Re: [kitten] [IANA #748877] please review SASL-SCRAM-256

Shawn M Emery <shawn.emery@oracle.com> Sun, 16 March 2014 23:55 UTC

Return-Path: <shawn.emery@oracle.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 553F61A0210 for <kitten@ietfa.amsl.com>; Sun, 16 Mar 2014 16:55:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.748
X-Spam-Level:
X-Spam-Status: No, score=-4.748 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.547, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NrR86-TmuWwf for <kitten@ietfa.amsl.com>; Sun, 16 Mar 2014 16:55:03 -0700 (PDT)
Received: from userp1040.oracle.com (userp1040.oracle.com [156.151.31.81]) by ietfa.amsl.com (Postfix) with ESMTP id 52DBC1A020B for <kitten@ietf.org>; Sun, 16 Mar 2014 16:55:03 -0700 (PDT)
Received: from acsinet21.oracle.com (acsinet21.oracle.com [141.146.126.237]) by userp1040.oracle.com (Sentrion-MTA-4.3.2/Sentrion-MTA-4.3.2) with ESMTP id s2GNssMR029335 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK) for <kitten@ietf.org>; Sun, 16 Mar 2014 23:54:55 GMT
Received: from aserz7022.oracle.com (aserz7022.oracle.com [141.146.126.231]) by acsinet21.oracle.com (8.14.4+Sun/8.14.4) with ESMTP id s2GNssLt012467 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for <kitten@ietf.org>; Sun, 16 Mar 2014 23:54:54 GMT
Received: from abhmp0007.oracle.com (abhmp0007.oracle.com [141.146.116.13]) by aserz7022.oracle.com (8.14.4+Sun/8.14.4) with ESMTP id s2GNssiK003256 for <kitten@ietf.org>; Sun, 16 Mar 2014 23:54:54 GMT
Received: from [10.159.120.127] (/10.159.120.127) by default (Oracle Beehive Gateway v4.0) with ESMTP ; Sun, 16 Mar 2014 16:54:53 -0700
Message-ID: <532639C6.40603@oracle.com>
Date: Sun, 16 Mar 2014 17:54:46 -0600
From: Shawn M Emery <shawn.emery@oracle.com>
User-Agent: Mozilla/5.0 (X11; SunOS i86pc; rv:17.0) Gecko/20140222 Thunderbird/17.0.6
MIME-Version: 1.0
To: "kitten@ietf.org" <kitten@ietf.org>
References: <RT-Ticket-748877@icann.org> <5319DE8B.1030202@att.com> <rt-4.0.8-12541-1394569374-953.748877-9-0@icann.org> <20140312162849.152e924b@latte.josefsson.org>
In-Reply-To: <20140312162849.152e924b@latte.josefsson.org>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Source-IP: acsinet21.oracle.com [141.146.126.237]
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/oLF84qjPB7bq4dMgs_jotcuSgPE
Subject: Re: [kitten] [IANA #748877] please review SASL-SCRAM-256
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 16 Mar 2014 23:55:07 -0000

On 03/12/14 09:28 AM, Simon Josefsson wrote:
> Dear all,
>
> We have received a request to register the SCRAM-SHA-256 and
> SCRAM-SHA-256-PLUS mechanism.  According to my understanding of what RFC
> 5802 section 10 says, the registration process is "IETF Review"
> http://tools.ietf.org/html/rfc5226#page-11  which requires an RFC, but I
> may be mistaken.  Anyway, suggestions on how to deal with the
> registration request is appreciated.

Typing as an individual... the mechanism name seems to be very much in 
keeping with guidance provided in 5802 section 4.

> Having a SCRAM with SHA-256 seems like a fairly non-controversial
> thing to me.  There are interop aspects though, and the utility of
> defining a lot of variants could be debated.  I would like to see a
> GSS-API OID registered at the same time for any new SCRAM-SHA-* family
> member, but it seems we forgot to write a policy to make sure that
> happens.  Other thoughts?

I don't envision that there will be a proliferation of SCRAM-SHA-* 
mechanism variations.  Certainly if we can keep to a small set of output 
sizes per algorithm.

Shawn.
-- 
>> Dear Simon,
>>
>> IANA has received a request from Tony Hansen (tony@att.com) for two
>> new registrations in the SASL Mechanisms registry at
>> http://www.iana.org/assignments/sasl-mechanisms.
>>
>> Please let us know when the two-week review period onsasl@ietf.org
>> is complete.
>>
>> thanks,
>>
>> Amanda Baber
>> IANA Request Specialist
>> ICANN
>>
>> ===
>>
>> IANA, please register the following:
>>
>> To:iana@iana.org
>> Subject: Registration of a new SASL mechanism SCRAM-SHA-256
>>
>> SASL mechanism name (or prefix for the family): SCRAM-SHA-256
>> Security considerations: Section 7 of [RFC5802]
>> Published specification (optional, recommended): [RFC5802]
>> Person & email address to contact for further information:
>> IETF SASL WG<kitten@ietf.org>
>> Intended usage: COMMON
>> Owner/Change controller: IESG<iesg@ietf.org>
>> Note:
>>
>> To:iana@iana.org
>> Subject: Registration of a new SASL mechanism SCRAM-SHA-256-PLUS
>>
>> SASL mechanism name (or prefix for the family): SCRAM-SHA-256-PLUS
>> Security considerations: Section 7 of [RFC5802]
>> Published specification (optional, recommended): [RFC5802]
>> Person & email address to contact for further information:
>> IETF SASL WG<kitten@ietf.org>
>> Intended usage: COMMON
>> Owner/Change controller: IESG<iesg@ietf.org>
>> Note:
>>
> _______________________________________________
> Kitten mailing list
> Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten
>
>