Re: ietf-nntp My notes from the NNTP WG meeting at the 37thIETF

Jack De Winter <jack@wildbear.on.ca> Fri, 20 December 1996 19:04 UTC

Received: from cnri by ietf.org id aa20087; 20 Dec 96 14:04 EST
Received: from ACADEM2.ACADEM.COM by CNRI.Reston.VA.US id aa17325; 20 Dec 96 14:04 EST
Received: (from majordomo@localhost) by academ2.academ.com (8.8.3/8.7.3) id MAA20345 for ietf-nntp-outgoing; Fri, 20 Dec 1996 12:59:52 -0600 (CST)
X-Authentication-Warning: academ2.academ.com: majordomo set sender to owner-ietf-nntp using -f
Received: from academ.com (root@ACADEM.COM [198.137.249.2]) by academ2.academ.com (8.8.3/8.7.3) with ESMTP id MAA20340 for <ietf-nntp@ACADEM2.ACADEM.COM>; Fri, 20 Dec 1996 12:59:44 -0600 (CST)
Received: from lacroix.wildbear.on.ca (lacroix.wildbear.on.ca [199.246.132.198]) by academ.com (8.8.3/8.7.1) with ESMTP id MAA04469 for <ietf-nntp@academ.com>; Fri, 20 Dec 1996 12:59:33 -0600 (CST)
Received: by lacroix.wildbear.on.ca from localhost (router,SLMailNT V3.0); Fri, 20 Dec 1996 13:52:41 -0500
Received: by lacroix.wildbear.on.ca from wildside.wildbear.on.ca (199.246.132.193::mail daemon,SLMailNT V3.0); Fri, 20 Dec 1996 13:52:41 -0500
Message-Id: <3.0.32.19961220135703.00694ee8@lacroix>
X-Sender: "Jack De Winter" <jack@wildbear.on.ca>
X-Mailer: Windows Eudora Pro Version 3.0 (32)
Date: Fri, 20 Dec 1996 13:57:03 -0500
To: Nat Ballou <NatBa@microsoft.com>, brian@nothing.ucsd.edu, moore@cs.utk.edu
MMDF-Warning: Parse error in original version of preceding line at CNRI.Reston.VA.US
From: Jack De Winter <jack@wildbear.on.ca>
Subject: Re: ietf-nntp My notes from the NNTP WG meeting at the 37thIETF
Cc: ietf-nntp@academ.com
MMDF-Warning: Parse error in original version of preceding line at CNRI.Reston.VA.US
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Comment: No Mime-content-encoding found in headers (although mime headers used), Content-Transfer-Encoding header added by lacroix.wildbear.on.ca (SLMailNT V3.0)
Sender: owner-ietf-nntp@academ.com
Precedence: bulk

At 08:58 AM 12/20/96 -0800, Nat Ballou wrote:
>> As a side note, I submitted the AUTHSASL draft for NNTP extension
>> yesterday and it was published as a draft this morning.  While I
>> see AUTHINFO GENERIC as being good for 'historical' and current
>> implementations, I see John Meyer's SASL work as a good unified
>> security approach.
>
>Actually, I'm totally confused by AUTHSASL proposal.  Why is it not 
>just AUTHINFO GENERIC SASL or something similar?

There is a problem with the AUTHINFO GENERIC command... there is no
specification of mechanisms for it.  If someone is using the AUTHINFO
GENERIC command and has an established set of rules for it, then perhaps
they could share.  Otherwise, it looks like something that may be the
same thing as AUTHSASL, but with no definitions.  As such, someone may
have interpretted it in a different way.  Following all of that, assuming
that someone has done an implementation that may not fit into the same
mold, we don't want to break it for them.

Its mostly a backwards compatibility issue.  From my reading, it looks
like that AUTHINFO GENERIC was supposed to end up being something like
SASL.  After all, it is defined in terms of the IMAP and POP3
authentication mechanisms, which are effectively SASL.  

If we had to do away with AUTHSASL in favour of something else, I would
want it to replace AUTHINFO GENERIC.  As this may cause backwards
compatability issues, I choose to call it something completely different
instead.  Also, there may be compatibility problems as the specification
for GENERIC states that first parameter is the authenticator, and that
may be in question.  There is also the concept of getting a list of the
supported authentication types, etc.

In other words, there are a lot of little things that may get in the
way.  Creating a separate command is a lot easier than worrying about
the legal wrangling in the main document.  Remember, we want to get the
977bis out and then add on to it.

regards,
Jack

-------------------------------------------------
Jack De Winter - Wildbear Consulting, Inc.
(519) 576-3873		http://www.wildbear.on.ca/

Author of SLMail(95/NT) (http://www.seattlelab.com/) and other great products.