
From nobody Thu Jan  1 09:41:50 2015
Return-Path: <alexey.melnikov@isode.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D579B1A1E0B for <kitten@ietfa.amsl.com>; Thu,  1 Jan 2015 09:41:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.008
X-Spam-Level: 
X-Spam-Status: No, score=-2.008 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CBCThX-oBfLU for <kitten@ietfa.amsl.com>; Thu,  1 Jan 2015 09:41:46 -0800 (PST)
Received: from waldorf.isode.com (ext-bt.isode.com [217.34.220.158]) by ietfa.amsl.com (Postfix) with ESMTP id 36CA11A1BFE for <kitten@ietf.org>; Thu,  1 Jan 2015 09:41:46 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1420134104; d=isode.com; s=selector; i=@isode.com; bh=v9XYc5nDZU0PU/QUYjyDsbyc6Cq5nqHvkj+rg95knNo=; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version: In-Reply-To:References:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description; b=Or4R0NhjyP6og2xoZO2LOvBwMe8wOLEjYqi5tjehjARbWr4WNH/jK7j29x22pzSZeQauSH REghQw5dLcM1XQrIis8g0NSfXG8RDWFO9M82MLbAnAbnP1Y4ZWXoWTibNeLYMIqc+7f16A E4eLP6dDULqtPibvMwNnUteLx01jfs8=;
Received: from [10.0.0.111] ((unknown) [213.83.78.110])  by waldorf.isode.com (submission channel) via TCP with ESMTPSA  id <VKWG1gAKaGCw@waldorf.isode.com>; Thu, 1 Jan 2015 17:41:43 +0000
X-SMTP-Protocol-Errors: NORDNS PIPELINING
From: Alexey Melnikov <alexey.melnikov@isode.com>
X-Mailer: iPad Mail (12B435)
In-Reply-To: <alpine.GSO.1.10.1412311426270.23489@multics.mit.edu>
Date: Thu, 1 Jan 2015 17:46:15 +0000
Message-Id: <3D9D6627-F6B2-456C-9C24-F224989B1979@isode.com>
References: <alpine.GSO.1.10.1412151142560.23489@multics.mit.edu> <alpine.GSO.1.10.1412311426270.23489@multics.mit.edu>
To: Benjamin Kaduk <kaduk@MIT.EDU>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary=Apple-Mail-62F18AB0-42C9-449A-9E7B-F33B08CDF829
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/rbGTXBbMqHKq2UA2Wz5MSwxH5gs
Cc: "kitten@ietf.org" <kitten@ietf.org>, "kitten-chairs@tools.ietf.org" <kitten-chairs@tools.ietf.org>
Subject: Re: [kitten] WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 01 Jan 2015 17:41:49 -0000

--Apple-Mail-62F18AB0-42C9-449A-9E7B-F33B08CDF829
Content-Type: text/plain;
	charset=us-ascii
Content-Transfer-Encoding: quoted-printable


> On 31 Dec 2014, at 19:27, Benjamin Kaduk <kaduk@MIT.EDU> wrote:
>=20
> We've gotten some "looks good"s on the oauth list, for those only on
> kitten@.
>=20
> Just under two weeks remain in the last call period.

I generally think that the document has improved recently and it is very clo=
se to being done. But I think examples in particular need to be fixed (and I=
 am sorry if I sound like a broken record on this, but I believe that exampl=
es are very important, as some people will just code based on them).

In 3.1:

key =3D 1*(ALPHA / ",")

So the key can be a single comma character, right?
client_resp    =3D (gs2-header kvsep 0*kvpair kvsep) / kvsep

Did you mean that the whole client response can be just a single separator c=
haracter? I think this is not compatible with GS2 framing. If you only meant=
 to allow that for failed authentication, I suggest you add a comment and po=
int to section 3.2.3.
In 3.2:

Nit:
 Note that the semantics of the authz-id is specified by
   the SASL framework [RFC4422].
If this is the same as "authzid" introduced in section 3.1, then you should r=
emove dash. (I was wondering if this is something else). But I think expandi=
ng this to be "authorization identity" would be better.

In 3.2.2:
oauth-configuration (OPTIONAL):  The URL for for a document
         following the OpenID Provider Configuration Information schema
         as described in OpenID Connect Discovery
I think it would help to clarify that the returned value is always an https (=
or http?) URI. If that can be something else, saying that would be great too=
.

In 3.2.3:

I think you don't need to have an explicit message to cancel authentication,=
 you can just use the SASL framework facility for this. In IMAP that would b=
e emitted as "*\r\n".

In particular, I think Cyrus SASL based implementations can handle "here is s=
ome data from the server, but this step produces failure on the client side,=
 so the client need to cancel the exchange" just fine.

In 4.1:

I think you need to explain that the example is only valid in the presence o=
f SASL-IR capability (and add an Informative reference), because the initial=
 client response parameter to AUTHENTICATE is only allowed when SASL-IR is a=
dvertised. Or you can just use an SMTP example here.


Examples in 4.1, 4.3 and 4.4 don't show negotiation of TLS, which is a MUST l=
evel requirement for AUTHBEARER SASL mechanism (as per section 5), so you sh=
ould fix examples to advertise STARTTLS capability and show use of STARTTLS c=
ommand.

If you would like me to provide full examples, let me know and I do that.

>=20
> -Ben
>=20
>> On Mon, 15 Dec 2014, Benjamin Kaduk wrote:
>>=20
>> This message begins the fourth Working Group Last Call (WGLC) of "A set o=
f
>> SASL Mechanisms for OAuth" <draft-ietf-kitten-sasl-oauth-18.txt>.  Due to=

>> the overlap of the last call period with holidays, the duration of the
>> WGLC is extended to four weeks, so the WGLC will end on 12 January 2015.
>> The draft is available at:
>>=20
>> https://tools.ietf.org/html/draft-ietf-kitten-sasl-oauth-18
>>=20
>> Because the changes between -15 and -18 involve behavior changes,
>> including changes regarding discovery and dynamic registration, the Chair=
s
>> decided to issue an additional last call.
>>=20
>> Please review the document and send comments to the Working Group
>> mailing list < kitten at itef.org > or the co-chairs < kitten-chairs
>> at tools.ietf.org > before the end of the WGLC.  Any and all comments
>> on the document are sought in order to access the strength of
>> consensus.  Even if you have read and commented on this or earlier
>> versions of the draft, please feel free to comment again.  This is
>> particularly important if you found issues with the previous version.
>>=20
>> As a reminder, comments can be anything from "this looks fine" to
>> "this is a horrible idea"; they can include suggestions for minor
>> editorial corrections to significant editorial changes.
>>=20
>>=20
>> - Your Kitten Chairs
>>=20
>> _______________________________________________
>> Kitten mailing list
>> Kitten@ietf.org
>> https://www.ietf.org/mailman/listinfo/kitten
>=20
> _______________________________________________
> Kitten mailing list
> Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten

