Re: [kitten] Request for feedback: draft-wibrown-ldapssotoken

William Brown <wibrown@redhat.com> Wed, 26 October 2016 23:58 UTC

Return-Path: <wibrown@redhat.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 17B84129880 for <kitten@ietfa.amsl.com>; Wed, 26 Oct 2016 16:58:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.333
X-Spam-Level:
X-Spam-Status: No, score=-7.333 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.431, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RipChiBF6Nvw for <kitten@ietfa.amsl.com>; Wed, 26 Oct 2016 16:58:40 -0700 (PDT)
Received: from mx1.redhat.com (mx1.redhat.com [209.132.183.28]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AD477129625 for <kitten@ietf.org>; Wed, 26 Oct 2016 16:58:40 -0700 (PDT)
Received: from int-mx09.intmail.prod.int.phx2.redhat.com (int-mx09.intmail.prod.int.phx2.redhat.com [10.5.11.22]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 6EC918124D for <kitten@ietf.org>; Wed, 26 Oct 2016 23:58:25 +0000 (UTC)
Received: from rei.prd.blackhats.net.au (ovpn-116-15.phx2.redhat.com [10.3.116.15]) by int-mx09.intmail.prod.int.phx2.redhat.com (8.14.4/8.14.4) with ESMTP id u9QNwMeb031196 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for <kitten@ietf.org>; Wed, 26 Oct 2016 19:58:24 -0400
Message-ID: <1477526302.5137.1.camel@redhat.com>
From: William Brown <wibrown@redhat.com>
To: "kitten@ietf.org" <kitten@ietf.org>
Date: Thu, 27 Oct 2016 09:58:22 +1000
In-Reply-To: <1473128531.15290.4.camel@redhat.com>
References: <1473028515.26123.44.camel@redhat.com> <900064F9-C173-49DE-9973-F7CE6A3762EE@padl.com> <1473128531.15290.4.camel@redhat.com>
Content-Type: multipart/signed; micalg="pgp-sha1"; protocol="application/pgp-signature"; boundary="=-o7hI0iBfFfHMjIW9EmHw"
Mime-Version: 1.0
X-Scanned-By: MIMEDefang 2.68 on 10.5.11.22
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.25]); Wed, 26 Oct 2016 23:58:25 +0000 (UTC)
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/n-Z_Uzyd4ehthcQniLb6JbUVS34>
Subject: Re: [kitten] Request for feedback: draft-wibrown-ldapssotoken
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 Oct 2016 23:58:42 -0000

On Tue, 2016-09-06 at 12:22 +1000, William Brown wrote:
> On Mon, 2016-09-05 at 11:31 +1000, Luke Howard wrote:
> > Hi William,
> > 
> > It would be worth mentioning in a Security Considerations section that this protocol (like all bearer tokens) is vulnerable to replay attacks.
> > 
> 
> Thank you, this is a excellent point. I have added this section and
> updated the draft.
> 

> 

Hi,

As mentioned I have updated this draft. I would appreciate further
comments and review.

https://tools.ietf.org/html/draft-wibrown-ldapssotoken-01

-- 
Sincerely,

William Brown
Software Engineer
Red Hat, Brisbane