[TLS] Re: Review of draft-santesson-tls-gssapi-00
Simon Josefsson <simon@josefsson.org> Fri, 09 March 2007 13:26 UTC
Return-path: <tls-bounces@lists.ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1HPf6j-0004Gm-8b; Fri, 09 Mar 2007 08:26:05 -0500
Received: from [10.90.34.44] (helo=chiedprmail1.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HPf6i-0004ES-Lw for tls@ietf.org; Fri, 09 Mar 2007 08:26:04 -0500
Received: from 178.230.13.217.in-addr.dgcsystems.net ([217.13.230.178] helo=yxa.extundo.com) by chiedprmail1.ietf.org with esmtp (Exim 4.43) id 1HPf6h-0002ah-5x for tls@ietf.org; Fri, 09 Mar 2007 08:26:04 -0500
Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l29DPL5X006544 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 9 Mar 2007 14:25:21 +0100
From: Simon Josefsson <simon@josefsson.org>
To: Pasi.Eronen@nokia.com
References: <20070122202751.CCBC45C01E@laser.networkresonance.com> <A15AC0FBACD3464E95961F7C0BCD1FF01EEDF5A8@EA-EXMSG-C307.europe.corp.microsoft.com> <86mz2nr65m.fsf@raman.networkresonance.com> <B356D8F434D20B40A8CEDAEC305A1F2403DE97E4@esebe105.NOE.Nokia.com>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:070309:tls@ietf.org::mbzRlJwgagSNjotA:GD5t
X-Hashcash: 1:22:070309:pasi.eronen@nokia.com::RX8Q/I1DwNC0P1Cr:CP6a
Date: Fri, 09 Mar 2007 14:25:21 +0100
In-Reply-To: <B356D8F434D20B40A8CEDAEC305A1F2403DE97E4@esebe105.NOE.Nokia.com> (Pasi Eronen's message of "Fri\, 9 Mar 2007 12\:49\:11 +0200")
Message-ID: <87hcsulfb2.fsf@mocca.josefsson.org>
User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
X-Spam-Status: No, score=-2.0 required=4.0 tests=AWL,BAYES_00, FORGED_RCVD_HELO autolearn=ham version=3.1.1
X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv
X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com
X-Virus-Status: Clean
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 69a74e02bbee44ab4f8eafdbcedd94a1
Cc: tls@ietf.org
Subject: [TLS] Re: Review of draft-santesson-tls-gssapi-00
X-BeenThere: tls@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/tls>
List-Post: <mailto:tls@lists.ietf.org>
List-Help: <mailto:tls-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@lists.ietf.org?subject=subscribe>
Errors-To: tls-bounces@lists.ietf.org
<Pasi.Eronen@nokia.com> writes: > Eric Rescorla wrote: > >> >> 2) The extended roundtrips is an un-escapable consequence. If >> >> necessary I believe we can define an upper boundary of the number >> >> of roundtrips. >> >> Well, any number >2 is a radical change in the TLS state machine. > > I agree; however, there are several ways to do the roundtrips, > and some of them might be slightly less radical than the one > current proposed in draft-santesson-tls-gssapi-01. > > Here's one sketch of how this could work: > > ClientHello > (ciphersuite TLS_RSA_GSSAPI_WITH_AES128_CBC_SHA, > gss_api extension with OID list) I like this approach better, although I don't understand why you need special GSSAPI ciphersuites, could you explain? Wouldn't it be possible to do this with an extension, to enable the extra roundtrips, without touching the ciphersuites? > gss_wrap(channel binding info)) -----> Using gss_wrap to wrap additional information, such as channel bindings, has some similarities with the SASL GS2 mechanism. Note that it doesn't seem to work with authentication-only GSS-API mechanisms that doesn't support GSS_Wrap. In general, I'm in favor of any protocol that permits GSS-API negotiation inside TLS but outside of the application data exchange. The details are less important to me, and I think it should be possible to come up with a good compromise here. /Simon _______________________________________________ TLS mailing list TLS@lists.ietf.org https://www1.ietf.org/mailman/listinfo/tls