--Apple-Mail-62F18AB0-42C9-449A-9E7B-F33B08CDF829
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><div><span></span></div><div><div><br></div=
><div>On 31 Dec 2014, at 19:27, Benjamin Kaduk &lt;<a href=3D"mailto:kaduk@M=
IT.EDU">kaduk@MIT.EDU</a>&gt; wrote:<br><br></div><blockquote type=3D"cite">=
<div><span>We've gotten some "looks good"s on the oauth list, for those only=
 on</span><br><span>kitten@.</span><br><span></span><br><span>Just under two=
 weeks remain in the last call period.</span><br></div></blockquote><div><br=
></div><div style=3D"color: rgba(0, 0, 0, 0.701961); -webkit-composition-fil=
l-color: rgba(130, 98, 83, 0.0980392); text-decoration: -webkit-letterpress;=
">I generally think that the document has improved recently and it is very c=
lose to being done. But I think examples in particular need to be fixed (and=
 I am sorry if I sound like a broken record on this, but I believe that exam=
ples are very important, as some people will just code based on them).</div>=
<div style=3D"color: rgba(0, 0, 0, 0.701961); -webkit-composition-fill-color=
: rgba(130, 98, 83, 0.0980392); text-decoration: -webkit-letterpress;"><br><=
/div><div style=3D"color: rgba(0, 0, 0, 0.701961); -webkit-composition-fill-=
color: rgba(130, 98, 83, 0.0980392); text-decoration: -webkit-letterpress;">=
In 3.1:</div><div style=3D"color: rgba(0, 0, 0, 0.701961); -webkit-compositi=
on-fill-color: rgba(130, 98, 83, 0.0980392); text-decoration: -webkit-letter=
press;"><span style=3D"font-family: Courier; font-size: 10pt; background-col=
or: rgb(255, 255, 255);"><br></span></div><div style=3D"color: rgba(0, 0, 0,=
 0.701961); -webkit-composition-fill-color: rgba(130, 98, 83, 0.0980392); te=
xt-decoration: -webkit-letterpress;"><span style=3D"font-family: Courier; fo=
nt-size: 10pt; background-color: rgb(255, 255, 255);">key            =3D 1*(=
ALPHA / ",")</span></div><div style=3D"color: rgba(0, 0, 0, 0.701961); -webk=
it-composition-fill-color: rgba(130, 98, 83, 0.0980392); text-decoration: -w=
ebkit-letterpress;"><div class=3D"page" title=3D"Page 7"><div class=3D"secti=
on" style=3D"background-color: rgb(255, 255, 255);"><div class=3D"layoutArea=
"><div class=3D"column"><pre><span style=3D"font-size: 10pt; font-family: Co=
urier;"><br></span></pre><pre><span style=3D"font-size: 10pt; font-family: C=
ourier;">So the key can be a single comma character, right?</span></pre></di=
v></div></div></div></div><div style=3D"color: rgba(0, 0, 0, 0.701961); -web=
kit-composition-fill-color: rgba(130, 98, 83, 0.0980392); text-decoration: -=
webkit-letterpress;"><div class=3D"page" title=3D"Page 7"><div class=3D"sect=
ion" style=3D"background-color: rgb(255, 255, 255);"><div class=3D"layoutAre=
a"><div class=3D"column"><pre><span style=3D"font-size: 10pt; font-family: C=
ourier;">client_resp    =3D (gs2-header kvsep 0*kvpair kvsep) / kvsep
</span></pre><pre><span style=3D"font-size: 10pt; font-family: Courier;"><br=
></span></pre><pre><span style=3D"font-size: 10pt; font-family: Courier;">Di=
d you mean that the whole client response can be just a single separator cha=
racter? I think this is not compatible with GS2 framing. </span><span style=3D=
"font-family: Courier; font-size: 10pt;">If you only meant to allow that for=
 failed authentication, I suggest you add a comment and point to section 3.2=
.3.</span></pre></div></div></div></div></div><div style=3D"color: rgba(0, 0=
, 0, 0.701961); -webkit-composition-fill-color: rgba(130, 98, 83, 0.0980392)=
; text-decoration: -webkit-letterpress;">In 3.2:</div><div style=3D"color: r=
gba(0, 0, 0, 0.701961); -webkit-composition-fill-color: rgba(130, 98, 83, 0.=
0980392); text-decoration: -webkit-letterpress;"><br></div><div style=3D"col=
or: rgba(0, 0, 0, 0.701961); -webkit-composition-fill-color: rgba(130, 98, 8=
3, 0.0980392); text-decoration: -webkit-letterpress;">Nit:</div><div style=3D=
"color: rgba(0, 0, 0, 0.701961); -webkit-composition-fill-color: rgba(130, 9=
8, 83, 0.0980392); text-decoration: -webkit-letterpress;"><div class=3D"page=
" title=3D"Page 8"><div class=3D"section" style=3D"background-color: rgb(255=
, 255, 255);"><div class=3D"layoutArea"><div class=3D"column"><pre><span sty=
le=3D"font-size: 10pt; font-family: Courier;"> Note that the semantics of th=
e authz-id is specified by
   the SASL framework [</span><span style=3D"font-size: 10pt; font-family: C=
ourier; color: rgb(0, 0, 255);">RFC4422</span><span style=3D"font-size: 10pt=
; font-family: Courier;">].
</span></pre></div></div></div></div></div><div style=3D"color: rgba(0, 0, 0=
, 0.701961); -webkit-composition-fill-color: rgba(130, 98, 83, 0.0980392); t=
ext-decoration: -webkit-letterpress;">If this is the same as "authzid" intro=
duced in section 3.1, then you should remove dash. (I was wondering if this i=
s something else). But I think expanding this to be "authorization identity"=
 would be better.</div><div style=3D"color: rgba(0, 0, 0, 0.701961); -webkit=
-composition-fill-color: rgba(130, 98, 83, 0.0980392); text-decoration: -web=
kit-letterpress;"><br></div><div style=3D"color: rgba(0, 0, 0, 0.701961); -w=
ebkit-composition-fill-color: rgba(130, 98, 83, 0.0980392); text-decoration:=
 -webkit-letterpress;">In 3.2.2:</div><div style=3D"color: rgba(0, 0, 0, 0.7=
01961); -webkit-composition-fill-color: rgba(130, 98, 83, 0.0980392); text-d=
ecoration: -webkit-letterpress;"><div class=3D"page" title=3D"Page 9"><div c=
lass=3D"section" style=3D"background-color: rgb(255, 255, 255);"><div class=3D=
"layoutArea"><div class=3D"column"><pre><span style=3D"font-size: 10pt; font=
-family: Courier;">oauth-configuration (OPTIONAL):  The URL for for a docume=
nt
         following the OpenID Provider Configuration Information schema
         as described in OpenID Connect Discovery
</span></pre></div></div></div></div></div><div style=3D"color: rgba(0, 0, 0=
, 0.701961); -webkit-composition-fill-color: rgba(130, 98, 83, 0.0980392); t=
ext-decoration: -webkit-letterpress;">I think it would help to clarify that t=
he returned value is always an https (or http?) URI. If that can be somethin=
g else, saying that would be great too.</div><div style=3D"color: rgba(0, 0,=
 0, 0.701961); -webkit-composition-fill-color: rgba(130, 98, 83, 0.0980392);=
 text-decoration: -webkit-letterpress;"><br></div><div style=3D"color: rgba(=
0, 0, 0, 0.701961); -webkit-composition-fill-color: rgba(130, 98, 83, 0.0980=
392); text-decoration: -webkit-letterpress;">In 3.2.3:</div><div style=3D"co=
lor: rgba(0, 0, 0, 0.701961); -webkit-composition-fill-color: rgba(130, 98, 8=
3, 0.0980392); text-decoration: -webkit-letterpress;"><br></div><div style=3D=
"color: rgba(0, 0, 0, 0.701961); -webkit-composition-fill-color: rgba(130, 9=
8, 83, 0.0980392); text-decoration: -webkit-letterpress;">I think you don't n=
eed to have an explicit message to cancel authentication, you can just use t=
he SASL framework facility for this. In IMAP that would be emitted as "*\r\n=
".</div><div style=3D"color: rgba(0, 0, 0, 0.701961); -webkit-composition-fi=
ll-color: rgba(130, 98, 83, 0.0980392); text-decoration: -webkit-letterpress=
;"><br></div><div style=3D"color: rgba(0, 0, 0, 0.701961); -webkit-compositi=
on-fill-color: rgba(130, 98, 83, 0.0980392); text-decoration: -webkit-letter=
press;">In particular, I think Cyrus SASL based implementations can handle "=
here is some data from the server, but this step produces failure on the cli=
ent side, so the client need to cancel the exchange" just fine.</div><div st=
yle=3D"color: rgba(0, 0, 0, 0.701961); -webkit-composition-fill-color: rgba(=
130, 98, 83, 0.0980392); text-decoration: -webkit-letterpress;"><br></div><d=
iv style=3D"color: rgba(0, 0, 0, 0.701961); -webkit-composition-fill-color: r=
gba(130, 98, 83, 0.0980392); text-decoration: -webkit-letterpress;">In 4.1:<=
/div><div style=3D"color: rgba(0, 0, 0, 0.701961); -webkit-composition-fill-=
color: rgba(130, 98, 83, 0.0980392); text-decoration: -webkit-letterpress;">=
<br></div><div style=3D"color: rgba(0, 0, 0, 0.701961); -webkit-composition-=
fill-color: rgba(130, 98, 83, 0.0980392); text-decoration: -webkit-letterpre=
ss;">I think you need to explain that the example is only valid in the prese=
nce of SASL-IR capability (and add an Informative reference), because the in=
itial client response parameter to AUTHENTICATE is only allowed when SASL-IR=
 is advertised. Or you can just use an SMTP example here.</div><div style=3D=
"color: rgba(0, 0, 0, 0.701961); -webkit-composition-fill-color: rgba(130, 9=
8, 83, 0.0980392); text-decoration: -webkit-letterpress;"><br></div><div sty=
le=3D"color: rgba(0, 0, 0, 0.701961); -webkit-composition-fill-color: rgba(1=
30, 98, 83, 0.0980392); text-decoration: -webkit-letterpress;"><br></div><di=
v style=3D"color: rgba(0, 0, 0, 0.701961); -webkit-composition-fill-color: r=
gba(130, 98, 83, 0.0980392); text-decoration: -webkit-letterpress;">Examples=
 in 4.1, 4.3 and 4.4 don't show negotiation of TLS, which is a MUST level re=
quirement for AUTHBEARER SASL mechanism (as per section 5), so you should fi=
x examples to advertise STARTTLS capability and show use of STARTTLS command=
.</div><div style=3D"color: rgba(0, 0, 0, 0.701961); -webkit-composition-fil=
l-color: rgba(130, 98, 83, 0.0980392); text-decoration: -webkit-letterpress;=
"><br></div><div style=3D"color: rgba(0, 0, 0, 0.701961); -webkit-compositio=
n-fill-color: rgba(130, 98, 83, 0.0980392); text-decoration: -webkit-letterp=
ress;">If you would like me to provide full examples, let me know and I do t=
hat.</div><div><br></div><blockquote type=3D"cite"><div><span></span><br><sp=
an>-Ben</span><br><span></span><br><span>On Mon, 15 Dec 2014, Benjamin Kaduk=
 wrote:</span><br><span></span><br><blockquote type=3D"cite"><span>This mess=
age begins the fourth Working Group Last Call (WGLC) of "A set of</span><br>=
</blockquote><blockquote type=3D"cite"><span>SASL Mechanisms for OAuth" &lt;=
draft-ietf-kitten-sasl-oauth-18.txt&gt;. &nbsp;Due to</span><br></blockquote=
><blockquote type=3D"cite"><span>the overlap of the last call period with ho=
lidays, the duration of the</span><br></blockquote><blockquote type=3D"cite"=
><span>WGLC is extended to four weeks, so the WGLC will end on 12 January 20=
15.</span><br></blockquote><blockquote type=3D"cite"><span>The draft is avai=
lable at:</span><br></blockquote><blockquote type=3D"cite"><span></span><br>=
</blockquote><blockquote type=3D"cite"><span><a href=3D"https://tools.ietf.o=
rg/html/draft-ietf-kitten-sasl-oauth-18">https://tools.ietf.org/html/draft-i=
etf-kitten-sasl-oauth-18</a></span><br></blockquote><blockquote type=3D"cite=
"><span></span><br></blockquote><blockquote type=3D"cite"><span>Because the c=
hanges between -15 and -18 involve behavior changes,</span><br></blockquote>=
<blockquote type=3D"cite"><span>including changes regarding discovery and dy=
namic registration, the Chairs</span><br></blockquote><blockquote type=3D"ci=
te"><span>decided to issue an additional last call.</span><br></blockquote><=
blockquote type=3D"cite"><span></span><br></blockquote><blockquote type=3D"c=
ite"><span>Please review the document and send comments to the Working Group=
</span><br></blockquote><blockquote type=3D"cite"><span>mailing list &lt; ki=
tten at <a href=3D"http://itef.org">itef.org</a> &gt; or the co-chairs &lt; k=
itten-chairs</span><br></blockquote><blockquote type=3D"cite"><span>at <a hr=
ef=3D"http://tools.ietf.org">tools.ietf.org</a> &gt; before the end of the W=
GLC. &nbsp;Any and all comments</span><br></blockquote><blockquote type=3D"c=
ite"><span>on the document are sought in order to access the strength of</sp=
an><br></blockquote><blockquote type=3D"cite"><span>consensus. &nbsp;Even if=
 you have read and commented on this or earlier</span><br></blockquote><bloc=
kquote type=3D"cite"><span>versions of the draft, please feel free to commen=
t again. &nbsp;This is</span><br></blockquote><blockquote type=3D"cite"><spa=
n>particularly important if you found issues with the previous version.</spa=
n><br></blockquote><blockquote type=3D"cite"><span></span><br></blockquote><=
blockquote type=3D"cite"><span>As a reminder, comments can be anything from "=
this looks fine" to</span><br></blockquote><blockquote type=3D"cite"><span>"=
this is a horrible idea"; they can include suggestions for minor</span><br><=
/blockquote><blockquote type=3D"cite"><span>editorial corrections to signifi=
cant editorial changes.</span><br></blockquote><blockquote type=3D"cite"><sp=
an></span><br></blockquote><blockquote type=3D"cite"><span></span><br></bloc=
kquote><blockquote type=3D"cite"><span>- Your Kitten Chairs</span><br></bloc=
kquote><blockquote type=3D"cite"><span></span><br></blockquote><blockquote t=
ype=3D"cite"><span>_______________________________________________</span><br=
></blockquote><blockquote type=3D"cite"><span>Kitten mailing list</span><br>=
</blockquote><blockquote type=3D"cite"><span><a href=3D"mailto:Kitten@ietf.o=
rg">Kitten@ietf.org</a></span><br></blockquote><blockquote type=3D"cite"><sp=
an><a href=3D"https://www.ietf.org/mailman/listinfo/kitten">https://www.ietf=
.org/mailman/listinfo/kitten</a></span><br></blockquote><blockquote type=3D"=
cite"><span></span><br></blockquote><span></span><br><span>_________________=
______________________________</span><br><span>Kitten mailing list</span><br=
><span><a href=3D"mailto:Kitten@ietf.org">Kitten@ietf.org</a></span><br><spa=
n><a href=3D"https://www.ietf.org/mailman/listinfo/kitten">https://www.ietf.=
org/mailman/listinfo/kitten</a></span><br></div></blockquote></div></body></=
html>=

