Re: [kitten] Requesting WG adoption of several SCRAM related documents
Alexey Melnikov <alexey.melnikov@isode.com> Fri, 05 November 2021 11:08 UTC
Return-Path: <alexey.melnikov@isode.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B38C33A0CD2 for <kitten@ietfa.amsl.com>; Fri, 5 Nov 2021 04:08:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.429
X-Spam-Level:
X-Spam-Status: No, score=-5.429 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, NICE_REPLY_A=-3.33, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=isode.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7P4g12X-m4Ko for <kitten@ietfa.amsl.com>; Fri, 5 Nov 2021 04:08:49 -0700 (PDT)
Received: from waldorf.isode.com (waldorf.isode.com [62.232.206.188]) by ietfa.amsl.com (Postfix) with ESMTP id 876053A0CD1 for <kitten@ietf.org>; Fri, 5 Nov 2021 04:08:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1636110524; d=isode.com; s=june2016; i=@isode.com; bh=jwd2LSaReEleeBSbhnENpwtcSEDO2s0uLaOrAU4WKjM=; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version: In-Reply-To:References:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description; b=CpsO0Hv79YNMXWs0xg94JjDOyO4HsaWlyFczqDhoAia/yc2QBVHqS0bUl2alWNn4jYcLcc M91PsvdLrvHpBibZVliOkazJffeqcAGUm+M+5Kn5D0jhJl/lSax99byzPrE45YSAP6k7V+ t7mSjhrL6bxVawaYOcRD7Cl884yZCa8=;
Received: from [192.168.1.222] (host5-81-100-95.range5-81.btcentralplus.com [5.81.100.95]) by waldorf.isode.com (submission channel) via TCP with ESMTPSA id <YYUQvAAF4ju6@waldorf.isode.com>; Fri, 5 Nov 2021 11:08:44 +0000
To: Sam Whited <sam@samwhited.com>, KITTEN Working Group <kitten@ietf.org>
References: <jlgpmrhi189.fsf@redhat.com> <139AC3E2-92B1-433A-A8AE-28C7DECFB619@josefsson.org> <72bf2b21-86db-4975-ab8f-b367d863f1f0@www.fastmail.com>
From: Alexey Melnikov <alexey.melnikov@isode.com>
Message-ID: <ed2cbbaf-98bc-ea16-8c48-b3ddb02c845a@isode.com>
Date: Fri, 05 Nov 2021 11:08:42 +0000
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Thunderbird/78.14.0
In-Reply-To: <72bf2b21-86db-4975-ab8f-b367d863f1f0@www.fastmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-GB
Content-transfer-encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/qaeLYBjuUMwrx4lM7J0h942lNR4>
Subject: Re: [kitten] Requesting WG adoption of several SCRAM related documents
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Nov 2021 11:08:55 -0000
On 04/11/2021 12:06, Sam Whited wrote: > Having reconsidered this in light of some of these comments, I think I > agree in terms of SCRAM-SHA-512 and SCRAM-SHA3. While I'm certainly not > *against* publishing these mechanisms (as I mentioned, I have > implemented them and used them already in some places) I do think SCRAM-SHA- > 256, for example, is likely strong enough for now. I am happy to defer decision on bringing them into the WG till a later date. > It doesn't show any > signs of weakness, so we might want to focus on a mechanism that has its > own hash/CB negotiation instead and is extensible enough to add 2FA > later (or whatever other requirements this group comes up with: better > hash agility comes to mind). I suppose I've changed to being neutral on > publishing the new SCRAM mechanisms. > > As for the 2FA document I think that represents something that's missing > from *current* mechanisms and should likely move forward. If we were to > focus on new mechanisms that could implement 2FA I think we'd be doing a > disservice to existing SASL/SCRAM users who may not be able to evaluate > and update to a new mechanism, but may be able to add 2FA to their > existing setup more quickly. I feel the same. So my update proposal is to work on the following in the WG: 1) SCRAM 2FA extension 2) Something like draft-cridland-kitten-clientkey for SASL re-authentication that can be used with SCRAM or similar mechanisms 3) A possible informational document about best SASL implementation practices, in particular how to deal with some SASL mechanisms only being available for some users. Best Regards, Alexey > —Sam > > On Wed, Nov 3, 2021, at 16:31, Simon Josefsson wrote: >> 3 nov. 2021 kl. 17:43 skrev Robbie Harwood <rharwood@redhat.com>: >>> Simon Josefsson <simon@josefsson.org> writes: >>> >>>> Hi. I'm not strongly opposed to these work items, but I do feel >>>> publishing these documents without adressing high-level concerns >>>> have a risk of causing problems during deployment. I think the WG >>>> should understand and consider the implication before adopting the >>>> documents >>>> - maybe there is alternative work that needs to happen >>>> before/instead. >>> Hi Simon, do you have any further thoughts on this in light of >>> Ruslan's and Alexey's comments in reply? >> No. I agree with what the replies, and haven’t changed my opinion. >> I’d rather see work on addressing the problems that were brought >> up, or stronger mechanisms, instead. But things aren’t a zero-sum >> game, so if enough people wants these drafts published, that’s what >> will happen. >> >> /Simon >> _______________________________________________ >> Kitten mailing list Kitten@ietf.org >> https://www.ietf.org/mailman/listinfo/kitten
- [kitten] Requesting WG adoption of several SCRAM … Alexey Melnikov
- Re: [kitten] Requesting WG adoption of several SC… Sam Whited
- Re: [kitten] Requesting WG adoption of several SC… Simon Josefsson
- Re: [kitten] Requesting WG adoption of several SC… Ruslan N. Marchenko
- Re: [kitten] Requesting WG adoption of several SC… Alexey Melnikov
- Re: [kitten] Requesting WG adoption of several SC… Robbie Harwood
- Re: [kitten] Requesting WG adoption of several SC… Simon Josefsson
- Re: [kitten] Requesting WG adoption of several SC… Sam Whited
- Re: [kitten] Requesting WG adoption of several SC… Alexey Melnikov
- Re: [kitten] Requesting WG adoption of several SC… Dave Cridland
- Re: [kitten] Requesting WG adoption of several SC… Alexey Melnikov
- Re: [kitten] Requesting WG adoption of several SC… Dave Cridland
- Re: [kitten] Requesting WG adoption of several SC… Alexey Melnikov
- Re: [kitten] Requesting WG adoption of several SC… Robbie Harwood
- Re: [kitten] Requesting WG adoption of several SC… Ruslan N. Marchenko
- Re: [kitten] Requesting WG adoption of several SC… Dave Cridland