- [TLS] Review of draft-santesson-tls-gssapi-00 Eric Rescorla
- RE: [TLS] Review of draft-santesson-tls-gssapi-00 Stefan Santesson
- RE: [TLS] Review of draft-santesson-tls-gssapi-00 Stefan Santesson
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Eric Rescorla
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Martin Rex
- RE: [TLS] Review of draft-santesson-tls-gssapi-00 Pasi.Eronen
- [TLS] Re: Review of draft-santesson-tls-gssapi-00 Simon Josefsson
- [TLS] RE: Review of draft-santesson-tls-gssapi-00 Pasi.Eronen
- RE: [TLS] Review of draft-santesson-tls-gssapi-00 Stefan Santesson
- [TLS] Re: Review of draft-santesson-tls-gssapi-00 Simon Josefsson
- [TLS] RE: Review of draft-santesson-tls-gssapi-00 Pasi.Eronen
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 EKR
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 EKR
- RE: [TLS] Review of draft-santesson-tls-gssapi-00 Stefan Santesson
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 EKR
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Martin Rex
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Martin Rex
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Martin Rex
- [TLS] Re: Review of draft-santesson-tls-gssapi-00 Simon Josefsson
- RE: [TLS] Review of draft-santesson-tls-gssapi-00 Stefan Santesson
- RE: [TLS] Review of draft-santesson-tls-gssapi-00 Stefan Santesson
- RE: [TLS] Review of draft-santesson-tls-gssapi-00 Pasi.Eronen
- RE: [TLS] Review of draft-santesson-tls-gssapi-00 Stefan Santesson
- RE: [TLS] Review of draft-santesson-tls-gssapi-00 Pasi.Eronen
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Jeffrey Altman
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Yoav Nir
- [TLS] TLS state machine Stefan Santesson
- RE: [TLS] TLS state machine Pasi.Eronen
- RE: [TLS] Review of draft-santesson-tls-gssapi-00 Pasi.Eronen
- [TLS] Re: Review of draft-santesson-tls-gssapi-00 Simon Josefsson
- RE: [TLS] Review of draft-santesson-tls-gssapi-00 Ari Medvinsky
- RE: [TLS] Review of draft-santesson-tls-gssapi-00 Pasi.Eronen
- [TLS] Re: Review of draft-santesson-tls-gssapi-00 Simon Josefsson
- Re: [TLS] Re: Review of draft-santesson-tls-gssap… Jeffrey Altman
- [TLS] RE: Review of draft-santesson-tls-gssapi-00 Pasi.Eronen
- RE: [TLS] Re: Review of draft-santesson-tls-gssap… Stefan Santesson
- RE: [TLS] TLS state machine Stefan Santesson
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Martin Rex
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Martin Rex
- Re: [***SPAM*** Score/Req: 11.0/5.0] Re: [TLS] Re… Jeffrey Altman
- Re: [TLS] Re: Review of draft-santesson-tls-gssap… Martin Rex
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Martin Rex
- Re: [***SPAM*** Score/Req: 11.0/5.0] Re: [TLS] Re… EKR
- Re: [***SPAM*** Score/Req: 11.0/5.0] Re: [TLS] Re… Jeffrey Altman
- RE: [TLS] TLS state machine Pasi.Eronen
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Martin Rex
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Jeffrey Altman
- Re: [TLS] TLS state machine Bodo Moeller
- Re: [TLS] TLS state machine Bodo Moeller
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Martin Rex
- Re: [TLS] Review of draft-santesson-tls-gssapi-00 Nelson B Bolyard
- RE: [TLS] Re: Review of draft-santesson-tls-gssap… Stefan Santesson
- Re: [TLS] TLS state machine tom.petch