--Apple-Mail-62F18AB0-42C9-449A-9E7B-F33B08CDF829--


From nobody Fri Jan  2 16:56:53 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A14851A8838 for <kitten@ietfa.amsl.com>; Fri,  2 Jan 2015 16:56:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.99
X-Spam-Level: 
X-Spam-Status: No, score=0.99 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, J_CHICKENPOX_41=0.6, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xuSI09qHFGg5 for <kitten@ietfa.amsl.com>; Fri,  2 Jan 2015 16:56:49 -0800 (PST)
Received: from nm16.bullet.mail.bf1.yahoo.com (nm16.bullet.mail.bf1.yahoo.com [98.139.212.175]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EB5541A8836 for <kitten@ietf.org>; Fri,  2 Jan 2015 16:56:48 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1420246608; bh=GKR8cbUKXm5ZFGvzSR/W4xy6HldH9ii8zmxIItTrL74=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=IT6x871+lKYoFC4uT6Xh+KD0V+D/bmjenf0LNRI5LT5EbOBRJ0V24rYjKky9yT29BhWN40vgYffodVRrjuYybOKeA8ddDfa+4iYzNHL0hxWFc4VvL5cH941Z7HMPgCWamqrmqi6T2RSdkVybyQU5LP+LkZaIlzQg1tiq78GtR4d8cbSKs2K9NLeCipJ7H+4glcFvpEykmVBjG+fYSWBNi93TkBzFqFM8NEvsjgKxkcoAT/JDLinYRdkBWLQAlhsWdSjphTHMEbCCYYkMq4bjEjcDNSGR5unRGQXOs1UF9EhmGPFEg+BQ3mphN3ia8/mz71cIc0UtR7z0CL1Rd98LEQ==
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s2048; d=yahoo.com; b=C0+qZy/NoIRArbyuTZCxBhsiho7C3Me3Re/QLtuR7yWUECzz2bL4bp4jufPTPXrOUPDxmYSkuW2YrVXgMAcEUoNk99jN9djhtyVQ1iNp2iyaTHD12u6/ZQvqMpxFEjc3EyVCGahVvu5OxqZoyQdOP2A5mcLp0rEi1gv6GVUy2cy8Bxdi+ImyfALRWYR6/rENeiChwOwP/JrzbHV87AS453LDvYqTvnXdFUUM/fL/eB+KH3DDFpmmL4IvQd2oLBZcj+E+4UaFzgQyMzMkOWToH9DlloANXs6v0H9DqmdX21VX/A/PHxcR6+AOEhivyheD2L9Rx22mh/xd09oFkGGjCw==;
Received: from [66.196.81.174] by nm16.bullet.mail.bf1.yahoo.com with NNFMP; 03 Jan 2015 00:56:48 -0000
Received: from [98.139.215.250] by tm20.bullet.mail.bf1.yahoo.com with NNFMP;  03 Jan 2015 00:56:48 -0000
Received: from [127.0.0.1] by omp1063.mail.bf1.yahoo.com with NNFMP; 03 Jan 2015 00:56:48 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 128976.14765.bm@omp1063.mail.bf1.yahoo.com
X-YMail-OSG: ThBJX5gVM1lreIgGMSXfN2Jm1bvNmiJAlH9.uT4NHU9FYEJYB8x6hMTdTK4UD58 fJXHjdCm9L6e9kjH1iSCXC.IFXboPXjPPrd7.8anX75AG72OXAZOtZOWkdb2PealA.HQzlltij.X bex98bT7o8qhJ39Dg1X3qFKa4_CptzJRauYqmkYjv4_glJxsCGPzdxxdxUynFMwt15o.8vI_ymvH kXh7pUl9mVnyBUF9d9JsgBZAOKL_YXTq._af6YprRycRXmq2B7AEi57mlrFKSE4MSn7qElBCM8ba GX3Q_XfrXF5stCEtAxKA_KntduUWQ4kopWS9kV7H8O5J2j9acGP6UrYUUGmhwkD.hMXmHjCZLKpr CsZUtF2DIuUqky1h4fLT0VXcAaGVCdF79U_E7i97oRP_rJCZbi4BQ8TF721WUpTpUMtQdZDLDiUo FOinxoudS3O7zXj6yFV9gvOoJz7nnmvq.Q.rni.CyXMTjTsw0UQB41FO4EB3SET3Uw..k4IMXszc nzSMdyAk0ZLSVpnGcfug3tRBrwdjtNZ.cBT5T57.iPBUJkWalENCbc8mIv5eT1uxoO12dimN9Ylh G_LtRev9GFiIIkrUYKZUa
Received: by 66.196.81.118; Sat, 03 Jan 2015 00:56:47 +0000 
Date: Sat, 3 Jan 2015 00:56:47 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Alexey Melnikov <alexey.melnikov@isode.com>,  Benjamin Kaduk <kaduk@MIT.EDU>
Message-ID: <377717803.3860512.1420246607276.JavaMail.yahoo@jws10611.mail.bf1.yahoo.com>
In-Reply-To: <3D9D6627-F6B2-456C-9C24-F224989B1979@isode.com>
References: <3D9D6627-F6B2-456C-9C24-F224989B1979@isode.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_3860511_76983976.1420246607258"
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/VF_2XFlPivXA5D5nz6ncoY6JUYI
Cc: "kitten@ietf.org" <kitten@ietf.org>, "kitten-chairs@tools.ietf.org" <kitten-chairs@tools.ietf.org>
Subject: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 03 Jan 2015 00:56:51 -0000

------=_Part_3860511_76983976.1420246607258
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

"key =3D 1*(ALPHA / ",")"=C2=A0This was an ill advised hack to allow the GS=
2 header to appear as a key. =C2=A0Removing the comma since this now explic=
itly uses the gs2-header..
re 3.2: changed to authorization identity.=20
re SASL-IR: added a note in the top of the examples section and an informat=
ive reference to 4959.
re 3.2.2 and the OpendID configuration URL. =C2=A0That spec requires "https=
" explicitly already. =C2=A0Repeat that here? =C2=A0Easy to cite that spec =
and say HTTPS is required but I usually try not to repeat things defined ot=
her places.
3.2.3 and an explicit message: =C2=A0Long ago in the life of this doc I was=
 told that some implementations may not support an empty message, so we put=
 the single character message there to have an explicit payload. =C2=A0I'm =
a bit leery of changing this now since there are implementations in play th=
at use it this way.

On requiring TLS and adding STARTTLS to the examples: your'e not happy with=
 the current "Note that line=C2=A0 breaks are inserted for readability and =
the underlying TLS establishment is not shown either."? =C2=A0I'd prefer to=
 add text saying something like "These Bearer token examples assume encrypt=
ed transport, if the underlying connection is not already TLS then STARTTLS=
 MUST be used as required in the Bearer Token specification.". =C2=A0I can =
also easily specify that this is IMAP over 995 or SMTP over 465.




  =20

  On Thursday, January 1, 2015 9:41 AM, Alexey Melnikov <alexey.melnikov@is=
ode.com> wrote:
  =20

=20
On 31 Dec 2014, at 19:27, Benjamin Kaduk <kaduk@MIT.EDU> wrote:


We've gotten some "looks good"s on the oauth list, for those only on
kitten@.

Just under two weeks remain in the last call period.


I generally think that the document has improved recently and it is very cl=
ose to being done. But I think examples in particular need to be fixed (and=
 I am sorry if I sound like a broken record on this, but I believe that exa=
mples are very important, as some people will just code based on them).
In 3.1:
key =3D 1*(ALPHA / ",")
So the key can be a single comma character, right?client_resp    =3D (gs2-h=
eader kvsep 0*kvpair kvsep) / kvsep

Did you mean that the whole client response can be just a single separator =
character? I think this is not compatible with GS2 framing. If you only mea=
nt to allow that for failed authentication, I suggest you add a comment and=
 point to section 3.2.3.In 3.2:
Nit: Note that the semantics of the authz-id is specified by
   the SASL framework [RFC4422].
If this is the same as "authzid" introduced in section 3.1, then you should=
 remove dash. (I was wondering if this is something else). But I think expa=
nding this to be "authorization identity" would be better.
In 3.2.2:oauth-configuration (OPTIONAL):  The URL for for a document
         following the OpenID Provider Configuration Information schema
         as described in OpenID Connect Discovery
I think it would help to clarify that the returned value is always an https=
 (or http?) URI. If that can be something else, saying that would be great =
too.
In 3.2.3:
I think you don't need to have an explicit message to cancel authentication=
, you can just use the SASL framework facility for this. In IMAP that would=
 be emitted as "*\r\n".
In particular, I think Cyrus SASL based implementations can handle "here is=
 some data from the server, but this step produces failure on the client si=
de, so the client need to cancel the exchange" just fine.
In 4.1:
I think you need to explain that the example is only valid in the presence =
of SASL-IR capability (and add an Informative reference), because the initi=
al client response parameter to AUTHENTICATE is only allowed when SASL-IR i=
s advertised. Or you can just use an SMTP example here.

Examples in 4.1, 4.3 and 4.4 don't show negotiation of TLS, which is a MUST=
 level requirement for AUTHBEARER SASL mechanism (as per section 5), so you=
 should fix examples to advertise STARTTLS capability and show use of START=
TLS command.
If you would like me to provide full examples, let me know and I do that.


-Ben

On Mon, 15 Dec 2014, Benjamin Kaduk wrote:


This message begins the fourth Working Group Last Call (WGLC) of "A set of


SASL Mechanisms for OAuth" <draft-ietf-kitten-sasl-oauth-18.txt>. =C2=A0Due=
 to


the overlap of the last call period with holidays, the duration of the


WGLC is extended to four weeks, so the WGLC will end on 12 January 2015.


The draft is available at:





https://tools.ietf.org/html/draft-ietf-kitten-sasl-oauth-18





Because the changes between -15 and -18 involve behavior changes,


including changes regarding discovery and dynamic registration, the Chairs


decided to issue an additional last call.





Please review the document and send comments to the Working Group


mailing list < kitten at itef.org > or the co-chairs < kitten-chairs


at tools.ietf.org > before the end of the WGLC. =C2=A0Any and all comments


on the document are sought in order to access the strength of


consensus. =C2=A0Even if you have read and commented on this or earlier


versions of the draft, please feel free to comment again. =C2=A0This is


particularly important if you found issues with the previous version.





As a reminder, comments can be anything from "this looks fine" to


"this is a horrible idea"; they can include suggestions for minor


editorial corrections to significant editorial changes.








