Re: [kitten] I-D Action: draft-ietf-kitten-pkinit-freshness-01.txt

Michiko Short <michikos@microsoft.com> Thu, 12 March 2015 22:27 UTC

Return-Path: <michikos@microsoft.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 221B41A87C3 for <kitten@ietfa.amsl.com>; Thu, 12 Mar 2015 15:27:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id z2jtqLVORfm3 for <kitten@ietfa.amsl.com>; Thu, 12 Mar 2015 15:27:23 -0700 (PDT)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1on0741.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc10::741]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2B94D1A87AE for <kitten@ietf.org>; Thu, 12 Mar 2015 15:27:22 -0700 (PDT)
Received: from BL2PR03MB212.namprd03.prod.outlook.com (10.255.230.151) by BL2PR03MB209.namprd03.prod.outlook.com (10.255.230.140) with Microsoft SMTP Server (TLS) id 15.1.112.13; Thu, 12 Mar 2015 22:27:03 +0000
Received: from BL2PR03MB212.namprd03.prod.outlook.com ([169.254.15.76]) by BL2PR03MB212.namprd03.prod.outlook.com ([169.254.15.76]) with mapi id 15.01.0112.000; Thu, 12 Mar 2015 22:27:03 +0000
From: Michiko Short <michikos@microsoft.com>
To: Benjamin Kaduk <kaduk@MIT.EDU>, Greg Hudson <ghudson@MIT.EDU>, Sam Hartman <hartmans-ietf@mit.edu>
Thread-Topic: [kitten] I-D Action: draft-ietf-kitten-pkinit-freshness-01.txt
Thread-Index: AQHQXCX307vPZrskK0qMbSTckV74FZ0XxPqAgAAGrwCAAaK8oA==
Date: Thu, 12 Mar 2015 22:27:03 +0000
Message-ID: <BL2PR03MB2124E0360819B3162C9E48DD0060@BL2PR03MB212.namprd03.prod.outlook.com>
References: <20150307024328.31740.75123.idtracker@ietfa.amsl.com> <alpine.GSO.1.10.1503111348200.3953@multics.mit.edu> <alpine.GSO.1.10.1503111405000.3953@multics.mit.edu> <5500AD51.5030902@mit.edu> <alpine.GSO.1.10.1503111725490.3953@multics.mit.edu>
In-Reply-To: <alpine.GSO.1.10.1503111725490.3953@multics.mit.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [2001:4898:80e8:ed31::2]
authentication-results: MIT.EDU; dkim=none (message not signed) header.d=none;
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BL2PR03MB209;
x-forefront-antispam-report: BMV:1; SFV:NSPM; SFS:(10019020)(6009001)(51704005)(377454003)(13464003)(24454002)(74316001)(15975445007)(86612001)(2900100001)(2171001)(19580395003)(76576001)(86362001)(76176999)(33656002)(2656002)(62966003)(93886004)(40100003)(92566002)(50986999)(102836002)(230783001)(87936001)(19580405001)(99286002)(46102003)(54356999)(122556002)(77156002)(106116001)(2950100001)(3826002); DIR:OUT; SFP:1102; SCL:1; SRVR:BL2PR03MB209; H:BL2PR03MB212.namprd03.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
x-microsoft-antispam-prvs: <BL2PR03MB2097DBAE31BBCA3500DE602D0060@BL2PR03MB209.namprd03.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(5002009)(5005006); SRVR:BL2PR03MB209; BCL:0; PCL:0; RULEID:; SRVR:BL2PR03MB209;
x-forefront-prvs: 05134F8B4F
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.onmicrosoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 12 Mar 2015 22:27:03.3542 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL2PR03MB209
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/cyi0PNxngvORa38NFkaAV6Dow-I>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-pkinit-freshness-01.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Mar 2015 22:27:25 -0000

Sam,

Are you ok with pulling the client request behavior? 

-----Original Message-----
From: Benjamin Kaduk [mailto:kaduk@MIT.EDU] 
Sent: Wednesday, March 11, 2015 2:26 PM
To: Greg Hudson
Cc: Michiko Short; kitten@ietf.org
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-pkinit-freshness-01.txt

On Wed, 11 Mar 2015, Greg Hudson wrote:

> On Wed, 11 Mar 2015, Benjamin Kaduk wrote:
> > It looks like this addresses all of Greg's questions, so I expect we 
> > will put this in the queue for WGLC.
>
> I still believe that section 2.1 is not necessary; clients should not 
> need to indicate support for PA_AS_FRESHNESS for a KDC to send it the 
> method-data of a preauth-required error.
>
> My last statement on the topic is here:
>
>     http://www.ietf.org/mail-archive/web/kitten/current/msg05326.html

Oops, sorry I missed that.
Yes, I believe you are correct.

-Ben