Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.txt

Alexey Melnikov <Alexey.Melnikov@isode.com> Wed, 08 October 2003 13:58 UTC

Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h98DwCKP047147 for <ietf-sasl-bks@above.proper.com>; Wed, 8 Oct 2003 06:58:12 -0700 (PDT) (envelope-from owner-ietf-sasl@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h98DwCW6047146 for ietf-sasl-bks; Wed, 8 Oct 2003 06:58:12 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-sasl@mail.imc.org using -f
Received: from rufus.isode.com (rufus.isode.com [62.3.217.251]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h98DwBKP047141 for <ietf-sasl@imc.org>; Wed, 8 Oct 2003 06:58:11 -0700 (PDT) (envelope-from Alexey.Melnikov@isode.com)
Received: from isode.com (shiny.isode.com [62.3.217.250]) by rufus.isode.com via TCP (with SMTP (internal)) with ESMTP; Wed, 8 Oct 2003 14:58:10 +0100
Message-ID: <3F8417F0.6000407@isode.com>
Date: Wed, 08 Oct 2003 14:58:08 +0100
From: Alexey Melnikov <Alexey.Melnikov@isode.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: "Kurt D. Zeilenga" <Kurt@OpenLDAP.org>
CC: ietf-sasl@imc.org
Subject: Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.txt
References: <5.2.0.9.0.20030915103818.03b51a88@127.0.0.1> <6.0.0.22.0.20031001100505.03e9ffd0@127.0.0.1>
In-Reply-To: <6.0.0.22.0.20031001100505.03e9ffd0@127.0.0.1>
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-sasl@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-sasl/mail-archive/>
List-ID: <ietf-sasl.imc.org>
List-Unsubscribe: <mailto:ietf-sasl-request@imc.org?body=unsubscribe>

Kurt D. Zeilenga wrote:

>>7.    The EXTERNAL mechanism
>>
>>  The mechanism name associated with external authentication is
>>  "EXTERNAL".
>>
>>  The client sends an initial response with the UTF-8 encoding of the
>>  authorization identity. The form of the authorization identity is
>>  further restricted by the application-level protocol's SASL profile.
>>
>>  The server uses information, external to SASL, to determine whether
>>  the client is authorized to authenticate as the authorization
>>  identity.
>>    
>>
>
>It may be appropriate to note that the client can make no
>assumptions as what information the server uses in determining
>client authorization.  E.g., just because TLS was established,
>doesn't mean the server will use TLS-provided information.
>  
>
Done. The new text reads:

The system providing this external information may be, for example,
IPSec or TLS. However, the client can make no assumptions as to what
information the server can use in determining client authorization.
E.g., just because TLS was established, doesn't mean that the server
will use the information provided by TLS.

>>7.2.  Example
>>
>>  The following is an example of an EXTERNAL authentication in the SMTP
>>  protocol [SMTP-AUTH].
>>    
>>
>
>Replace [SMTP-AUTH] with an informative reference to the SMTP base
>specification.  Insert [SMTP-AUTH] after the word "profile" below.
>
Done.

Alexey