- Your Kitten Chairs





_______________________________________________


Kitten mailing list


Kitten@ietf.org


https://www.ietf.org/mailman/listinfo/kitten





_______________________________________________
Kitten mailing list
Kitten@ietf.org
https://www.ietf.org/mailman/listinfo/kitten


_______________________________________________
Kitten mailing list
Kitten@ietf.org
https://www.ietf.org/mailman/listinfo/kitten


   
------=_Part_3860511_76983976.1420246607258
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div id=3D"yiv0245518097"><div id=3D"yui_3_16_0_1_14198068706=
97_720201"><div style=3D"color:#000;background-color:#fff;font-family:Helve=
ticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-=
size:12px;" id=3D"yui_3_16_0_1_1419806870697_720200"><div id=3D"yiv02455180=
97yui_3_16_0_1_1419806870697_711052"><span></span></div><div id=3D"yiv02455=
18097yui_3_16_0_1_1419806870697_711050"><div style=3D"font-size: 15.5555562=
973022px;" class=3D"" id=3D"yui_3_16_0_1_1419806870697_734960"><span style=
=3D"font-family: Courier; font-size: 10pt;" class=3D"" id=3D"yui_3_16_0_1_1=
419806870697_734959">"key =3D 1*(ALPHA / ",")"&nbsp;</span><span style=3D"f=
ont-size: 12px;">This was an ill advised hack to allow the GS2 header to ap=
pear as a key. &nbsp;Removing the comma since this now explicitly uses the =
gs2-header..</span></div></div><div id=3D"yiv0245518097yui_3_16_0_1_1419806=
870697_711050" dir=3D"ltr"><span><br></span></div><div dir=3D"ltr" id=3D"yi=
v0245518097yui_3_16_0_1_1419806870697_711046"><span id=3D"yiv0245518097yui_=
3_16_0_1_1419806870697_711048">re 3.2: changed to authorization identity.</=
span></div> <div class=3D"yiv0245518097qtdSeparateBR" id=3D"yiv0245518097yu=
i_3_16_0_1_1419806870697_710992"><br clear=3D"none"></div><div class=3D"yiv=
0245518097qtdSeparateBR" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_7109=
92" dir=3D"ltr">re SASL-IR: added a note in the top of the examples section=
 and an informative reference to 4959.</div><div class=3D"yiv0245518097qtdS=
eparateBR" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_710992"><br></div>=
<div class=3D"yiv0245518097qtdSeparateBR" dir=3D"ltr" id=3D"yiv0245518097yu=
i_3_16_0_1_1419806870697_710992">re 3.2.2 and the OpendID configuration URL=
. &nbsp;That spec requires "https" explicitly already. &nbsp;Repeat that he=
re? &nbsp;Easy to cite that spec and say HTTPS is required but I usually tr=
y not to repeat things defined other places.</div><div class=3D"yiv02455180=
97qtdSeparateBR" dir=3D"ltr" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_=
710992"><br clear=3D"none"></div><div class=3D"yiv0245518097qtdSeparateBR" =
dir=3D"ltr" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_710992">3.2.3 and=
 an explicit message: &nbsp;Long ago in the life of this doc I was told tha=
t some implementations may not support an empty message, so we put the sing=
le character message there to have an explicit payload. &nbsp;I'm a bit lee=
ry of changing this now since there are implementations in play that use it=
 this way.</div><div class=3D"yiv0245518097qtdSeparateBR" dir=3D"ltr" id=3D=
"yiv0245518097yui_3_16_0_1_1419806870697_710992"><br></div><div class=3D"yi=
v0245518097qtdSeparateBR" dir=3D"ltr" id=3D"yiv0245518097yui_3_16_0_1_14198=
06870697_710992"><br></div><div class=3D"yiv0245518097qtdSeparateBR" dir=3D=
"ltr" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_710992">On requiring TL=
S and adding STARTTLS to the examples: your'e not happy with the current "<=
span style=3D"font-size: 12px;" class=3D"">Note that line&nbsp;</span><span=
 class=3D"" style=3D"font-size: 12px; white-space: pre;">=09</span><span st=
yle=3D"font-size: 12px;" id=3D"yui_3_16_0_1_1419806870697_724221">breaks ar=
e inserted for readability and the underlying TLS establishment is not show=
n either."? &nbsp;I'd prefer to add text saying something like "These Beare=
r token examples assume encrypted transport, if the underlying connection i=
s not already TLS then STARTTLS MUST be used as required in the Bearer Toke=
n specification.". &nbsp;I can also easily specify that this is IMAP over 9=
95 or SMTP over 465.</span></div><div class=3D"yiv0245518097qtdSeparateBR" =
dir=3D"ltr" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_710992"><span sty=
le=3D"font-size: 12px;"><br></span></div><div class=3D"yiv0245518097qtdSepa=
rateBR" dir=3D"ltr" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_710992"><=
span style=3D"font-size: 12px;"><br></span></div><div class=3D"yiv024551809=
7qtdSeparateBR" dir=3D"ltr" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_7=
10992"><br clear=3D"none"></div><div class=3D"yiv0245518097qtdSeparateBR" d=
ir=3D"ltr" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_710992"><br clear=
=3D"none"><br clear=3D"none"></div><div class=3D"yiv0245518097yahoo_quoted"=
 id=3D"yiv0245518097yui_3_16_0_1_1419806870697_710981" style=3D"display: bl=
ock;"> <div id=3D"yiv0245518097yui_3_16_0_1_1419806870697_710980" style=3D"=
font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande,=
 sans-serif;font-size:12px;"> <div id=3D"yiv0245518097yui_3_16_0_1_14198068=
70697_710979" style=3D"font-family:HelveticaNeue, Helvetica Neue, Helvetica=
, Arial, Lucida Grande, sans-serif;font-size:16px;"> <div class=3D"qtdSepar=
ateBR"><br><br></div><div class=3D"yiv0245518097yqt2856481274" id=3D"yiv024=
5518097yqt56194"><div dir=3D"ltr" id=3D"yiv0245518097yui_3_16_0_1_141980687=
0697_710989"> <font id=3D"yiv0245518097yui_3_16_0_1_1419806870697_710988" s=
ize=3D"2" face=3D"Arial"> On Thursday, January 1, 2015 9:41 AM, Alexey Meln=
ikov &lt;alexey.melnikov@isode.com&gt; wrote:<br clear=3D"none"> </font> </=
div>  <br clear=3D"none"><br clear=3D"none"> <div class=3D"yiv0245518097y_m=
sg_container" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_710978"><div id=
=3D"yiv0245518097"><div id=3D"yiv0245518097yui_3_16_0_1_1419806870697_71097=
7"><div><span></span></div><div id=3D"yiv0245518097yui_3_16_0_1_14198068706=
97_710976"><div id=3D"yiv0245518097yui_3_16_0_1_1419806870697_710985"><br c=
lear=3D"none"></div><div id=3D"yiv0245518097yui_3_16_0_1_1419806870697_7109=
83">On 31 Dec 2014, at 19:27, Benjamin Kaduk &lt;<a rel=3D"nofollow" shape=
=3D"rect" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_712334" ymailto=3D"=
mailto:kaduk@MIT.EDU" target=3D"_blank" href=3D"mailto:kaduk@MIT.EDU">kaduk=
@MIT.EDU</a>&gt; wrote:<br clear=3D"none"><br clear=3D"none"></div><blockqu=
ote id=3D"yiv0245518097yui_3_16_0_1_1419806870697_711172" type=3D"cite"><di=
v id=3D"yiv0245518097yui_3_16_0_1_1419806870697_711171"><span id=3D"yiv0245=
518097yui_3_16_0_1_1419806870697_712332">We've gotten some "looks good"s on=
 the oauth list, for those only on</span><br clear=3D"none"><span>kitten@.<=
/span><br clear=3D"none"><span></span><br clear=3D"none"><span id=3D"yiv024=
5518097yui_3_16_0_1_1419806870697_712330">Just under two weeks remain in th=
e last call period.</span><br clear=3D"none"></div></blockquote><div id=3D"=
yiv0245518097yui_3_16_0_1_1419806870697_711169"><br clear=3D"none"></div><d=
iv id=3D"yiv0245518097yui_3_16_0_1_1419806870697_711156" style=3D"">I gener=
ally think that the document has improved recently and it is very close to =
being done. But I think examples in particular need to be fixed (and I am s=
orry if I sound like a broken record on this, but I believe that examples a=
re very important, as some people will just code based on them).</div><div =
id=3D"yiv0245518097yui_3_16_0_1_1419806870697_711158" style=3D""><br clear=
=3D"none"></div><div id=3D"yiv0245518097yui_3_16_0_1_1419806870697_711160" =
style=3D"">In 3.1:</div><div id=3D"yiv0245518097yui_3_16_0_1_1419806870697_=
711162" style=3D""><span style=3D"font-family:Courier;font-size:10pt;backgr=
ound-color:rgb(255, 255, 255);"><br clear=3D"none"></span></div><div style=
=3D""><span style=3D"font-family:Courier;font-size:10pt;background-color:rg=
b(255, 255, 255);">key            =3D 1*(ALPHA / ",")</span></div><div id=
=3D"yiv0245518097yui_3_16_0_1_1419806870697_711044" style=3D""><div class=
=3D"yiv0245518097page" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_711043=
" title=3D"Page 7"><div class=3D"yiv0245518097section" id=3D"yiv0245518097y=
ui_3_16_0_1_1419806870697_711042" style=3D"background-color:rgb(255, 255, 2=
55);"><div class=3D"yiv0245518097layoutArea" id=3D"yiv0245518097yui_3_16_0_=
1_1419806870697_711041"><div class=3D"yiv0245518097column" id=3D"yiv0245518=
097yui_3_16_0_1_1419806870697_711040"><pre id=3D"yiv0245518097yui_3_16_0_1_=
1419806870697_711039"><span style=3D"font-size:10pt;font-family:Courier;"><=
br clear=3D"none"></span></pre><pre><span style=3D"font-size:10pt;font-fami=
ly:Courier;">So the key can be a single comma character, right?</span></pre=
></div></div></div></div></div><div id=3D"yiv0245518097yui_3_16_0_1_1419806=
870697_711004" style=3D""><div class=3D"yiv0245518097page" id=3D"yiv0245518=
097yui_3_16_0_1_1419806870697_711003" title=3D"Page 7"><div class=3D"yiv024=
5518097section" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_711002" style=
=3D"background-color:rgb(255, 255, 255);"><div class=3D"yiv0245518097layout=
Area" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_711001"><div class=3D"y=
iv0245518097column" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_711000"><=
pre id=3D"yui_3_16_0_1_1419806870697_725376"><span style=3D"font-size:10pt;=
font-family:Courier;">client_resp    =3D (gs2-header kvsep 0*kvpair kvsep) =
/ kvsep
</span></pre><pre id=3D"yiv0245518097yui_3_16_0_1_1419806870697_710999"><sp=
an style=3D"font-size:10pt;font-family:Courier;"><br clear=3D"none"></span>=
</pre><pre id=3D"yiv0245518097yui_3_16_0_1_1419806870697_711025"><span id=
=3D"yiv0245518097yui_3_16_0_1_1419806870697_711024" style=3D"font-size:10pt=
;font-family:Courier;">Did you mean that the whole client response can be j=
ust a single separator character? I think this is not compatible with GS2 f=
raming. </span><span style=3D"font-family:Courier;font-size:10pt;" id=3D"yu=
i_3_16_0_1_1419806870697_725380">If you only meant to allow that for failed=
 authentication, I suggest you add a comment and point to section 3.2.3.</s=
pan></pre></div></div></div></div></div><div style=3D"">In 3.2:</div><div s=
tyle=3D""><br clear=3D"none"></div><div style=3D"" id=3D"yui_3_16_0_1_14198=
06870697_726901">Nit:</div><div style=3D"" id=3D"yui_3_16_0_1_1419806870697=
