Re: [precis] Stephen Farrell's No Objection on draft-ietf-precis-saslprepbis-17: (with COMMENT)

Peter Saint-Andre - &yet <peter@andyet.net> Wed, 27 May 2015 16:19 UTC

Return-Path: <peter@andyet.net>
X-Original-To: precis@ietfa.amsl.com
Delivered-To: precis@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3FBCC1A1F00 for <precis@ietfa.amsl.com>; Wed, 27 May 2015 09:19:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level:
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=unavailable
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CG7U5uZRKTvO for <precis@ietfa.amsl.com>; Wed, 27 May 2015 09:19:22 -0700 (PDT)
Received: from mail-ig0-f172.google.com (mail-ig0-f172.google.com [209.85.213.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C63311A1EEA for <precis@ietf.org>; Wed, 27 May 2015 09:19:19 -0700 (PDT)
Received: by igbpi8 with SMTP id pi8so89183030igb.1 for <precis@ietf.org>; Wed, 27 May 2015 09:19:19 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :cc:subject:references:in-reply-to:content-type :content-transfer-encoding; bh=uo2RrwJ2o3jWDm7uy+V0m6BDuJy76p4M+zbjkWn3q5k=; b=gEpc1fwyRRI0AWGzySt0URAs5IxzfPZO3jMf4pjYd3OwK6RB2xBOQNq5JHeGIkJHza VXR+bdKja7msgmjoqdwRHAPPrJw53ph1sJd5U5n18OJvNBQtd/uDxTXWed66pSORhHFL KJ/6XDvM5KdyXK6leNH80PjVJSMzfb8QF/pYew4E4tRGP/SEAZC/7+wpYsd4cVhxYPzu Bo8e/0cBKVkF3JOloK9RzRpM4bcR1IUl7x7MSxtfd6ElwTETJ06CSDDcRiSpIbvXIYze mXwS4PRd4IWI6PwZtIkB6D0X9wEkieovD4NDewIRYxB6E68zyvwXQuMqZ/VDoUaMHfVs 4dng==
X-Gm-Message-State: ALoCoQl7IgzUK5vssPpDHX27YCmVpYtIiiofdCWEEZXR/eIIoh4+rK0JD2kp28LeZ03fceTDBxXs
X-Received: by 10.42.52.4 with SMTP id h4mr4631283icg.32.1432743559302; Wed, 27 May 2015 09:19:19 -0700 (PDT)
Received: from aither.local (c-73-34-202-214.hsd1.co.comcast.net. [73.34.202.214]) by mx.google.com with ESMTPSA id n14sm13815704ion.5.2015.05.27.09.19.16 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 27 May 2015 09:19:17 -0700 (PDT)
Message-ID: <5565EE83.6070007@andyet.net>
Date: Wed, 27 May 2015 10:19:15 -0600
From: Peter Saint-Andre - &yet <peter@andyet.net>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:31.0) Gecko/20100101 Thunderbird/31.6.0
MIME-Version: 1.0
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>, Alexey Melnikov <alexey.melnikov@isode.com>, The IESG <iesg@ietf.org>
References: <20150527132109.25645.76593.idtracker@ietfa.amsl.com> <5565DB7E.6080508@andyet.net> <5565DEF5.6090405@cs.tcd.ie> <5565E295.1010505@andyet.net> <5565E65D.9030605@andyet.net> <5565E6EB.7010505@isode.com> <5565EB85.2060407@cs.tcd.ie>
In-Reply-To: <5565EB85.2060407@cs.tcd.ie>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/precis/QOxCr9UtOlwbkHMIl_TMsaoxE3I>
Cc: draft-ietf-precis-saslprepbis.ad@ietf.org, precis-chairs@ietf.org, precis@ietf.org, draft-ietf-precis-saslprepbis@ietf.org, draft-ietf-precis-saslprepbis.shepherd@ietf.org
Subject: Re: [precis] Stephen Farrell's No Objection on draft-ietf-precis-saslprepbis-17: (with COMMENT)
X-BeenThere: precis@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Preparation and Comparison of Internationalized Strings <precis.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/precis>, <mailto:precis-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/precis/>
List-Post: <mailto:precis@ietf.org>
List-Help: <mailto:precis-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/precis>, <mailto:precis-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 27 May 2015 16:19:23 -0000

On 5/27/15 10:06 AM, Stephen Farrell wrote:
>
>
> On 27/05/15 16:46, Alexey Melnikov wrote:
>>>
>>> NEW
>>>        Note: Some existing systems allow an empty string in places where
>>>        a password would be expected (e.g., command-line tools that might
>>>        be called from an automated script, or servers that might need to
>>>        be restarted without human intervention).  From the perspective of
>>>        this document (and RFC 4013 before it), these empty strings are
>>>        not passwords but are workarounds for the practical difficulty of
>>>        using passwords in certain scenarios.  The prohibition on zero-
>>>        length passwords is not a recommendation regarding password
>>>        strength (since a password of only one byte is highly insecure),
>>>        but is meant to prevent applications from mistakenly omitting a
>>>        password entirely, since when internationalized characters are
>>>        accepted a non-empty sequence of characters can result in a zero-
>>>        length password after canonicalization.
>> Yes, this looks great. Thank you!
>
> Same here. That's a fine addition I think.

OK, we'll submit a revised I-D after the telechat.

Peter

-- 
Peter Saint-Andre
https://andyet.com/