[SPKM] Re: Comments on draft-zhu-pku2u-01.txt

Nicolas Williams <Nicolas.Williams@sun.com> Sat, 17 March 2007 03:27 UTC

Return-path: <spkm-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1HSPZu-0004Av-5T; Fri, 16 Mar 2007 23:27:34 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HSPZs-0004Ab-PA for spkm@ietf.org; Fri, 16 Mar 2007 23:27:32 -0400
Received: from sca-ea-mail-1.sun.com ([192.18.43.24]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HSPZm-0004t8-9M for spkm@ietf.org; Fri, 16 Mar 2007 23:27:32 -0400
Received: from centralmail4brm.central.Sun.COM ([129.147.62.198]) by sca-ea-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id l2H3RPF4021929 for <spkm@ietf.org>; Sat, 17 Mar 2007 03:27:25 GMT
Received: from binky.central.sun.com (binky.Central.Sun.COM [129.153.128.104]) by centralmail4brm.central.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL, v2.2) with ESMTP id l2H3ROAm008750 for <spkm@ietf.org>; Fri, 16 Mar 2007 21:27:25 -0600 (MDT)
Received: from binky.central.sun.com (localhost [127.0.0.1]) by binky.central.sun.com (8.13.8+Sun/8.13.6) with ESMTP id l2H3QjiM022705; Fri, 16 Mar 2007 22:26:45 -0500 (CDT)
Received: (from nw141292@localhost) by binky.central.sun.com (8.13.8+Sun/8.13.8/Submit) id l2H3QhmY022704; Fri, 16 Mar 2007 22:26:43 -0500 (CDT)
X-Authentication-Warning: binky.central.sun.com: nw141292 set sender to Nicolas.Williams@sun.com using -f
Date: Fri, 16 Mar 2007 22:26:43 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: "Liqiang(Larry) Zhu" <lzhu@windows.microsoft.com>
Message-ID: <20070317032642.GH22445@Sun.COM>
Mail-Followup-To: "Liqiang(Larry) Zhu" <lzhu@windows.microsoft.com>, Jeffrey Hutzelman <jhutz@cmu.edu>, Olga Kornievskaia <aglo@citi.umich.edu>, Michael.Eisler@netapp.com, andros@citi.umich.edu, kitten@lists.ietf.org, spkm@ietf.org
References: <45FB0398.3080406@citi.umich.edu> <729D2796944018A823D6E75A@sirius.fac.cs.cmu.edu> <CAAAEFE273EAD341A4B02AAA9CA6F733051CA960@WIN-MSG-20.wingroup.windeploy.ntdev.microsoft.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <CAAAEFE273EAD341A4B02AAA9CA6F733051CA960@WIN-MSG-20.wingroup.windeploy.ntdev.microsoft.com>
User-Agent: Mutt/1.5.7i
X-Spam-Score: 0.0 (/)
X-Scan-Signature: d6b246023072368de71562c0ab503126
Cc: kitten@lists.ietf.org, andros@citi.umich.edu, Olga Kornievskaia <aglo@citi.umich.edu>, Michael.Eisler@netapp.com, spkm@ietf.org, Jeffrey Hutzelman <jhutz@cmu.edu>
Subject: [SPKM] Re: Comments on draft-zhu-pku2u-01.txt
X-BeenThere: spkm@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Low Infrastructure Public Key GSS mechanism <spkm.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/spkm>, <mailto:spkm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/spkm>
List-Post: <mailto:spkm@ietf.org>
List-Help: <mailto:spkm-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/spkm>, <mailto:spkm-request@ietf.org?subject=subscribe>
Errors-To: spkm-bounces@ietf.org

On Fri, Mar 16, 2007 at 07:01:09PM -0700, Liqiang(Larry) Zhu wrote:
> Jeff wrote:
> > This is a good point.  GSS_S_CONTINUE_NEEDED indicates that it will be
> 
> > necessary to make the call again with another token provided by the
> peer. 
> > When GSS_Init_sec_context or GSS_Accept_sec_context emits an error
> token, 
> > it should also return an appropriate error status, not 
> > GSS_S_CONTINUE_NEEDED.
> 
> This is not necessary accurate. In the User2User protocol,
> http://www.watersprings.org/pub/id/draft-swift-win2k-krb-user2user-03.tx
> t,
> the server can return a KRB_ERROR with the GSS_S_CONTINUE_NEEDED status.

Where does GSS_S_CONTINUE_NEEDED appear in the KRB-ERROR??  Normally
status codes like GSS_S_CONTINUE_NEEDED are not sent in a mechanism
token -- they are implied.

_______________________________________________
SPKM mailing list
SPKM@ietf.org
https://www1.ietf.org/mailman/listinfo/spkm