_720948"><div class=3D"yiv0245518097page" title=3D"Page 8" id=3D"yui_3_16_0=
_1_1419806870697_720947"><div class=3D"yiv0245518097section" style=3D"backg=
round-color:rgb(255, 255, 255);" id=3D"yui_3_16_0_1_1419806870697_720946"><=
div class=3D"yiv0245518097layoutArea" id=3D"yui_3_16_0_1_1419806870697_7209=
45"><div class=3D"yiv0245518097column" id=3D"yui_3_16_0_1_1419806870697_720=
944"><pre id=3D"yui_3_16_0_1_1419806870697_720943"><span style=3D"font-size=
:10pt;font-family:Courier;"> Note that the semantics of the authz-id is spe=
cified by
   the SASL framework [</span><span style=3D"font-size:10pt;font-family:Cou=
rier;color:rgb(0, 0, 255);">RFC4422</span><span style=3D"font-size:10pt;fon=
t-family:Courier;">].
</span></pre></div></div></div></div></div><div style=3D"">If this is the s=
ame as "authzid" introduced in section 3.1, then you should remove dash. (I=
 was wondering if this is something else). But I think expanding this to be=
 "authorization identity" would be better.</div><div style=3D"" id=3D"yui_3=
_16_0_1_1419806870697_726903"><br clear=3D"none"></div><div style=3D"" id=
=3D"yui_3_16_0_1_1419806870697_726905">In 3.2.2:</div><div id=3D"yiv0245518=
097yui_3_16_0_1_1419806870697_711153" style=3D""><div class=3D"yiv024551809=
7page" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_711152" title=3D"Page =
9"><div class=3D"yiv0245518097section" id=3D"yiv0245518097yui_3_16_0_1_1419=
806870697_711151" style=3D"background-color:rgb(255, 255, 255);"><div class=
=3D"yiv0245518097layoutArea" id=3D"yiv0245518097yui_3_16_0_1_1419806870697_=
711150"><div class=3D"yiv0245518097column" id=3D"yiv0245518097yui_3_16_0_1_=
1419806870697_711149"><pre id=3D"yiv0245518097yui_3_16_0_1_1419806870697_71=
1148"><span id=3D"yiv0245518097yui_3_16_0_1_1419806870697_711147" style=3D"=
font-size:10pt;font-family:Courier;">oauth-configuration (OPTIONAL):  The U=
RL for for a document
         following the OpenID Provider Configuration Information schema
         as described in OpenID Connect Discovery
</span></pre></div></div></div></div></div><div style=3D"">I think it would=
 help to clarify that the returned value is always an https (or http?) URI.=
 If that can be something else, saying that would be great too.</div><div s=
tyle=3D"" id=3D"yui_3_16_0_1_1419806870697_729162"><br clear=3D"none"></div=
><div style=3D"" id=3D"yui_3_16_0_1_1419806870697_729164">In 3.2.3:</div><d=
iv style=3D"" id=3D"yui_3_16_0_1_1419806870697_726907"><br clear=3D"none"><=
/div><div style=3D"" id=3D"yui_3_16_0_1_1419806870697_726909">I think you d=
on't need to have an explicit message to cancel authentication, you can jus=
t use the SASL framework facility for this. In IMAP that would be emitted a=
s "*\r\n".</div><div style=3D"" id=3D"yui_3_16_0_1_1419806870697_730757"><b=
r clear=3D"none"></div><div style=3D"" id=3D"yui_3_16_0_1_1419806870697_730=
745">In particular, I think Cyrus SASL based implementations can handle "he=
re is some data from the server, but this step produces failure on the clie=
nt side, so the client need to cancel the exchange" just fine.</div><div st=
yle=3D"" id=3D"yui_3_16_0_1_1419806870697_730747"><br clear=3D"none"></div>=
<div style=3D"" id=3D"yui_3_16_0_1_1419806870697_720955">In 4.1:</div><div =
style=3D"" id=3D"yui_3_16_0_1_1419806870697_730755"><br clear=3D"none"></di=
v><div style=3D"" id=3D"yui_3_16_0_1_1419806870697_720953">I think you need=
 to explain that the example is only valid in the presence of SASL-IR capab=
ility (and add an Informative reference), because the initial client respon=
se parameter to AUTHENTICATE is only allowed when SASL-IR is advertised. Or=
 you can just use an SMTP example here.</div><div style=3D"" id=3D"yui_3_16=
_0_1_1419806870697_730749"><br clear=3D"none"></div><div style=3D"" id=3D"y=
ui_3_16_0_1_1419806870697_730751"><br clear=3D"none"></div><div style=3D"" =
id=3D"yui_3_16_0_1_1419806870697_721885">Examples in 4.1, 4.3 and 4.4 don't=
 show negotiation of TLS, which is a MUST level requirement for AUTHBEARER =
SASL mechanism (as per section 5), so you should fix examples to advertise =
STARTTLS capability and show use of STARTTLS command.</div><div style=3D"">=
<br clear=3D"none"></div><div style=3D"">If you would like me to provide fu=
ll examples, let me know and I do that.</div><div class=3D"yiv0245518097yqt=
4926020949" id=3D"yiv0245518097yqtfd08928"><div><br clear=3D"none"></div><b=
lockquote type=3D"cite" id=3D"yui_3_16_0_1_1419806870697_720951"><div id=3D=
"yui_3_16_0_1_1419806870697_720950"><span></span><br clear=3D"none"><span>-=
Ben</span><br clear=3D"none"><span></span><br clear=3D"none"><span>On Mon, =
15 Dec 2014, Benjamin Kaduk wrote:</span><br clear=3D"none"><span></span><b=
r clear=3D"none"><blockquote type=3D"cite"><span>This message begins the fo=
urth Working Group Last Call (WGLC) of "A set of</span><br clear=3D"none"><=
/blockquote><blockquote type=3D"cite"><span>SASL Mechanisms for OAuth" &lt;=
draft-ietf-kitten-sasl-oauth-18.txt&gt;. &nbsp;Due to</span><br clear=3D"no=
ne"></blockquote><blockquote type=3D"cite"><span>the overlap of the last ca=
ll period with holidays, the duration of the</span><br clear=3D"none"></blo=
ckquote><blockquote type=3D"cite"><span>WGLC is extended to four weeks, so =
the WGLC will end on 12 January 2015.</span><br clear=3D"none"></blockquote=
><blockquote type=3D"cite"><span>The draft is available at:</span><br clear=
=3D"none"></blockquote><blockquote type=3D"cite"><span></span><br clear=3D"=
none"></blockquote><blockquote type=3D"cite"><span><a rel=3D"nofollow" shap=
e=3D"rect" target=3D"_blank" href=3D"https://tools.ietf.org/html/draft-ietf=
-kitten-sasl-oauth-18">https://tools.ietf.org/html/draft-ietf-kitten-sasl-o=
auth-18</a></span><br clear=3D"none"></blockquote><blockquote type=3D"cite"=
><span></span><br clear=3D"none"></blockquote><blockquote type=3D"cite"><sp=
an>Because the changes between -15 and -18 involve behavior changes,</span>=
<br clear=3D"none"></blockquote><blockquote type=3D"cite"><span>including c=
hanges regarding discovery and dynamic registration, the Chairs</span><br c=
lear=3D"none"></blockquote><blockquote type=3D"cite"><span>decided to issue=
 an additional last call.</span><br clear=3D"none"></blockquote><blockquote=
 type=3D"cite"><span></span><br clear=3D"none"></blockquote><blockquote typ=
e=3D"cite"><span>Please review the document and send comments to the Workin=
g Group</span><br clear=3D"none"></blockquote><blockquote type=3D"cite"><sp=
an>mailing list &lt; kitten at <a rel=3D"nofollow" shape=3D"rect" target=3D=
"_blank" href=3D"http://itef.org/">itef.org</a> &gt; or the co-chairs &lt; =
kitten-chairs</span><br clear=3D"none"></blockquote><blockquote type=3D"cit=
e"><span>at <a rel=3D"nofollow" shape=3D"rect" target=3D"_blank" href=3D"ht=
tp://tools.ietf.org/">tools.ietf.org</a> &gt; before the end of the WGLC. &=
nbsp;Any and all comments</span><br clear=3D"none"></blockquote><blockquote=
 type=3D"cite"><span>on the document are sought in order to access the stre=
ngth of</span><br clear=3D"none"></blockquote><blockquote type=3D"cite"><sp=
an>consensus. &nbsp;Even if you have read and commented on this or earlier<=
/span><br clear=3D"none"></blockquote><blockquote type=3D"cite"><span>versi=
ons of the draft, please feel free to comment again. &nbsp;This is</span><b=
r clear=3D"none"></blockquote><blockquote type=3D"cite"><span>particularly =
important if you found issues with the previous version.</span><br clear=3D=
"none"></blockquote><blockquote type=3D"cite"><span></span><br clear=3D"non=
e"></blockquote><blockquote type=3D"cite" id=3D"yui_3_16_0_1_1419806870697_=
729158"><span id=3D"yui_3_16_0_1_1419806870697_729157">As a reminder, comme=
nts can be anything from "this looks fine" to</span><br clear=3D"none"></bl=
ockquote><blockquote type=3D"cite"><span>"this is a horrible idea"; they ca=
n include suggestions for minor</span><br clear=3D"none"></blockquote><bloc=
kquote type=3D"cite"><span>editorial corrections to significant editorial c=
hanges.</span><br clear=3D"none"></blockquote><blockquote type=3D"cite"><sp=
an></span><br clear=3D"none"></blockquote><blockquote type=3D"cite"><span><=
/span><br clear=3D"none"></blockquote><blockquote type=3D"cite"><span>- You=
r Kitten Chairs</span><br clear=3D"none"></blockquote><blockquote type=3D"c=
ite"><span></span><br clear=3D"none"></blockquote><blockquote type=3D"cite"=
><span>_______________________________________________</span><br clear=3D"n=
one"></blockquote><blockquote type=3D"cite"><span>Kitten mailing list</span=
><br clear=3D"none"></blockquote><blockquote type=3D"cite"><span><a rel=3D"=
nofollow" shape=3D"rect" ymailto=3D"mailto:Kitten@ietf.org" target=3D"_blan=
k" href=3D"mailto:Kitten@ietf.org">Kitten@ietf.org</a></span><br clear=3D"n=
one"></blockquote><blockquote type=3D"cite"><span><a rel=3D"nofollow" shape=
=3D"rect" target=3D"_blank" href=3D"https://www.ietf.org/mailman/listinfo/k=
itten">https://www.ietf.org/mailman/listinfo/kitten</a></span><br clear=3D"=
none"></blockquote><blockquote type=3D"cite"><span></span><br clear=3D"none=
"></blockquote><span></span><br clear=3D"none"><span id=3D"yui_3_16_0_1_141=
9806870697_729160">_______________________________________________</span><b=
r clear=3D"none"><span>Kitten mailing list</span><br clear=3D"none"><span><=
a rel=3D"nofollow" shape=3D"rect" ymailto=3D"mailto:Kitten@ietf.org" target=
=3D"_blank" href=3D"mailto:Kitten@ietf.org">Kitten@ietf.org</a></span><br c=
lear=3D"none"><span><a rel=3D"nofollow" shape=3D"rect" target=3D"_blank" hr=
ef=3D"https://www.ietf.org/mailman/listinfo/kitten">https://www.ietf.org/ma=
ilman/listinfo/kitten</a></span><br clear=3D"none"></div></blockquote></div=
></div></div></div><br clear=3D"none"><div class=3D"yiv0245518097yqt4926020=
949" id=3D"yiv0245518097yqtfd47896">_______________________________________=
________<br clear=3D"none">Kitten mailing list<br clear=3D"none"><a rel=3D"=
nofollow" shape=3D"rect" ymailto=3D"mailto:Kitten@ietf.org" target=3D"_blan=
k" href=3D"mailto:Kitten@ietf.org">Kitten@ietf.org</a><br clear=3D"none"><a=
 rel=3D"nofollow" shape=3D"rect" target=3D"_blank" href=3D"https://www.ietf=
.org/mailman/listinfo/kitten">https://www.ietf.org/mailman/listinfo/kitten<=
/a><br clear=3D"none"></div><br clear=3D"none"><br clear=3D"none"></div></d=
iv>  </div> </div>  </div> </div></div></div></div></body></html>
------=_Part_3860511_76983976.1420246607258--


