Re: [kitten] Fwd: [Technical Errata Reported] RFC5801 (2825)

Simon Josefsson <simon@josefsson.org> Mon, 14 November 2011 09:17 UTC

Return-Path: <simon@josefsson.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 11E0321F844E for <kitten@ietfa.amsl.com>; Mon, 14 Nov 2011 01:17:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.754
X-Spam-Level:
X-Spam-Status: No, score=-101.754 tagged_above=-999 required=5 tests=[AWL=-1.845, BAYES_00=-2.599, FH_HOST_EQ_D_D_D_D=0.765, HELO_MISMATCH_COM=0.553, HOST_EQ_STATICB=1.372, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id L3DYmh1iBBHc for <kitten@ietfa.amsl.com>; Mon, 14 Nov 2011 01:17:43 -0800 (PST)
Received: from yxa-v.extundo.com (static-213-115-179-173.sme.bredbandsbolaget.se [213.115.179.173]) by ietfa.amsl.com (Postfix) with ESMTP id 6E11E21F8F10 for <kitten@ietf.org>; Mon, 14 Nov 2011 01:17:00 -0800 (PST)
Received: from latte.josefsson.org (static-213-115-179-130.sme.bredbandsbolaget.se [213.115.179.130]) (authenticated bits=0) by yxa-v.extundo.com (8.14.3/8.14.3/Debian-5+lenny1) with ESMTP id pAE9GYtj023689 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Mon, 14 Nov 2011 10:16:36 +0100
From: Simon Josefsson <simon@josefsson.org>
To: Shawn M Emery <shawn.emery@oracle.com>
References: <4DEF26FE.5070904__4175.18786057389$1307518736$gmane$org@cs.tcd.ie> <87d3ioycn4.fsf@latte.josefsson.org> <4DEF48C0.3000508@cs.tcd.ie> <4EBF2B2A.8000602@cs.tcd.ie> <4EC0CB2F.10706__31780.7765132331$1321257821$gmane$org@oracle.com>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:111114:kitten@ietf.org::jlpot5ryvGglzZTA:BBdO
X-Hashcash: 1:22:111114:shawn.emery@oracle.com::ZvsyXEARCEIIuJUA:BhZ2
Date: Mon, 14 Nov 2011 10:16:34 +0100
In-Reply-To: <4EC0CB2F.10706__31780.7765132331$1321257821$gmane$org@oracle.com> (Shawn M. Emery's message of "Mon, 14 Nov 2011 01:02:55 -0700")
Message-ID: <874ny783nx.fsf@latte.josefsson.org>
User-Agent: Gnus/5.110018 (No Gnus v0.18) Emacs/24.0.91 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain
X-Virus-Scanned: clamav-milter 0.97.3 at yxa-v
X-Virus-Status: Clean
Cc: kitten@ietf.org
Subject: Re: [kitten] Fwd: [Technical Errata Reported] RFC5801 (2825)
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Nov 2011 09:17:46 -0000

Shawn M Emery <shawn.emery@oracle.com> writes:

> On 11/12/11 7:27 PM, Stephen Farrell wrote:
>> Folks,
>>
>> Not being on the top of anyone's list, this doesn't
>> seem to have progressed since June.
>>
>> Can we resolve this on the list or at this week's
>> meeting?
>
> Let's discuss this during the session.
>
> Simon,
>
> What was the result of your tests running against the updated version
> of GNU SASL?

I must admit that I forgot about this.  GNU SASL still populate the
initiator-address-type and acceptor-address-type fields to 0.

Did any other implementers experiment with changing this?

I'm a bit uncertain how to test this properly, just modifying GNU SASL
to use 0 instead of 255 will likely work running against itself, but the
bigger question is probably if any interoperability between the old
variant and the new variant is affect, and if the choice of GSS-API
library has any bearing of the outcome.  Or even GS2 implementation.

I still agree that it is a bug in the specification though.  If you want
to see a resolution to this errata report now, I suggest to approve it
and we'll figure out if there are any interop issues later on.  You can
always update the errata later on if that turns out to be the case.

