Re: [kitten] Fwd: [Technical Errata Reported] RFC5801 (2825)

Simon Josefsson <simon@josefsson.org> Wed, 08 June 2011 08:02 UTC

Return-Path: <simon@josefsson.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2559121F855F for <kitten@ietfa.amsl.com>; Wed, 8 Jun 2011 01:02:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -104.599
X-Spam-Level:
X-Spam-Status: No, score=-104.599 tagged_above=-999 required=5 tests=[AWL=-2.000, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id enmLtXt3EK9V for <kitten@ietfa.amsl.com>; Wed, 8 Jun 2011 01:02:28 -0700 (PDT)
Received: from yxa-v.extundo.com (yxa-v.extundo.com [213.115.69.139]) by ietfa.amsl.com (Postfix) with ESMTP id EB23721F843D for <kitten@ietf.org>; Wed, 8 Jun 2011 01:02:24 -0700 (PDT)
Received: from latte.josefsson.org (c80-216-4-108.bredband.comhem.se [80.216.4.108]) (authenticated bits=0) by yxa-v.extundo.com (8.14.3/8.14.3/Debian-5+lenny1) with ESMTP id p58827UZ016370 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Wed, 8 Jun 2011 10:02:09 +0200
From: Simon Josefsson <simon@josefsson.org>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
References: <4DEF26FE.5070904__4175.18786057389$1307518736$gmane$org@cs.tcd.ie>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:110608:kitten@ietf.org::94dxZ8gTeFrnkp7P:33eV
X-Hashcash: 1:22:110608:stephen.farrell@cs.tcd.ie::XvFMTOSVlRVVbScr:1/xC
Date: Wed, 08 Jun 2011 10:02:07 +0200
In-Reply-To: <4DEF26FE.5070904__4175.18786057389$1307518736$gmane$org@cs.tcd.ie> (Stephen Farrell's message of "Wed, 08 Jun 2011 08:38:38 +0100")
Message-ID: <87d3ioycn4.fsf@latte.josefsson.org>
User-Agent: Gnus/5.110018 (No Gnus v0.18) Emacs/23.2 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain
X-Virus-Scanned: clamav-milter 0.97 at yxa-v
X-Virus-Status: Clean
Cc: kitten@ietf.org
Subject: Re: [kitten] Fwd: [Technical Errata Reported] RFC5801 (2825)
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 08 Jun 2011 08:02:29 -0000

Stephen Farrell <stephen.farrell@cs.tcd.ie> writes:

> Hi all,
>
> Can you confirm that this is correct, or not?

I think we could use some more discussion before approving this -- for
example, what impact does this have on existing implementations?

I will try to change my implementation to use 255 instead of 0 and see
if it still works and inteoperates with my old version.  It would be
useful if others could do similar experiments.  I don't expect serious
problems, but I think we should consider the impact before approving
this.

I do agree it is a bug in the specification though.

/Simon

> Thanks,
> S.
>
> -------- Original Message --------
> Subject: [Technical Errata Reported] RFC5801 (2825)
> Date: Tue,  7 Jun 2011 20:58:20 -0700 (PDT)
> From: RFC Errata System <rfc-editor@rfc-editor.org>
> To: simon@josefsson.org, Nicolas.Williams@oracle.com,
> stephen.farrell@cs.tcd.ie, turners@ieca.com, tlyu@mit.edu,
> kurt.zeilenga@isode.com
> CC: thomas.maslen@quest.com, rfc-editor@rfc-editor.org
>
>
> The following errata report has been submitted for RFC5801,
> "Using Generic Security Service Application Program Interface (GSS-API)
> Mechanisms in Simple Authentication and Security Layer (SASL): The GS2
> Mechanism Family".
>
> --------------------------------------
> You may review the report below and at:
> http://www.rfc-editor.org/errata_search.php?rfc=5801&eid=2825
>
> --------------------------------------
> Type: Technical
> Reported by: Thomas Maslen <thomas.maslen@quest.com>
>
> Section: 5.1
>
> Original Text
> -------------
> The initiator-address-type and acceptor-address-type fields of the
> GSS-CHANNEL-BINDINGS structure MUST be set to 0.
>
>
> Corrected Text
> --------------
> The initiator-address-type and acceptor-address-type fields of the
> GSS-CHANNEL-BINDINGS structure MUST be set to 255 (GSS_C_AF_NULLADDR).
>
>
> Notes
> -----
> See RFC 2744, section 3.11, last paragraph:  "[...] or omit addressing
> information, specifying GSS_C_AF_NULLADDR as the address-types".
>
> Appendix A of RFC 2744 specifies that the value of GSS_C_AF_NULLADDR is 255.
>
> Instructions:
> -------------
> This errata is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party (IESG)
> can log in to change the status and edit the report, if necessary.
>
> --------------------------------------
> RFC5801 (draft-ietf-sasl-gs2-20)
> --------------------------------------
> Title               : Using Generic Security Service Application Program
> Interface (GSS-API) Mechanisms in Simple Authentication and Security
> Layer (SASL): The GS2 Mechanism Family
> Publication Date    : July 2010
> Author(s)           : S. Josefsson, N. Williams
> Category            : PROPOSED STANDARD
> Source              : Simple Authentication and Security Layer
> Area                : Security
> Stream              : IETF
> Verifying Party     : IESG