Re: [kitten] I-D Action: draft-ietf-kitten-sasl-saml-ec-01.txt

Simon Josefsson <simon@josefsson.org> Wed, 04 April 2012 14:54 UTC

Return-Path: <simon@josefsson.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7659B21F8693 for <kitten@ietfa.amsl.com>; Wed, 4 Apr 2012 07:54:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -98.886
X-Spam-Level:
X-Spam-Status: No, score=-98.886 tagged_above=-999 required=5 tests=[AWL=-0.836, BAYES_20=-0.74, FH_HOST_EQ_D_D_D_D=0.765, HELO_MISMATCH_COM=0.553, HOST_EQ_STATICB=1.372, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d1zPqTs9a1Ng for <kitten@ietfa.amsl.com>; Wed, 4 Apr 2012 07:54:30 -0700 (PDT)
Received: from yxa-v.extundo.com (static-213-115-179-173.sme.bredbandsbolaget.se [213.115.179.173]) by ietfa.amsl.com (Postfix) with ESMTP id AEEE321F8686 for <kitten@ietf.org>; Wed, 4 Apr 2012 07:54:29 -0700 (PDT)
Received: from latte.josefsson.org (static-213-115-179-130.sme.bredbandsbolaget.se [213.115.179.130]) (authenticated bits=0) by yxa-v.extundo.com (8.14.3/8.14.3/Debian-5+lenny1) with ESMTP id q34EsBTU028567 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Wed, 4 Apr 2012 16:54:13 +0200
From: Simon Josefsson <simon@josefsson.org>
To: "Cantor, Scott" <cantor.2@osu.edu>
References: <CAK3OfOg5UEGPU+YwyeFya4b_hOO5ttO+O2quonYe3YDusJDXSA@mail.gmail.com> <CB72DD0B.16031%cantor.2__3062.16176036305$1330476125$gmane$org@osu.edu>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:120404:kitten@ietf.org::b4/D8040x59AdO5/:CN9
X-Hashcash: 1:22:120404:cantor.2@osu.edu::s/IJp+6TSN3FRt6b:WGH
X-Hashcash: 1:22:120404:jbasney@illinois.edu::hbwN6uFZ220jBBvW:1EHL
X-Hashcash: 1:22:120404:nico@cryptonector.com::lOJ+5uhYTV74wOq9:8iyQ
Date: Wed, 04 Apr 2012 16:54:11 +0200
In-Reply-To: <CB72DD0B.16031%cantor.2__3062.16176036305$1330476125$gmane$org@osu.edu> (Scott Cantor's message of "Wed, 29 Feb 2012 00:41:34 +0000")
Message-ID: <87fwcjlf8s.fsf@latte.josefsson.org>
User-Agent: Gnus/5.130004 (Ma Gnus v0.4) Emacs/24.0.94 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain
X-Virus-Scanned: clamav-milter 0.97.3 at yxa-v
X-Virus-Status: Clean
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-sasl-saml-ec-01.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 04 Apr 2012 14:54:30 -0000

"Cantor, Scott" <cantor.2@osu.edu> writes:

> On 2/28/12 7:31 PM, "Nico Williams" <nico@cryptonector.com> wrote:
>>
>>The GSS-API does not permit empty tokens.  I'm not sure if an initial
>>context token that is empty but for the pseudo-ASN.1 header is OK.
>>However, I think the right thing to do is to add one constant byte to
>>this one token.
>
> I copied that text from the other SAML mechanism (though I don't see it
> there literally anymore), and Simon ok'd it, so I would assume that it is
> ok to omit the constant byte. If not, I'll specify something in the next
> draft.

I think leaving out it should work.  Adding a dummy character is fine
too.  It doesn't matter.

> Also, I'm not sure that OID is "official". In fact, I would guess it's
> not. The SAML mech currently says in draft-09 that the mech OID is TBD, so
> I would imagine this one is too. I can't honestly even say where it came
> from.

The OID is from my tree.  We probably should use IANA's SMI OID number
tree instead.

/Simon