Re: [kitten] Fwd: I-D Action: draft-hansen-scram-sha256-00.txt

Simon Josefsson <simon@josefsson.org> Fri, 11 April 2014 20:45 UTC

Return-Path: <simon@josefsson.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DF7191A074C for <kitten@ietfa.amsl.com>; Fri, 11 Apr 2014 13:45:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level:
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Xo48-vK4Yyty for <kitten@ietfa.amsl.com>; Fri, 11 Apr 2014 13:45:38 -0700 (PDT)
Received: from duva.sjd.se (duva.sjd.se [IPv6:2001:9b0:1:1702::100]) by ietfa.amsl.com (Postfix) with ESMTP id 5E6E61A0737 for <kitten@ietf.org>; Fri, 11 Apr 2014 13:45:37 -0700 (PDT)
Received: from latte.josefsson.org (static-213-115-179-130.sme.bredbandsbolaget.se [213.115.179.130]) (authenticated bits=0) by duva.sjd.se (8.14.4/8.14.4/Debian-4) with ESMTP id s3BKjTSF010980 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Fri, 11 Apr 2014 22:45:31 +0200
Date: Fri, 11 Apr 2014 22:45:28 +0200
From: Simon Josefsson <simon@josefsson.org>
To: Tony Hansen <tony@att.com>
Message-ID: <20140411224528.3abf6ee2@latte.josefsson.org>
In-Reply-To: <534844A4.7030304@att.com>
References: <20140411193636.13894.48805.idtracker@ietfa.amsl.com> <534844A4.7030304@att.com>
X-Mailer: Claws Mail 3.8.1 (GTK+ 2.24.10; x86_64-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: clamav-milter 0.98.1 at duva.sjd.se
X-Virus-Status: Clean
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/iwu260PM7QM0ial0YGlifQakpHk
Cc: kitten@ietf.org
Subject: Re: [kitten] Fwd: I-D Action: draft-hansen-scram-sha256-00.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Apr 2014 20:45:40 -0000

You wrote:

> As promised, here is an internet draft to register
> SCRAM-SHA-256[-PLUS].

Thanks.  It looks good to me.  If you are not saying anything about
GSS-API per-message token algorithm, you will end up getting
aes128-cts-hmac-sha1-96 there because that's what RFC 5802 says.  Is
that OK with you?  I don't think there is a SHA2-based Kerberos enctype
registered yet.  I don't see this as a problem, I just wanted to make a
note of it -- some people may consider it a bit misaligned.

/Simon