Re: [kitten] Comments on draft-ietf-krb-wg-camac-08

Benjamin Kaduk <kaduk@MIT.EDU> Sat, 02 August 2014 02:53 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A8B4A1A0373 for <kitten@ietfa.amsl.com>; Fri, 1 Aug 2014 19:53:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.202
X-Spam-Level:
X-Spam-Status: No, score=-4.202 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ahr3HBF4h7jv for <kitten@ietfa.amsl.com>; Fri, 1 Aug 2014 19:53:13 -0700 (PDT)
Received: from dmz-mailsec-scanner-3.mit.edu (dmz-mailsec-scanner-3.mit.edu [18.9.25.14]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A01661A020A for <kitten@ietf.org>; Fri, 1 Aug 2014 19:53:13 -0700 (PDT)
X-AuditID: 1209190e-f79946d000007db1-57-53dc5297614b
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-3.mit.edu (Symantec Messaging Gateway) with SMTP id 63.A2.32177.7925CD35; Fri, 1 Aug 2014 22:53:11 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id s722rBOi009913 for <kitten@ietf.org>; Fri, 1 Aug 2014 22:53:11 -0400
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id s722r9pZ003329 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Fri, 1 Aug 2014 22:53:11 -0400
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id s722r857004610; Fri, 1 Aug 2014 22:53:08 -0400 (EDT)
Date: Fri, 01 Aug 2014 22:53:08 -0400
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: "kitten@ietf.org" <kitten@ietf.org>
In-Reply-To: <tslha1whwvn.fsf@mit.edu>
Message-ID: <alpine.GSO.1.10.1408012251230.21571@multics.mit.edu>
References: <tslwqax1mhm.fsf@mit.edu> <53D7DBE2.3010105@mit.edu> <ldvfvhgrvzl.fsf@sarnath.mit.edu> <CAK3OfOj=HvzinngO0Gj8kJeV=NGrv2pMvO_PBUPX9moQ4t4nzg@mail.gmail.com> <tslha1whwvn.fsf@mit.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"; format="flowed"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrCIsWRmVeSWpSXmKPExsUixCmqrDs96E6wwZYv+hZHN69icWD0WLLk J1MAYxSXTUpqTmZZapG+XQJXRsOJKewF99kruu7sY2pg/MPaxcjJISFgIrH+5kE2CFtM4sK9 9UA2F4eQwGwmiabFF9khnGOMEvumnGCGcK4zScxvmQPWIiRQL/Ho2RMWEJtFQEvidOdEsLFs AioSM99sBKsREVCX2HtoKliNsICNxJvd88FqOAXUJP7OPs0EYvMKOEqcnLYDattBRokvFzrZ QRKiAjoSq/dPYYEoEpQ4ORNiGbOApcS5P9fZJjAKzEKSmoUktYCRaRWjbEpulW5uYmZOcWqy bnFyYl5eapGusV5uZoleakrpJkZwAEry7WD8elDpEKMAB6MSD6/BvtvBQqyJZcWVuYcYJTmY lER5+czuBAvxJeWnVGYkFmfEF5XmpBYfYpTgYFYS4S1zA8rxpiRWVqUW5cOkpDlYlMR531pb BQsJpCeWpGanphakFsFkZTg4lCR4fwUANQoWpaanVqRl5pQgpJk4OEGG8wANfwNSw1tckJhb nJkOkT/FqMuxaP/LbiYhlrz8vFQpcd45IEUCIEUZpXlwc2CJ4xWjONBbwrxMgUBVPMCkAzfp FdASJqAlNYa3QZaUJCKkpBoYs5idZtlLrKxd52Sz59X3/ftlU0r3LTnw4uwf9w4byYM+qwoc 9xZ9WrfJX3K76qv97X4myz3fSZ5/JKGg6Hqn+fJrps/rN6ibV79NfHu+b+GObfzNIeK7HE3Z vi/9VL3BzNqzqL/nC9Oy2L2Tqi3Kflqaiviu5V9yWLM0dJ5Izff7eoyFwW11SizFGYmGWsxF xYkA3QsTSPcCAAA=
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/H0VdEtUmxRzaXqFKAfXPiF-TzWA
Subject: Re: [kitten] Comments on draft-ietf-krb-wg-camac-08
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 02 Aug 2014 02:53:15 -0000

On Fri, 1 Aug 2014, Sam Hartman wrote:

>>>>>> "Nico" == Nico Williams <nico@cryptonector.com> writes:
>
>    Nico> On Fri, Aug 1, 2014 at 11:54 AM, Tom Yu <tlyu@mit.edu> wrote:
>    >> I agree that AD-CAMMAC should have the same effect on the
>    >> criticality of its contents as AD-KDC-ISSUED.  We can recommend
>    >> that a CAMMAC be put in AD-IF-RELEVANT if it is likely that the
>    >> consuming service won't understand it.  The KDC might have enough
>    >> knowledge of the capabilities of the service that the extra layer
>    >> of wrapping might not be necessary.
>
>    Nico> I agree with this.
>
> I'm fine with this too.

I'm glad to see lots of people chiming in with agreement, but are we all 
clear on what we're agreeing to?

Are we accepting Greg's reading of 4120 section 5.2.6.2, "This element and 
the elements it encapsulates MAY safely be ignored by applications, 
application servers, and KDCs that do not implement this element."

-Ben