From nobody Sat Jan  3 08:56:44 2015
Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE3AF1A9037; Sat,  3 Jan 2015 08:56:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U2yc-L-IkMWk; Sat,  3 Jan 2015 08:56:39 -0800 (PST)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 66AE91A9035; Sat,  3 Jan 2015 08:56:39 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id 78CBEBEF4; Sat,  3 Jan 2015 16:56:37 +0000 (GMT)
X-Virus-Scanned: Debian amavisd-new at scss.tcd.ie
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7omE9n57cqW7; Sat,  3 Jan 2015 16:56:35 +0000 (GMT)
Received: from [10.87.48.73] (unknown [86.46.27.117]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id CC20BBEDE; Sat,  3 Jan 2015 16:56:35 +0000 (GMT)
Message-ID: <54A81F41.2010207@cs.tcd.ie>
Date: Sat, 03 Jan 2015 16:56:33 +0000
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: "kitten@ietf.org" <kitten@ietf.org>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/EK6JHm9tHV6JkNtBJsZfu9xEo3U
Cc: IESG <iesg@ietf.org>
Subject: [kitten] draft-ietf-kitten-cammac IESG evaluation emails
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 03 Jan 2015 16:56:42 -0000

Hiya,

Looks like I messed up the set of email addresses being copied
on IESG evaluation for this draft. (Thanks Kathleen for spotting
that and I just fixed it.)

I think the only substantive thing so far not seen is Barry's
comment [1] and Ben's response that said:

"
That's basically correct.  There's a table in section 5.2.6 of RFC 4120
which lists how the contents of the ad-data member are to be interpreted
for a given ad-type value, which one could say this document is also
updating.
"

So we probably want to add an RFC editor note if that's the only
change. But let's see what else turns up in IESG eval.

Apologies,
S.

[1]
https://datatracker.ietf.org/doc/draft-ietf-kitten-cammac/ballot/#barry-leiba


From nobody Sun Jan  4 03:37:44 2015
Return-Path: <alexey.melnikov@isode.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AF1D51A8739 for <kitten@ietfa.amsl.com>; Sun,  4 Jan 2015 03:37:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.111
X-Spam-Level: 
X-Spam-Status: No, score=-0.111 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vwLFGn906b_Z for <kitten@ietfa.amsl.com>; Sun,  4 Jan 2015 03:37:41 -0800 (PST)
Received: from waldorf.isode.com (ext-bt.isode.com [217.34.220.158]) by ietfa.amsl.com (Postfix) with ESMTP id 3E9011A8710 for <kitten@ietf.org>; Sun,  4 Jan 2015 03:37:41 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1420371460; d=isode.com; s=selector; i=@isode.com; bh=afhGWEGTJ1ILPNykr2RSMrJHpxwQCjsYHg7Ij6V89IU=; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version: In-Reply-To:References:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description; b=SCNH2V2plSLhkbq5vVOc7qhieV+5C0ZluMjw/AEveAExPSOrg6vvxB8zQWp4yYtZym0wO9 QHHAHRaL+Bwl0Eq/niI1Kav9OIh73jN8soe8G/ihrpQkHS2M78JrnCOHxob6pUZtTyW1/Y wzy3svBl/9tbg6JzHFNXctH6bXVJZ+U=;
Received: from [192.168.0.12] (cpc5-nmal20-2-0-cust24.19-2.cable.virginm.net [92.234.84.25])  by waldorf.isode.com (submission channel) via TCP with ESMTPSA  id <VKkmAwAKaEH-@waldorf.isode.com>; Sun, 4 Jan 2015 11:37:40 +0000
X-SMTP-Protocol-Errors: PIPELINING
From: Alexey Melnikov <alexey.melnikov@isode.com>
X-Mailer: iPad Mail (12B435)
In-Reply-To: <377717803.3860512.1420246607276.JavaMail.yahoo@jws10611.mail.bf1.yahoo.com>
Date: Sun, 4 Jan 2015 11:42:22 +0000
Message-Id: <F4209A2F-CEB5-498B-9DA9-1C4628C64BE4@isode.com>
References: <3D9D6627-F6B2-456C-9C24-F224989B1979@isode.com> <377717803.3860512.1420246607276.JavaMail.yahoo@jws10611.mail.bf1.yahoo.com>
To: Bill Mills <wmills_92105@yahoo.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/iq5GQniAEM6xwdTAZqAnSb-c8l8
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Jan 2015 11:37:43 -0000

Hi Bill,

> On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:
>=20
> 3.2.3 and an explicit message:  Long ago in the life of this doc I was tol=
d that some implementations may not support an empty message, so we put the s=
ingle character message there to have an explicit payload.  I'm a bit leery o=
f changing this now since there are implementations in play that use it this=
 way.

I didn't suggest you should be sending empty message. I said you should be u=
sing SASL cancellation token, which is a mandatory RFC 4422 feature.

Any implementation would have to support this mode of operation anyway, beca=
use a SASL client can cancel any exchange.



From nobody Sun Jan  4 03:41:31 2015
Return-Path: <alexey.melnikov@isode.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E7F9B1A876C for <kitten@ietfa.amsl.com>; Sun,  4 Jan 2015 03:41:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.408
X-Spam-Level: 
X-Spam-Status: No, score=-1.408 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, J_CHICKENPOX_41=0.6, MIME_QP_LONG_LINE=0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pe2-q20MsLI6 for <kitten@ietfa.amsl.com>; Sun,  4 Jan 2015 03:41:28 -0800 (PST)
Received: from waldorf.isode.com (ext-bt.isode.com [217.34.220.158]) by ietfa.amsl.com (Postfix) with ESMTP id 9BD881A8710 for <kitten@ietf.org>; Sun,  4 Jan 2015 03:41:28 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1420371687; d=isode.com; s=selector; i=@isode.com; bh=YiPVmPc4EfyNftEsb4a6BB9yU/6WxCpqP885bNvLTT4=; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version: In-Reply-To:References:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description; b=r9IP1hdZWuKdRpT5eMa6RnE1bscroaLqVcXEaCn6NA2mYQj1HXuhOyGXT9H/GRSaqcNQx7 JwPKkHMe4/6V/nfFOEuf8j4cFwCK++RuDUMZox8BK/3tqzPePJ1F6uaxfIW8EfBZWU2crH X6GvIQoZZK62C5MtLSPdyb2mfW0b1EE=;
Received: from [192.168.0.12] (cpc5-nmal20-2-0-cust24.19-2.cable.virginm.net [92.234.84.25])  by waldorf.isode.com (submission channel) via TCP with ESMTPSA  id <VKkm5wAKaH8M@waldorf.isode.com>; Sun, 4 Jan 2015 11:41:27 +0000
X-SMTP-Protocol-Errors: PIPELINING
From: Alexey Melnikov <alexey.melnikov@isode.com>
X-Mailer: iPad Mail (12B435)
In-Reply-To: <377717803.3860512.1420246607276.JavaMail.yahoo@jws10611.mail.bf1.yahoo.com>
Date: Sun, 4 Jan 2015 11:46:10 +0000
Message-Id: <78174425-E391-4E6D-85DD-99D3B3A715EC@isode.com>
References: <3D9D6627-F6B2-456C-9C24-F224989B1979@isode.com> <377717803.3860512.1420246607276.JavaMail.yahoo@jws10611.mail.bf1.yahoo.com>
To: Bill Mills <wmills_92105@yahoo.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary=Apple-Mail-81320BF5-E536-4662-8B48-BE6163C124A0
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/uWGvVh5gsQkxAuUdFfoEgafy-_o
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Jan 2015 11:41:30 -0000

--Apple-Mail-81320BF5-E536-4662-8B48-BE6163C124A0
Content-Type: text/plain;
	charset=us-ascii
Content-Transfer-Encoding: quoted-printable

Hi Bill,

> On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:
>=20
> On requiring TLS and adding STARTTLS to the examples: your'e not happy wit=
h the current "Note that line 	breaks are inserted for readability and the=
 underlying TLS establishment is not shown either."?  I'd prefer to add text=
 saying something like "These Bearer token examples assume encrypted transpo=
rt, if the underlying connection is not already TLS then STARTTLS MUST be us=
ed as required in the Bearer Token specification.".

Yes, that would work and I think your expanded text is better.

>  I can also easily specify that this is IMAP over 995

993
> or SMTP over 465.

I suggest you don't do that, because neither port 993 nor 465 are registered=
 with IANA. I know it is not your problem, but there is no point in potentia=
lly getting this document delayed by this.


