Re: [websec] Session Continuation = Session Bound State?

Nico Williams <nico@cryptonector.com> Tue, 19 March 2013 15:21 UTC

Return-Path: <nico@cryptonector.com>
X-Original-To: websec@ietfa.amsl.com
Delivered-To: websec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B32E821F8D34 for <websec@ietfa.amsl.com>; Tue, 19 Mar 2013 08:21:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[AWL=0.075, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CtMAcxzat5uG for <websec@ietfa.amsl.com>; Tue, 19 Mar 2013 08:21:19 -0700 (PDT)
Received: from homiemail-a65.g.dreamhost.com (caiajhbdcbbj.dreamhost.com [208.97.132.119]) by ietfa.amsl.com (Postfix) with ESMTP id F1F7C21F8D5D for <websec@ietf.org>; Tue, 19 Mar 2013 08:21:18 -0700 (PDT)
Received: from homiemail-a65.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a65.g.dreamhost.com (Postfix) with ESMTP id 69DF17E4072 for <websec@ietf.org>; Tue, 19 Mar 2013 08:21:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=cryptonector.com; h= mime-version:in-reply-to:references:date:message-id:subject:from :to:cc:content-type; s=cryptonector.com; bh=YDDQqRWp1me2dtdryMOJ Hs33iDo=; b=ZhynC9Ih1XI90fdT3Ye3ZvfoKnEowjGNPscUJdL2QfYoYBGrP5yt JgIK78kbImQLYMOIKE3qVEJBZIYQoAU/Gby3Bae1Jkete+wsL3dxcFxtseOpxNxS jb5ofjxUF+0rji1Y7UMyf5ZwyJROo1dIW1r4sO7SlTlW6SfNQt4zaJc=
Received: from mail-wi0-f176.google.com (mail-wi0-f176.google.com [209.85.212.176]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: nico@cryptonector.com) by homiemail-a65.g.dreamhost.com (Postfix) with ESMTPSA id 3FAAC7E4058 for <websec@ietf.org>; Tue, 19 Mar 2013 08:21:16 -0700 (PDT)
Received: by mail-wi0-f176.google.com with SMTP id hm14so4088993wib.3 for <websec@ietf.org>; Tue, 19 Mar 2013 08:21:14 -0700 (PDT)
MIME-Version: 1.0
X-Received: by 10.180.108.3 with SMTP id hg3mr3891706wib.33.1363706474972; Tue, 19 Mar 2013 08:21:14 -0700 (PDT)
Received: by 10.217.113.198 with HTTP; Tue, 19 Mar 2013 08:21:14 -0700 (PDT)
In-Reply-To: <D771EC64-65A1-4EE1-A511-3FE750257E71@checkpoint.com>
References: <CAMm+Lwge7VBNWvWG01UN4j9=1nB+b8prusSVxgOpOcNLbZT8Sg@mail.gmail.com> <D771EC64-65A1-4EE1-A511-3FE750257E71@checkpoint.com>
Date: Tue, 19 Mar 2013 10:21:14 -0500
Message-ID: <CAK3OfOivpTzy4fe9_SQU1aYRR1fQJdKmc7Pin7-kSa8JQ41Dcg@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Yoav Nir <ynir@checkpoint.com>
Content-Type: text/plain; charset="UTF-8"
Cc: websec <websec@ietf.org>
Subject: Re: [websec] Session Continuation = Session Bound State?
X-BeenThere: websec@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Web Application Security Minus Authentication and Transport <websec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/websec>, <mailto:websec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/websec>
List-Post: <mailto:websec@ietf.org>
List-Help: <mailto:websec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Mar 2013 15:21:19 -0000

On Mon, Mar 18, 2013 at 7:14 AM, Yoav Nir <ynir@checkpoint.com> wrote:
> I'm kind of partial to "session management"

I am too, but am afraid that that can lead to confusion, since we're
only dealing with establishment, use, and synchronous destruction of
sessions, not any other aspect of session management (e.g., listing
active sessions, administrative session destruction, setting of
session parameter negotiation parameters, ...).

I've liked both terms Phillip has proposed so far: Session Continuation, and:

>> How about Session Bound State as the term of art?

I'd also be happy with:  Session Layer.  (And: Cookie Slayer, and any
other punny names we might think of :)

Nico
--