Re: [TLS] Re: Comments on draft-santesson-tls-ume-04/draft-santesson-tls-supp-00

Eric Rescorla <ekr@raman.networkresonance.com> Tue, 18 April 2006 18:05 UTC

Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1FVuZw-0003hi-E7; Tue, 18 Apr 2006 14:05:32 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1FVuZv-0003gH-Dg; Tue, 18 Apr 2006 14:05:31 -0400
Received: from raman.networkresonance.com ([198.144.196.3]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1FVuZu-00061e-2n; Tue, 18 Apr 2006 14:05:31 -0400
Received: by raman.networkresonance.com (Postfix, from userid 1001) id BED901E8C1F; Tue, 18 Apr 2006 11:05:29 -0700 (PDT)
To: "Stefan Santesson" <stefans@microsoft.com>
Subject: Re: [TLS] Re: Comments on draft-santesson-tls-ume-04/draft-santesson-tls-supp-00
References: <BF9309599A71984CAC5BAC5ECA62994404AA28B7@EUR-MSG-11.europe.corp.microsoft.com>
From: Eric Rescorla <ekr@raman.networkresonance.com>
Date: Tue, 18 Apr 2006 11:05:29 -0700
In-Reply-To: <BF9309599A71984CAC5BAC5ECA62994404AA28B7@EUR-MSG-11.europe.corp.microsoft.com> (Stefan Santesson's message of "Tue, 18 Apr 2006 18:56:59 +0100")
Message-ID: <861wvubvyu.fsf@raman.networkresonance.com>
User-Agent: Gnus/5.1007 (Gnus v5.10.7) XEmacs/21.4.18 (berkeley-unix)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 82c9bddb247d9ba4471160a9a865a5f3
Cc: iesg@ietf.org, tls@ietf.org
X-BeenThere: tls@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
Reply-To: EKR <ekr@networkresonance.com>
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/tls>
List-Post: <mailto:tls@lists.ietf.org>
List-Help: <mailto:tls-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@lists.ietf.org?subject=subscribe>
Errors-To: tls-bounces@lists.ietf.org

"Stefan Santesson" <stefans@microsoft.com> writes:

>> Eric:
>> 
>> >These drafts seem basically sound. Minor comments below.
>> >
>> >-tls-supp:
>> >You should state that only one SupplementalData field may
>> >be used per handshake.
>> 
>> I agree.  This was pointed out by the Gen-ART reviewer too.
>> 
>
> [Stefan] I've put this on my change log. To be precise in words, should
> the text state that "The client and server MUST NOT send more than one
> supplementalData handshake message each."?

Yes, I think that's right.


>> This is being discussed.  The reason that I would like to see it as
>> standards-track is that the structure supports more than just
>> Microsoft names.  The Microsoft names are simply the first ones that
>> are supported.
>> 
> [Stefan] A agree to the proposed path of the reason stated by Russ. I'm
> willing to tune down the mentioning of Microsoft as it isn't necessary
> for the syntax definitions of this document.

That doesn't really resolve my issue, because it still results in
incompletely specified semantics.


>> >You can do the UPN hint extension exchange and then NOT
>> >send supp_data? That seems wrong.
>> 
>> I agree, if the negotiation is successful, then the supplemental data
>> should be sent.
>> 
> [Stefan] I don't see much value in this direction as the server MUST be
> prepared for the case where the client chooses not to send any hint. It
> may have come to the conclusion that this is not the right server to
> send the hint it intended for some reason. Another reason may be that
> the user has declined sending his user name to this server in a user
> dialog box.
>
> I view sending of hints as completely voluntary at the discretion of the
> client. Even after extension exchange.

Then that that needs to be stated clearly in the specification.

-Ekr





_______________________________________________
TLS mailing list
TLS@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls