Re: [kitten] New Version Notification for draft-ietf-kitten-iakerb-00.txt

Greg Hudson <ghudson@MIT.EDU> Mon, 06 May 2013 18:02 UTC

Return-Path: <ghudson@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D28B21F84CE for <kitten@ietfa.amsl.com>; Mon, 6 May 2013 11:02:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level:
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NvODmliPV3Bj for <kitten@ietfa.amsl.com>; Mon, 6 May 2013 11:02:30 -0700 (PDT)
Received: from dmz-mailsec-scanner-7.mit.edu (DMZ-MAILSEC-SCANNER-7.MIT.EDU [18.7.68.36]) by ietfa.amsl.com (Postfix) with ESMTP id 0230E21F90DF for <kitten@ietf.org>; Mon, 6 May 2013 11:02:26 -0700 (PDT)
X-AuditID: 12074424-b7f8c6d0000028c4-89-5187f0325bd7
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) by dmz-mailsec-scanner-7.mit.edu (Symantec Messaging Gateway) with SMTP id 12.AE.10436.230F7815; Mon, 6 May 2013 14:02:26 -0400 (EDT)
Received: from outgoing.mit.edu (OUTGOING-AUTH-1.MIT.EDU [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id r46I2PQ1029396 for <kitten@ietf.org>; Mon, 6 May 2013 14:02:25 -0400
Received: from [18.101.8.104] (VPN-18-101-8-104.MIT.EDU [18.101.8.104]) (authenticated bits=0) (User authenticated as ghudson@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id r46I2NFU015144 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Mon, 6 May 2013 14:02:25 -0400
Message-ID: <5187F02F.3070105@mit.edu>
Date: Mon, 06 May 2013 14:02:23 -0400
From: Greg Hudson <ghudson@MIT.EDU>
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:17.0) Gecko/20130404 Thunderbird/17.0.5
MIME-Version: 1.0
To: kitten@ietf.org
References: <20130411064110.29519.54840.idtracker@ietfa.amsl.com> <001201ce3695$c13005e0$439011a0$@augustcellars.com> <005301ce36e6$265d9bd0$7318d370$@augustcellars.com> <51671F8E.3050701@mit.edu> <02cf01ce3a2c$902997a0$b07cc6e0$@augustcellars.com> <3151B618-970E-4F21-9C8C-E21984F9024D@padl.com>
In-Reply-To: <3151B618-970E-4F21-9C8C-E21984F9024D@padl.com>
X-Enigmail-Version: 1.4.6
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrAIsWRmVeSWpSXmKPExsUixG6nrmv0oT3QYOMyVoujm1exODB6LFny kymAMYrLJiU1J7MstUjfLoErY/n/++wFHRwV5xt2MTcwnmHrYuTkkBAwkXg17wKULSZx4d56 IJuLQ0hgH6PEkQkvWSGcY4wSGzecZIRwbjJJ3L/4jAWkhVdATaJv/2NmEJtFQFVi4ctPTCA2 m4CyxMGz38BqRAVCJE5/bmKGqBeUODnzCVhcREBYYvfWd2BxYYEgiQWbDrBALFjBJDFl2VdG kASngI3EsoOnWCDuk5RYNK0TzGYW0JF41/eAGcKWl9j+dg7zBEbBWUh2zEJSNgtJ2QJG5lWM sim5Vbq5iZk5xanJusXJiXl5qUW65nq5mSV6qSmlmxjBAeuisoOx+ZDSIUYBDkYlHl7FU+2B QqyJZcWVuYcYJTmYlER5Od4BhfiS8lMqMxKLM+KLSnNSiw8xSnAwK4nwVq4ByvGmJFZWpRbl w6SkOViUxHmvp9z0FxJITyxJzU5NLUgtgsnKcHAoSfDOBRkqWJSanlqRlplTgpBm4uAEGc4D NHw7SA1vcUFibnFmOkT+FKOilDjv1rdACQGQREZpHlwvLKG8YhQHekUYop0HmIzgul8BDWYC GpzABza4JBEhJdXAOPtA2E5G7fzpz9+YvX6l9FWhK/teyvWvJ7+8ZAow3LChtvLZuqsH7st7 POnNXr3cf0tSxt0u698X7i4s8Txm+nf70gma64uP7fR6sD+4y95tEe9maz2bPzfWHPG+vzuQ kS9LzfKy4bM/PzYt3pXMHdF467Gej+ERWadP7Icmt8bd3hPkELT7CIsSS3FGoqEWc1FxIgDE ZP2rAwMAAA==
Subject: Re: [kitten] New Version Notification for draft-ietf-kitten-iakerb-00.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 May 2013 18:02:36 -0000

Today I did a more careful comparison of draft-zhu-ws-kerb vs.
draft-ietf-kitten-iakerb, and uncovered a second superficial difference.
 draft-zhu-ws-kerb states:

   The initial context establishment token of IAKERB MUST have the
   generic token framing described in section 3.1 of [RFC2743] with the
   mechanism OID being id-kerberos-iakerb, and any subsequent IAKERB
   context establishment token MUST NOT have this token framing.

while draft-kitten-ietf-iakerb states:

   All context establishment token of IAKERB MUST have the generic token
   framing described in section 3.1 of [RFC2743] with the mechanism OID
   being id-kerberos-iakerb.

Luckily, MIT's implementation allows framing to be present for all
context establishment tokens.  This makes the situation tractable; we
can change our code to always generate framing, without breaking
compatibility with ourselves.

I will send a separate message (in a different thread) with a list of
options for handling the compatibility differences.