Re: <msg-id> in CRAM-MD5

Lyndon Nerenberg <lyndon@orthanc.ca> Fri, 09 July 2004 21:13 UTC

Received: from above.proper.com (localhost.vpnc.org [127.0.0.1]) by above.proper.com (8.12.11/8.12.9) with ESMTP id i69LDF3F008303; Fri, 9 Jul 2004 14:13:15 -0700 (PDT) (envelope-from owner-ietf-sasl@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.11/8.12.9/Submit) id i69LDFw7008302; Fri, 9 Jul 2004 14:13:15 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-sasl@mail.imc.org using -f
Received: from orthanc.ca (orthanc.ca [209.89.70.53]) by above.proper.com (8.12.11/8.12.9) with ESMTP id i69LD5JF008290 for <ietf-sasl@imc.org>; Fri, 9 Jul 2004 14:13:14 -0700 (PDT) (envelope-from lyndon@orthanc.ca)
Received: from d154-5-18-205.bchsia.telus.net (d154-5-18-205.bchsia.telus.net [154.5.18.205]) (authenticated bits=0) by orthanc.ca (8.12.10/8.12.10) with ESMTP id i69LD59O034589 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 9 Jul 2004 15:13:07 -0600 (MDT) (envelope-from lyndon@orthanc.ca)
Date: Fri, 09 Jul 2004 14:13:00 -0700
From: Lyndon Nerenberg <lyndon@orthanc.ca>
To: "Kurt D. Zeilenga" <Kurt@OpenLDAP.org>
cc: ietf-sasl@imc.org
Subject: Re: <msg-id> in CRAM-MD5
Message-ID: <2147483647.1089382380@d154-5-18-205.bchsia.telus.net>
In-Reply-To: <6.0.1.1.0.20040709122444.04ac1778@127.0.0.1>
References: <6.0.1.1.0.20040310231958.02c45708@127.0.0.1> <2147483647.1089312033@d154-5-18-205.bchsia.telus.net> <6.0.1.1.0.20040709122444.04ac1778@127.0.0.1>
X-Mailer: Mulberry/3.1.1 (Mac OS X)
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
X-Spam-Status: No, hits=-4.9 required=5.0 tests=BAYES_00 autolearn=no version=2.63
X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on orthanc.ca
Sender: owner-ietf-sasl@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-sasl/mail-archive/>
List-ID: <ietf-sasl.imc.org>
List-Unsubscribe: <mailto:ietf-sasl-request@imc.org?body=unsubscribe>

--On 2004-7-9 12:25 PM -0700 "Kurt D. Zeilenga" <Kurt@OpenLDAP.org> 
wrote:

>> challenge = "<" 3*( %21-3B / %3D / %3F-7E ) ">"
>>             ; a bracketed string of printing characters, not
>>             ; containing embedded "<" or ">"
>>
>> and modify the text to emphasize the importance of generating unique
>> challenges, making reference to the historical behaviour.
>
> Seems reasonable to me.

Excellent. I've sent version -03 of the draft off for publication. The 
major changes from -02 are:

- reformatted and edited to put it into the style the RFC Editor 
prefers;

- <challenge> mods as described (explanitory text still to come);

- new and updated examples from Simon. It would be useful if someone 
could contribute an ACAP example (or some other non-IMAP example, and 
which doesn't base64 encode parts of the exchange);

- addressed *most* of Kurt's review comments from his March 10 message 
to the list.

Still to be done:

- Changes from RFC2195;

- the Abstract and Introduction still need work;

- text rational for <challenge>: uniqueness property and historical 
behaviour (and probably a short paragraph under Security 
Considerations).

--lyndon