQ-0001DE-6b for kitten@ietf.org; Tue, 06 Feb 2007 19:21:56 -0500
Received: from nwk-ea-fw-1.sun.com ([192.18.42.249]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HEaZK-00086u-Fn for kitten@ietf.org; Tue, 06 Feb 2007 19:21:56 -0500
Received: from d1-sfbay-09.sun.com ([192.18.39.119]) by nwk-ea-fw-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l170LkUw009543 for <kitten@ietf.org>; Tue, 6 Feb 2007 16:21:46 -0800 (PST)
Received: from conversion-daemon.d1-sfbay-09.sun.com by d1-sfbay-09.sun.com (Sun Java System Messaging Server 6.2-6.01 (built Apr 3 2006)) id <0JD200501GW5CL00@d1-sfbay-09.sun.com> (original mail from Seema.Malkani@Sun.COM) for kitten@ietf.org; Tue, 06 Feb 2007 16:21:46 -0800 (PST)
Received: from [192.18.60.128] by d1-sfbay-09.sun.com (Sun Java System Messaging Server 6.2-6.01 (built Apr 3 2006)) with ESMTPSA id <0JD200FSRH08P4QI@d1-sfbay-09.sun.com> for kitten@ietf.org; Tue, 06 Feb 2007 16:21:45 -0800 (PST)
Date: Tue, 06 Feb 2007 16:21:40 -0800
From: Seema Malkani <Seema.Malkani@Sun.COM>
In-reply-to: <45C3A94D.1090707@sun.com>
To: Shawn M Emery <Shawn.Emery@Sun.COM>
Message-id: <45C91B94.9030106@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format="flowed"; charset="ISO-8859-15"
Content-transfer-encoding: 7bit
X-Accept-Language: en-us, en
References: <45C3A94D.1090707@sun.com>
User-Agent: Mozilla/5.0 (X11; U; SunOS sun4u; en-US; rv:1.7) Gecko/20041221
X-Spam-Score: 0.0 (/)
X-Scan-Signature: f607d15ccc2bc4eaf3ade8ffa8af02a0
Cc: kitten@ietf.org
Subject: Re: draft-ietf-kitten-rfc2853bis-02 review
X-BeenThere: kitten@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
Reply-To: Seema.Malkani@Sun.COM
List-Id: Common Authentication Technologies - Next Generation <kitten.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/kitten>
List-Post: <mailto:kitten@lists.ietf.org>
List-Help: <mailto:kitten-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@lists.ietf.org?subject=subscribe>
Errors-To: kitten-bounces@lists.ietf.org

Shawn M Emery wrote On 02/02/07 13:12,:

>
> As promised at IETF-68, here is my review of this draft.  I apologize 
> for not doing this sooner.
>
> Overall comments:
>
> Does this draft need to obsolete RFC 2853, but rather just contain the
> corrections/clarifications based from RFC 2743? I think that most of
> the people looking at this document are going to be those you already
> have existing class libraries and will want to know what exactly should
> be changed.

This draft does need to obsolete RFC 2853. The GSS error codes were 
misaligned in the spec, which need to be fixed.

>
> Are there any issues where garbage collection may be indeterministic
> enough for freeing sensitive data?

No. The GC will sweep all objects not referenced. If you are concerned 
about any sensitive data, we do provide API where applicable. For 
instance, we provide an API dispose() to release any system resources.

>
> 4. Additional Controls
> -- 
> Optional services list needs delimiters of item and its definition.
>
> 5.2 Provider Framework
> -- 
> Add comma here:
>
> functionality to the components obtained from providers, the GSS-API
> can be extended to support an arbitrary list of mechanisms.

Will fix it.

>
>
> 5.14 Channel Bindings
> -- 
>
> The channel binding mechanism example is out-dated. Refer to:
> draft-ietf-kitten-gssapi-channel-bindings-02.txt

This draft does not change the Channel Bindings structure. Extensions to 
GSS will be covered separately.

>
> 6.3 GSSCredential interface
> -- 
>
> Should we consider draft-ietf-kitten-gssapi-store-cred-02.txt here/now? 

All GSS extensions will be covered separately.

Thanks,
Seema

_______________________________________________
Kitten mailing list
Kitten@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/kitten