Re: [kitten] Comments on draft-ietf-kitten-password-storage-04

Sam Whited <sam@samwhited.com> Tue, 06 April 2021 11:55 UTC

Return-Path: <sam@samwhited.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E31B73A211D for <kitten@ietfa.amsl.com>; Tue, 6 Apr 2021 04:55:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.12
X-Spam-Level:
X-Spam-Status: No, score=-2.12 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=samwhited.com header.b=RbWeXfK4; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=Ni1dLPGh
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 83pRqk9u6aCs for <kitten@ietfa.amsl.com>; Tue, 6 Apr 2021 04:55:30 -0700 (PDT)
Received: from wout1-smtp.messagingengine.com (wout1-smtp.messagingengine.com [64.147.123.24]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 41DAF3A1F9E for <kitten@ietf.org>; Tue, 6 Apr 2021 04:55:01 -0700 (PDT)
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.west.internal (Postfix) with ESMTP id CE9971396; Tue, 6 Apr 2021 07:54:57 -0400 (EDT)
Received: from imap34 ([10.202.2.84]) by compute4.internal (MEProxy); Tue, 06 Apr 2021 07:54:57 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=samwhited.com; h=mime-version:message-id:in-reply-to:references:date:from:to :cc:subject:content-type:content-transfer-encoding; s=fm2; bh=ZG a72hhn4fcv6LqUyticQWVD7LwZXo2BzaW93InwMjY=; b=RbWeXfK4Pt1rNXbSXd DJMOVYcY4p03udg7gajQKBEbYJsoTIruevucdAOoBSwgh8Q1PJuwqcLbKyrd+kin rMwRu3GksdE9pR/el7ENrBIr+EaNbAz0HY9NxHtajT1yzNNm/sW0vwbUTZl0Ts+z wtYA2IxtpbJkGrkmN2xvl9lCFwB0gYGeE3D9eZD10ADcDo3WQbhxK7cd6ssByywb NEemhs2/x2KlSrHinWIMA/cqf+XM6cI3KzH1JUrhXyHWBPfuhGHp5zjn19LhA6HH l+o5xDpGgKr2M5NNN4UKBTD+ATeFtbSpDNB2KgTuW8Tp83DfIJXudUlo6PzWCQYW m9vg==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm2; bh=ZGa72hhn4fcv6LqUyticQWVD7LwZXo2BzaW93InwM jY=; b=Ni1dLPGh8AXNc1lLQGQtfHUxKVlrI2thZEvk8jHpmj3sd/UGp2pg55XD/ 8n4Xzlha+M7L2AwIcXIl9tDCXSXd6/FiYyZMIaBSyitpncUiciICoLaOPvERvhv8 EL8FeqqrFKGYjSkFaDoVSuYhirKoM7chGdn12xTw/KvNavPwmSvl/sM89nOVSrSO PLhw9V1/z2wjUHsvAeHbcJmPCDHrR4BA22Md8Y3izWYSuE4RGaoFqwo4etVsqUaq /25aJsSUsSKTpiDrIpvvqaOQN6+kOApbuaAIIEj+IoZUP0sz0oIhpVZayOESZPDB nfjoDGSCbV0waxYTnlhGbLo7RVBGw==
X-ME-Sender: <xms:EUxsYCQr_0wmwAJPnlwUed8QNUbsouBs2rx0DDeZ-xKSuhs0xzF0pg> <xme:EUxsYHzSjU554O67_5k7FrN_W98R8YF510X27jhHbJvaix1S0md61rTURsPcA2vTW WNEcAS_weruDFPqhA>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrudejgedggeegucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhepofgfggfkjghffffhvffutgfgsehtqhertderreejnecuhfhrohhmpedfufgr mhcuhghhihhtvggufdcuoehsrghmsehsrghmfihhihhtvggurdgtohhmqeenucggtffrrg htthgvrhhnpedvffeuvdduhfefvdeiheeukeffhfekjeevgffggedtlefhhffhieevkedu vefhjeenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfhhrohhmpe hsrghmsehsrghmfihhihhtvggurdgtohhm
X-ME-Proxy: <xmx:EUxsYP1eLmefu1x1r6f7iaybnW8kab6VN_P3Zt5mQCkWIC3yE9c6kQ> <xmx:EUxsYOArNdSOk8zJSaPDPwxnZb4D5sT5kgWrugni7pU_IZiUbQeITA> <xmx:EUxsYLiy0g4uqgOZaevKPlN9C-r8j6qkgrbQge0ZCm3hLKwMlb-a7A> <xmx:EUxsYNdYsxWfS7t1oL4JpbrHB-53cYVlLGOhc7JNELJYachCjt68_Q>
Received: by mailuser.nyi.internal (Postfix, from userid 501) id 2B0C9280076; Tue, 6 Apr 2021 07:54:57 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.5.0-alpha0-273-g8500d2492d-fm-20210323.002-g8500d249
Mime-Version: 1.0
Message-Id: <455785b0-db9e-44f7-a1af-78cf3ed206d2@www.fastmail.com>
In-Reply-To: <AA7EE33C-B172-4288-A79E-5039C23A2A33@bluepopcorn.net>
References: <E4D53992-EFFD-4938-8427-D276B5A0A178@bluepopcorn.net> <b72c8211-07ce-467c-9476-faa0354736a1@www.fastmail.com> <AA7EE33C-B172-4288-A79E-5039C23A2A33@bluepopcorn.net>
Date: Tue, 06 Apr 2021 07:54:36 -0400
From: "Sam Whited" <sam@samwhited.com>
To: "Jim Fenton" <fenton@bluepopcorn.net>
Cc: "KITTEN Working Group" <kitten@ietf.org>
Content-Type: text/plain;charset=utf-8
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/k2A6J3YyMNLibwNLt4Uf_FZbvJM>
Subject: Re: [kitten] Comments on draft-ietf-kitten-password-storage-04
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Apr 2021 11:55:40 -0000

I've gone ahead and fixed this as suggested. I set this as a "SHOULD" in
case someone needed backwards compatibility I think, but if it's in this
category a MUST seems appropriate. These are not safe mechanisms.

—Sam

On Mon, Apr 5, 2021, at 23:01, Jim Fenton wrote:
> I haven’t looked at the specific mechanisms that might be marked
> OBSOLETE or LIMITED, but making that a MUST NOT would ensure that
> there aren’t conflicting requirements. If you do want to have one
> requirement refine the other, it would be better put them together and
> connect them with an “and”.