[sasl] [Editorial Errata Reported] RFC5802 (2640)

RFC Errata System <rfc-editor@rfc-editor.org> Mon, 22 November 2010 10:47 UTC

Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: sasl@core3.amsl.com
Delivered-To: sasl@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 0EBE13A6919 for <sasl@core3.amsl.com>; Mon, 22 Nov 2010 02:47:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.352
X-Spam-Level:
X-Spam-Status: No, score=-102.352 tagged_above=-999 required=5 tests=[AWL=0.248, BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6nnrsRfFxNls for <sasl@core3.amsl.com>; Mon, 22 Nov 2010 02:47:02 -0800 (PST)
Received: from rfc-editor.org (rfc-editor.org [IPv6:2001:1890:1112:1::2f]) by core3.amsl.com (Postfix) with ESMTP id 54EE33A6A57 for <sasl@ietf.org>; Mon, 22 Nov 2010 02:47:02 -0800 (PST)
Received: by rfc-editor.org (Postfix, from userid 30) id 05AE8E06B1; Mon, 22 Nov 2010 02:47:58 -0800 (PST)
To: chris.newman@oracle.com, ams@toroid.org, Alexey.Melnikov@isode.com, Nicolas.Williams@oracle.com, turners@ieca.com, tim.polk@nist.gov, tlyu@mit.edu, kurt.zeilenga@isode.com
From: RFC Errata System <rfc-editor@rfc-editor.org>
Message-Id: <20101122104758.05AE8E06B1@rfc-editor.org>
Date: Mon, 22 Nov 2010 02:47:58 -0800
X-Mailman-Approved-At: Mon, 22 Nov 2010 12:24:42 -0800
Cc: sasl@ietf.org, jehan@zemarmot.net, rfc-editor@rfc-editor.org
Subject: [sasl] [Editorial Errata Reported] RFC5802 (2640)
X-BeenThere: sasl@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: SASL Working Group <sasl.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/sasl>, <mailto:sasl-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sasl>
List-Post: <mailto:sasl@ietf.org>
List-Help: <mailto:sasl-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sasl>, <mailto:sasl-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Nov 2010 10:47:03 -0000

The following errata report has been submitted for RFC5802,
"Salted Challenge Response Authentication Mechanism (SCRAM) SASL and GSS-API Mechanisms".

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=5802&eid=2640

--------------------------------------
Type: Editorial
Reported by: Jehan Pagès <jehan@zemarmot.net>

Section: 5

Original Text
-------------
The server verifies the nonce and the proof, verifies that the
authorization identity (if supplied by the client in the first
message) is authorized to act as the authentication identity, and,
finally, it responds with a "server-final-message", concluding the
authentication exchange.



Corrected Text
--------------
The server verifies the nonce and the proof, verifies that the
authentication identity is authorized to act as the authorization
identity (if supplied by the client in the first message) , and,
finally, it responds with a "server-final-message", concluding the
authentication exchange.

Notes
-----
It is the authentication identity which acts as (if authorized to) the authorization identity, not the opposite.

Instructions:
-------------
This errata is currently posted as "Reported". If necessary, please
use "Reply All" to discuss whether it should be verified or
rejected. When a decision is reached, the verifying party (IESG)
can log in to change the status and edit the report, if necessary. 

--------------------------------------
RFC5802 (draft-ietf-sasl-scram-11)
--------------------------------------
Title               : Salted Challenge Response Authentication Mechanism (SCRAM) SASL and GSS-API Mechanisms
Publication Date    : July 2010
Author(s)           : C. Newman, A. Menon-Sen, A. Melnikov, N. Williams
Category            : PROPOSED STANDARD
Source              : Simple Authentication and Security Layer
Area                : Security
Stream              : IETF
Verifying Party     : IESG