Re: [kitten] Éric Vyncke's Abstain on draft-ietf-kitten-krb-spake-preauth-11: (with COMMENT)

Greg Hudson <ghudson@mit.edu> Thu, 18 January 2024 17:49 UTC

Return-Path: <ghudson@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C3703C14F6A7 for <kitten@ietfa.amsl.com>; Thu, 18 Jan 2024 09:49:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.409
X-Spam-Level:
X-Spam-Status: No, score=-4.409 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=mit.edu
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id S0JHb3Y2yE5f for <kitten@ietfa.amsl.com>; Thu, 18 Jan 2024 09:49:52 -0800 (PST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 42060C14F6BD for <kitten@ietf.org>; Thu, 18 Jan 2024 09:49:52 -0800 (PST)
Received: from [100.64.0.1] (pool-173-76-238-212.bstnma.fios.verizon.net [173.76.238.212]) (authenticated bits=0) (User authenticated as ghudson@ATHENA.MIT.EDU) by outgoing.mit.edu (8.14.7/8.12.4) with ESMTP id 40IHnSPb019890 (version=TLSv1/SSLv3 cipher=AES128-GCM-SHA256 bits=128 verify=NOT); Thu, 18 Jan 2024 12:49:40 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mit.edu; s=outgoing; t=1705600181; bh=E/ed1hRZOE6Irwr5TuqbLUDtuWndyKR3bw1cZKv2x24=; h=Message-ID:Date:MIME-Version:Subject:From:Content-Type; b=ZswyluzxraUexUnKYT0RfC0g61tt77HnsLkNc5+5LTwhcTM5vQf7W8P65LvWXkEjN nbqzi3iefsOpQ7OuDjhU2VOLDAwc8co850nYoKxD7+5JYSSXn+vN71WOIpQMhE0e1o 1C45+8vxF6Gxelx523zVeld58LNEhyt3k6zMhP9RV/ZftUH8m24PJ1Vop0OfudearO zhwG9eHOLQSEJA2g2prPFDoRCAUrGHSCbmcjiEmJAObfM4NYFKdfexMIzTlwwT/1Jn d/98cxuV2Fb909C2jpvl3P+d7KoQf+h0FZENyt4qVBAmFyiZl16bI1K01QkVb6NTsS Lm1z+t7C1GPqg==
Message-ID: <f526e7db-8d59-435c-a4d4-b0e24ba51319@mit.edu>
Date: Thu, 18 Jan 2024 12:49:27 -0500
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-US
To: Éric Vyncke <evyncke@cisco.com>, The IESG <iesg@ietf.org>
Cc: draft-ietf-kitten-krb-spake-preauth@ietf.org, kitten-chairs@ietf.org, kitten@ietf.org, Nicolas Williams <nico@cryptonector.com>
References: <170548795493.9233.457004559586916802@ietfa.amsl.com>
From: Greg Hudson <ghudson@mit.edu>
In-Reply-To: <170548795493.9233.457004559586916802@ietfa.amsl.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/ZEuzDS6AxywfmYqF7IHWN6sSv-M>
Subject: Re: [kitten] Éric Vyncke's Abstain on draft-ietf-kitten-krb-spake-preauth-11: (with COMMENT)
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 18 Jan 2024 17:49:56 -0000

On 1/17/24 05:39, Éric Vyncke via Datatracker wrote:
> ## Section 1.2
> 
> `this pre-authentication mechanism`, which one is this ? I guess the Kerberos
> one but it may be worth being clear on "this".

The ID under consideration is wholly devoted to defining a new Kerberos 
pre-authentication mechanism, and that new mechanism is the referent of 
"this pre-authentication mechanism".

The draft currently uses that phrase six times.  I will change each use 
to "the SPAKE pre-authentication mechanism", _except_ for this first 
one, because the resulting sentence would be awkward: "SPAKE was 
selected for the SPAKE pre-authentication mechanism for the following 
properties".  However, I will change "SPAKE was selected" to "SPAKE is 
selected" to make it clear that the sentence is not a historical statement.

(While considering this comment, I noticed that the ID title was just 
"SPAKE pre-authentication".  I will change it to "Kerberos SPAKE 
Pre-Authentication".)

> ## Section 1.3
> 
> Suggest to expand "OTP" at first use.

It's only used the once, so I will expand it to "One-Time Password" and 
dispense with the acronym.