--Apple-Mail-81320BF5-E536-4662-8B48-BE6163C124A0
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><div>Hi Bill,</div><div><br>On 3 Jan 2015, a=
t 00:56, Bill Mills &lt;<a href=3D"mailto:wmills_92105@yahoo.com">wmills_921=
05@yahoo.com</a>&gt; wrote:<br><br></div><blockquote type=3D"cite">On requir=
ing TLS and adding STARTTLS to the examples: your'e not happy with the curre=
nt "<span style=3D"font-size: 12px;" class=3D"">Note that line&nbsp;</span><=
span class=3D"" style=3D"font-size: 12px; white-space: pre;">	</span><spa=
n style=3D"font-size: 12px;" id=3D"yui_3_16_0_1_1419806870697_724221">breaks=
 are inserted for readability and the underlying TLS establishment is not sh=
own either."? &nbsp;I'd prefer to add text saying something like "These Bear=
er token examples assume encrypted transport, if the underlying connection i=
s not already TLS then STARTTLS MUST be used as required in the Bearer Token=
 specification.".</span></blockquote><div><br></div>Yes, that would work and=
 I think your expanded text is better.<div><br><blockquote type=3D"cite"><sp=
an style=3D"font-size: 12px;" id=3D"yui_3_16_0_1_1419806870697_724221"> &nbs=
p;I can also easily specify that this is IMAP over 995</span></blockquote><d=
iv><br></div>993<br><blockquote type=3D"cite"><span style=3D"font-size: 12px=
;" id=3D"yui_3_16_0_1_1419806870697_724221">or SMTP over 465.</span></blockq=
uote><br></div><div>I suggest you don't do that, because neither port 993 no=
r 465 are registered with IANA. I know it is not your problem, but there is n=
o point in potentially getting this document delayed by this.</div><div><br>=
</div></body></html>=

--Apple-Mail-81320BF5-E536-4662-8B48-BE6163C124A0--


From nobody Sun Jan  4 03:44:55 2015
Return-Path: <alexey.melnikov@isode.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2585C1A87CA for <kitten@ietfa.amsl.com>; Sun,  4 Jan 2015 03:44:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.01
X-Spam-Level: 
X-Spam-Status: No, score=-2.01 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mdWoJexl9xQo for <kitten@ietfa.amsl.com>; Sun,  4 Jan 2015 03:44:53 -0800 (PST)
Received: from waldorf.isode.com (ext-bt.isode.com [217.34.220.158]) by ietfa.amsl.com (Postfix) with ESMTP id DD7FC1A03C7 for <kitten@ietf.org>; Sun,  4 Jan 2015 03:44:52 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1420371892; d=isode.com; s=selector; i=@isode.com; bh=YCMBkxnnM1OjTCTjH4HrYluNJ4/oEdXXlEBQF/GZSK0=; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version: In-Reply-To:References:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description; b=QPlLiHfmaYKsm4Cy17HLSclUcs/xKliR152Wn5j7f2W8Kq6xdRJSW5S+HiNWY6smVQwqFO 4jSfXIYMpeTFOel3Px/id/les4RuRaq83agLUdYLxRTFr9cyLj7zCnqu9rlBfcpyQLCSmt qHrnG1oehE4lGEQSDxPfUu4tnsLpmQ0=;
Received: from [192.168.0.12] (cpc5-nmal20-2-0-cust24.19-2.cable.virginm.net [92.234.84.25])  by waldorf.isode.com (submission channel) via TCP with ESMTPSA  id <VKknswAKaLYV@waldorf.isode.com>; Sun, 4 Jan 2015 11:44:52 +0000
X-SMTP-Protocol-Errors: PIPELINING
From: Alexey Melnikov <alexey.melnikov@isode.com>
X-Mailer: iPad Mail (12B435)
In-Reply-To: <377717803.3860512.1420246607276.JavaMail.yahoo@jws10611.mail.bf1.yahoo.com>
Date: Sun, 4 Jan 2015 11:49:34 +0000
Message-Id: <0FBE45D4-68AE-46D8-B42E-A1DAA8557F2F@isode.com>
References: <3D9D6627-F6B2-456C-9C24-F224989B1979@isode.com> <377717803.3860512.1420246607276.JavaMail.yahoo@jws10611.mail.bf1.yahoo.com>
To: Bill Mills <wmills_92105@yahoo.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/wfm4uNNLeq8VHilQRfvOQnPBW84
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Jan 2015 11:44:54 -0000

Hi Bill,

> On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:
>=20
> re 3.2.2 and the OpendID configuration URL.  That spec requires "https" ex=
plicitly already.  Repeat that here?  Easy to cite that spec and say HTTPS i=
s required but I usually try not to repeat things defined other places.

I would prefer if you add "as per XXX spec, this is always "https" URL". Thi=
s might be obvious for somebody who knows OpenID specs in details, but I thi=
nk this sort reminder would help implementors who don't have time to researc=
h this in details.

Best Regards,
Alexey


From nobody Sun Jan  4 14:30:55 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 536C61A0231; Sun,  4 Jan 2015 14:30:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XHj-3YpW8Rzc; Sun,  4 Jan 2015 14:30:51 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id E64A51A0147; Sun,  4 Jan 2015 14:30:51 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.0.p1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150104223051.25758.7861.idtracker@ietfa.amsl.com>
Date: Sun, 04 Jan 2015 14:30:51 -0800
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/QF29wl81zugQD7ZhdI91PVGgzOE
Cc: kitten@ietf.org
Subject: [kitten] I-D Action: draft-ietf-kitten-gss-loop-04.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Jan 2015 22:30:53 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Common Authentication Technology Next Generation Working Group of the IETF.

        Title           : Structure of the GSS Negotiation Loop
        Author          : Benjamin Kaduk
	Filename        : draft-ietf-kitten-gss-loop-04.txt
	Pages           : 20
	Date            : 2015-01-04

Abstract:
   This document specifies the generic structure of the negotiation loop
   to establish a GSS security context between initiator and acceptor.
   The control flow of the loop is indicated for both parties, including
   error conditions, and indications are given for where application-
   specific behavior must be specified.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-kitten-gss-loop/

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-kitten-gss-loop-04

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=draft-ietf-kitten-gss-loop-04


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Sun Jan  4 14:31:53 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AD2A41A0147 for <kitten@ietfa.amsl.com>; Sun,  4 Jan 2015 14:31:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DWaFOmGuiDEa for <kitten@ietfa.amsl.com>; Sun,  4 Jan 2015 14:31:50 -0800 (PST)
Received: from dmz-mailsec-scanner-3.mit.edu (dmz-mailsec-scanner-3.mit.edu [18.9.25.14]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 773CC1A004C for <kitten@ietf.org>; Sun,  4 Jan 2015 14:31:50 -0800 (PST)
X-AuditID: 1209190e-f799e6d000000cfe-cc-54a9bf552bc4
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-3.mit.edu (Symantec Messaging Gateway) with SMTP id 16.F1.03326.55FB9A45; Sun,  4 Jan 2015 17:31:49 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id t04MVmhF032074 for <kitten@ietf.org>; Sun, 4 Jan 2015 17:31:49 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t04MVljd015666 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Sun, 4 Jan 2015 17:31:48 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t04MVknN009414; Sun, 4 Jan 2015 17:31:46 -0500 (EST)
Date: Sun, 4 Jan 2015 17:31:46 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
In-Reply-To: <20150104223051.25758.7861.idtracker@ietfa.amsl.com>
Message-ID: <alpine.GSO.1.10.1501041731160.23489@multics.mit.edu>
References: <20150104223051.25758.7861.idtracker@ietfa.amsl.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrKIsWRmVeSWpSXmKPExsUixG6nohu6f2WIwbv7khZHN69icWD0WLLk J1MAYxSXTUpqTmZZapG+XQJXxsoGjoK5nBWbX89lbGBsZ+9i5OSQEDCR6P8wiQXCFpO4cG89 WxcjF4eQwGImieN7XrBDOMcYJQ7/uMoIUiUkcJ1JordBBsKul1i1oYcVxGYR0JLomXoezGYT UJGY+WYjG4gtIiAssXvrO2YQW1jAWWLjnV1gNZwCjhIzZjSBXcELZM//sIMZYqaDRO/K42C2 qICOxOr9U1ggagQlTs58AmYzA+1aPn0bywRGgVlIUrOQpBYwMq1ilE3JrdLNTczMKU5N1i1O TszLSy3SNdbLzSzRS00p3cQICj1OSb4djF8PKh1iFOBgVOLhFWBcGSLEmlhWXJl7iFGSg0lJ lNdvD1CILyk/pTIjsTgjvqg0J7X4EKMEB7OSCO+yOytChHhTEiurUovyYVLSHCxK4rybfvCF CAmkJ5akZqemFqQWwWRlODiUJHjX7AUaKliUmp5akZaZU4KQZuLgBBnOAzT8IkgNb3FBYm5x ZjpE/hSjopQ473mQhABIIqM0D64XlhpeMYoDvSLM+xykigeYVuC6XwENZgIa/HnZcpDBJYkI KakGxqUPHXiUeeXYD1nnbuM7YMt/98LmsEMhd/pE64SlJ3wUbfINncwxMyv0zpU70xbsc3hk cN7lf8I3nrqtNyYuNJv9kvP+7D0+1w/znZ5S/6f78r/HEcHhT/Qy3x+bPjGT2d9sQZLG1nZZ 375GaZ9rwS/rzvrZ8YnzhG/L5uf/avyOp8R09sd1G5RYijMSDbWYi4oTAdijygLoAgAA
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/HP68W2UnNGofGDitJNYFbkqeCIc
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-gss-loop-04.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Jan 2015 22:31:52 -0000

On Sun, 4 Jan 2015, internet-drafts@ietf.org wrote:

>
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
>  This draft is a work item of the Common Authentication Technology Next Generation Working Group of the IETF.
>
>         Title           : Structure of the GSS Negotiation Loop
>         Author          : Benjamin Kaduk
> 	Filename        : draft-ietf-kitten-gss-loop-04.txt
> 	Pages           : 20
> 	Date            : 2015-01-04
>
> Abstract:
>    This document specifies the generic structure of the negotiation loop
>    to establish a GSS security context between initiator and acceptor.
>    The control flow of the loop is indicated for both parties, including
>    error conditions, and indications are given for where application-
>    specific behavior must be specified.
>
>
> There's also a htmlized version available at:
> http://tools.ietf.org/html/draft-ietf-kitten-gss-loop-04
>
> A diff from the previous version is available at:
> http://www.ietf.org/rfcdiff?url2=draft-ietf-kitten-gss-loop-04

This is just a few more nits found during shepherd review, that I missed
fixing in the -03.