/Simon

> Shawn.
> --
>> On 06/08/2011 11:02 AM, Stephen Farrell wrote:
>>>
>>>
>>> On 08/06/11 09:02, Simon Josefsson wrote:
>>>> Stephen Farrell<stephen.farrell@cs.tcd.ie>  writes:
>>>>
>>>>> Hi all,
>>>>>
>>>>> Can you confirm that this is correct, or not?
>>>>
>>>> I think we could use some more discussion before approving this -- for
>>>> example, what impact does this have on existing implementations?
>>>
>>> Good point. I'm fine with waiting for the WG to give me the
>>> answer that I'll cut'n'paste into the errata tool:-) Sooner
>>> is of course better for that.
>>>
>>> Thanks,
>>> S.
>>>
>>>>
>>>> I will try to change my implementation to use 255 instead of 0 and see
>>>> if it still works and inteoperates with my old version.  It would be
>>>> useful if others could do similar experiments.  I don't expect serious
>>>> problems, but I think we should consider the impact before approving
>>>> this.
>>>>
>>>> I do agree it is a bug in the specification though.
>>>>
>>>> /Simon
>>>>
>>>>> Thanks,
>>>>> S.
>>>>>
>>>>> -------- Original Message --------
>>>>> Subject: [Technical Errata Reported] RFC5801 (2825)
>>>>> Date: Tue,  7 Jun 2011 20:58:20 -0700 (PDT)
>>>>> From: RFC Errata System<rfc-editor@rfc-editor.org>
>>>>> To: simon@josefsson.org, Nicolas.Williams@oracle.com,
>>>>> stephen.farrell@cs.tcd.ie, turners@ieca.com, tlyu@mit.edu,
>>>>> kurt.zeilenga@isode.com
>>>>> CC: thomas.maslen@quest.com, rfc-editor@rfc-editor.org
>>>>>
>>>>>
>>>>> The following errata report has been submitted for RFC5801,
>>>>> "Using Generic Security Service Application Program Interface
>>>>> (GSS-API)
>>>>> Mechanisms in Simple Authentication and Security Layer (SASL): The GS2
>>>>> Mechanism Family".
>>>>>
>>>>> --------------------------------------
>>>>> You may review the report below and at:
>>>>> http://www.rfc-editor.org/errata_search.php?rfc=5801&eid=2825
>>>>>
>>>>> --------------------------------------
>>>>> Type: Technical
>>>>> Reported by: Thomas Maslen<thomas.maslen@quest.com>
>>>>>
>>>>> Section: 5.1
>>>>>
>>>>> Original Text
>>>>> -------------
>>>>> The initiator-address-type and acceptor-address-type fields of the
>>>>> GSS-CHANNEL-BINDINGS structure MUST be set to 0.
>>>>>
>>>>>
>>>>> Corrected Text
>>>>> --------------
>>>>> The initiator-address-type and acceptor-address-type fields of the
>>>>> GSS-CHANNEL-BINDINGS structure MUST be set to 255 (GSS_C_AF_NULLADDR).
>>>>>
>>>>>
>>>>> Notes
>>>>> -----
>>>>> See RFC 2744, section 3.11, last paragraph:  "[...] or omit addressing
>>>>> information, specifying GSS_C_AF_NULLADDR as the address-types".
>>>>>
>>>>> Appendix A of RFC 2744 specifies that the value of
>>>>> GSS_C_AF_NULLADDR is 255.
>>>>>
>>>>> Instructions:
>>>>> -------------
>>>>> This errata is currently posted as "Reported". If necessary, please
>>>>> use "Reply All" to discuss whether it should be verified or
>>>>> rejected. When a decision is reached, the verifying party (IESG)
>>>>> can log in to change the status and edit the report, if necessary.
>>>>>
>>>>> --------------------------------------
>>>>> RFC5801 (draft-ietf-sasl-gs2-20)
>>>>> --------------------------------------
>>>>> Title               : Using Generic Security Service Application
>>>>> Program
>>>>> Interface (GSS-API) Mechanisms in Simple Authentication and Security
>>>>> Layer (SASL): The GS2 Mechanism Family
>>>>> Publication Date    : July 2010
>>>>> Author(s)           : S. Josefsson, N. Williams
>>>>> Category            : PROPOSED STANDARD
>>>>> Source              : Simple Authentication and Security Layer
>>>>> Area                : Security
>>>>> Stream              : IETF
>>>>> Verifying Party     : IESG
>>>>
>>> _______________________________________________
>>> Kitten mailing list
>>> Kitten@ietf.org
>>> https://www.ietf.org/mailman/listinfo/kitten
>>>
>> _______________________________________________
>> Kitten mailing list
>> Kitten@ietf.org
>> https://www.ietf.org/mailman/listinfo/kitten