-Ben


From nobody Sun Jan  4 21:14:26 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6C6841A1B15 for <kitten@ietfa.amsl.com>; Sun,  4 Jan 2015 21:14:24 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iMKlwBsGQ-wN for <kitten@ietfa.amsl.com>; Sun,  4 Jan 2015 21:14:23 -0800 (PST)
Received: from nm6.bullet.mail.bf1.yahoo.com (nm6.bullet.mail.bf1.yahoo.com [98.139.212.165]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C0B1B1A1B00 for <kitten@ietf.org>; Sun,  4 Jan 2015 21:14:22 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1420434861; bh=AXHQuniSbJUMEKUNNIngmoikzaMGOWjoffRpvP8erdA=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=C+iYFkiDdMMawHSV2K2JXvPNbrlTOQz9EAlY4Jje5xouF406XZGe3ChwOdOolEvSU5BjGj+uHPTCDU+13jdxmQenISi1YcmAwWkoAUKCC9qc8lmFAdwTG5N5LtI12C4RE8PHfNehYufG2Ifp48SO75WREcQwWFe+5JGlU2ATTLqD3EYqwnrQlZSC5wh//HWnj2aIHAe8/lE25GI4CeRZuCfzsJDQ18WgvGWgO2UG/lQn2wVYYd/8PpNdPlTf8ybclkzjl4vWqAuj9l1f8etdpNPwRrFXco6djelBTWsOlcl1/ncB3nnO2fG/lDWkoOfAxnFxEjWq6FeVuc5rQbukUQ==
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s2048; d=yahoo.com; b=ROQnzCQqO1IABqYYWgJitiR1QXqgA65jLB7RafovqSCwozHXHY8KD8/y6b5CygNOe8psVVK5DqYF61DAtdbJrahQRfivWlqTmQup9uZwNOcKYxMfLdICNHDMP+gPWct7rH1qlwbT8JVZXFWMmvJNF4zipsqQwA6FOpGyp9qL2ojHa+nsCCP7HgSPUEZgp5kSHn/mDrFcEbI6aMFrISMo0vziGLZ8+q6KakF3MQ6FpuNHwa477uOrMSoyQeDihuRtKtdJOpFeN+LkMBPaV3JsN74QCSJO1QAoJrjuDoJnoPCn7uV/S19B9I+EEGxCYpO/b3QHP3efnc+V58cWvY98bA==;
Received: from [98.139.215.143] by nm6.bullet.mail.bf1.yahoo.com with NNFMP; 05 Jan 2015 05:14:21 -0000
Received: from [98.139.212.249] by tm14.bullet.mail.bf1.yahoo.com with NNFMP;  05 Jan 2015 05:14:21 -0000
Received: from [127.0.0.1] by omp1058.mail.bf1.yahoo.com with NNFMP; 05 Jan 2015 05:14:21 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 953301.62082.bm@omp1058.mail.bf1.yahoo.com
X-YMail-OSG: .XxPqN4VM1nHtxtFvdBySXb2LRIrxr73OOAVPU0SPjW_8Go51kHy6aDV4_YYBvd sjxHVYAFEEZtX8jIt7zvcQQuPm7iR_qlnZTlZdapJ8aSAzT0Gtql8ygz_Z1zAqZKgXoPTS6hArcu jv12Xm24msGsJ8R0H8AjQ5yxdTb2FM6ZACvS1bFmsGDCHVaDlPMZ3WjD5eoJK0WRmEPt8wkX7EnB EkVQwajEe_Et1x5dhuRMw4SSUd9bxTeQLrUmWW7QkBIYDBko6mAEAUj0gMMNmso85txytk6g5Aaj A_64bgZVjJphycZILmA5VDlFYNwJ1zrOrTUscY.aN3vByn779HemJput00sQBecAJwOM.VRlRMCu HTcjebHI3qRvNXyGtvi4cWVU5zyk4wPdvebO_7cwqJOdllPrpFsE5J.CqIB.._gVfTLqMVXmhLRw swLHJFSD6a.12sYDWyE7xLfgaajSJ4GvLTR1n64HYJVmtHKezmb9pTD4ta3ZboWt6.e0QMvjBI2W SrwQh6_Sk
Received: by 66.196.80.145; Mon, 05 Jan 2015 05:14:21 +0000 
Date: Mon, 5 Jan 2015 05:14:21 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Alexey Melnikov <alexey.melnikov@isode.com>
Message-ID: <906184359.4479100.1420434861170.JavaMail.yahoo@jws106131.mail.bf1.yahoo.com>
In-Reply-To: <F4209A2F-CEB5-498B-9DA9-1C4628C64BE4@isode.com>
References: <F4209A2F-CEB5-498B-9DA9-1C4628C64BE4@isode.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_4479099_1404418954.1420434861166"
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/enn2o_kIfOPYOWM6J9M-bd7piGI
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Jan 2015 05:14:24 -0000

------=_Part_4479099_1404418954.1420434861166
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

 Ah OK. =C2=A0This is a significant change. =C2=A0Can we make using the can=
cellation token optional? =C2=A0The extant implementations use the current =
sequence.
-bill

     On Sunday, January 4, 2015 3:37 AM, Alexey Melnikov <alexey.melnikov@i=
sode.com> wrote:
  =20

 Hi Bill,

> On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:
>=20
> 3.2.3 and an explicit message:=C2=A0 Long ago in the life of this doc I w=
as told that some implementations may not support an empty message, so we p=
ut the single character message there to have an explicit payload.=C2=A0 I'=
m a bit leery of changing this now since there are implementations in play =
that use it this way.

I didn't suggest you should be sending empty message. I said you should be =
using SASL cancellation token, which is a mandatory RFC 4422 feature.

Any implementation would have to support this mode of operation anyway, bec=
ause a SASL client can cancel any exchange.



   
------=_Part_4479099_1404418954.1420434861166
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div><span></span></div> <div class=3D"qtdSeparateBR" id=3D"y=
ui_3_16_0_1_1419806870697_1414222" dir=3D"ltr">Ah OK. &nbsp;This is a signi=
ficant change. &nbsp;Can we make using the cancellation token optional? &nb=
sp;The extant implementations use the current sequence.</div><div class=3D"=
qtdSeparateBR" id=3D"yui_3_16_0_1_1419806870697_1414222" dir=3D"ltr"><br></=
div><div class=3D"qtdSeparateBR" id=3D"yui_3_16_0_1_1419806870697_1414222" =
dir=3D"ltr">-bill<br><br></div><div class=3D"yahoo_quoted" style=3D"display=
: block;" id=3D"yui_3_16_0_1_1419806870697_1414214"> <div style=3D"font-fam=
ily: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-s=
erif; font-size: 12px;" id=3D"yui_3_16_0_1_1419806870697_1414213"> <div sty=
le=3D"font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida =
Grande, sans-serif; font-size: 16px;" id=3D"yui_3_16_0_1_1419806870697_1414=
212"> <div dir=3D"ltr" id=3D"yui_3_16_0_1_1419806870697_1414220"> <font siz=
e=3D"2" face=3D"Arial" id=3D"yui_3_16_0_1_1419806870697_1414219"> On Sunday=
, January 4, 2015 3:37 AM, Alexey Melnikov &lt;alexey.melnikov@isode.com&gt=
; wrote:<br> </font> </div>  <br><br> <div class=3D"y_msg_container" id=3D"=
yui_3_16_0_1_1419806870697_1414211">Hi Bill,<br clear=3D"none"><div class=
=3D"yqt4192359203" id=3D"yqtfd94690"><br clear=3D"none">&gt; On 3 Jan 2015,=
 at 00:56, Bill Mills &lt;<a shape=3D"rect" ymailto=3D"mailto:wmills_92105@=
yahoo.com" href=3D"mailto:wmills_92105@yahoo.com">wmills_92105@yahoo.com</a=
>&gt; wrote:<br clear=3D"none">&gt; <br clear=3D"none">&gt; 3.2.3 and an ex=
plicit message:&nbsp; Long ago in the life of this doc I was told that some=
 implementations may not support an empty message, so we put the single cha=
racter message there to have an explicit payload.&nbsp; I'm a bit leery of =
changing this now since there are implementations in play that use it this =
way.</div><br clear=3D"none"><br clear=3D"none">I didn't suggest you should=
 be sending empty message. I said you should be using SASL cancellation tok=
en, which is a mandatory RFC 4422 feature.<br clear=3D"none"><br clear=3D"n=
one">Any implementation would have to support this mode of operation anyway=
, because a SASL client can cancel any exchange.<div class=3D"yqt4192359203=
" id=3D"yqtfd29085"><br clear=3D"none"><br clear=3D"none"></div><br><br></d=
iv>  </div> </div>  </div> </div></body></html>
------=_Part_4479099_1404418954.1420434861166--


From nobody Mon Jan  5 04:42:03 2015
Return-Path: <alexey.melnikov@isode.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 093701A6F15 for <kitten@ietfa.amsl.com>; Mon,  5 Jan 2015 04:42:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.009
X-Spam-Level: 
X-Spam-Status: No, score=-2.009 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SMxzBp5TQvBW for <kitten@ietfa.amsl.com>; Mon,  5 Jan 2015 04:42:00 -0800 (PST)
Received: from waldorf.isode.com (ext-bt.isode.com [217.34.220.158]) by ietfa.amsl.com (Postfix) with ESMTP id 249AF1A6F0E for <kitten@ietf.org>; Mon,  5 Jan 2015 04:42:00 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1420461719; d=isode.com; s=selector; i=@isode.com; bh=ovZ+urfGSGY4mg4ezvoIxw/jRuKowWjOsnpqmgTELws=; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version: In-Reply-To:References:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description; b=H+DmY2Dk8+DyMbghy4ALrw3iowR85hLPrqN5tJbX2Ly88Nt9A3CCFJ1KlsJC7RgLlNQtBX bvwfWAVJQZek3l3BiJ5dDN6ZaysJCJ1BZH39PdA+i7KUwjYAxCDDqPeeLFPufRLgbJElD5 rj+ch7LGIy9UGQvxaUXPCsDlfYB0Fa4=;
Received: from [172.20.1.215] (dhcp-215.isode.net [172.20.1.215])  by waldorf.isode.com (submission channel) via TCP with ESMTPSA  id <VKqGlgAKaE-V@waldorf.isode.com>; Mon, 5 Jan 2015 12:41:58 +0000
Message-ID: <54AA8627.6020002@isode.com>
Date: Mon, 05 Jan 2015 12:40:07 +0000
From: Alexey Melnikov <alexey.melnikov@isode.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.2.0
To: Bill Mills <wmills_92105@yahoo.com>
References: <F4209A2F-CEB5-498B-9DA9-1C4628C64BE4@isode.com> <906184359.4479100.1420434861170.JavaMail.yahoo@jws106131.mail.bf1.yahoo.com>
In-Reply-To: <906184359.4479100.1420434861170.JavaMail.yahoo@jws106131.mail.bf1.yahoo.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="------------010708070102020505040000"
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/NkGOqldfnGoBqkau8iqdtvjaVH0
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Jan 2015 12:42:02 -0000

--------------010708070102020505040000
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit

On 05/01/2015 05:14, Bill Mills wrote:
> Ah OK.  This is a significant change.  Can we make using the 
> cancellation token optional?
Not really. Any protocol needs to define the cancellation token 
(according to RFC 2244) and any mechanism implementation (or SASL 
framework library) that doesn't complete in 1 round trip need to be able 
to handle it.

I think it is Ok not to change the spec, but it would be a good idea to 
point out that standard SASL cancellation token can still be used. 
Adding an example would be even better.
> The extant implementations use the current sequence.
>
> -bill
>
> On Sunday, January 4, 2015 3:37 AM, Alexey Melnikov 
> <alexey.melnikov@isode.com> wrote:
>
>
> Hi Bill,
>
> > On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com 
> <mailto:wmills_92105@yahoo.com>> wrote:
> >
> > 3.2.3 and an explicit message:  Long ago in the life of this doc I 
> was told that some implementations may not support an empty message, 
> so we put the single character message there to have an explicit 
> payload. I'm a bit leery of changing this now since there are 
> implementations in play that use it this way.
>
>
> I didn't suggest you should be sending empty message. I said you 
> should be using SASL cancellation token, which is a mandatory RFC 4422 
> feature.
>
> Any implementation would have to support this mode of operation 
> anyway, because a SASL client can cancel any exchange.


--------------010708070102020505040000
Content-Type: text/html; charset=utf-8
Content-transfer-encoding: quoted-printable

<html>
  <head>
    <meta content=3D"text/html; charset=3Dutf-8" http-equiv=3D"Content-Type"=
>
  </head>
  <body bgcolor=3D"#FFFFFF" text=3D"#000000">
    On 05/01/2015 05:14, Bill Mills wrote:<br>
    <blockquote
cite=3D"mid:906184359.4479100.1420434861170.JavaMail.yahoo@jws106131.mail.bf=
1.yahoo.com"
      type=3D"cite">
      <div style=3D"color:#000; background-color:#fff;
        font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial,
        Lucida Grande, sans-serif;font-size:12px">
        <div><span></span></div>
        <div class=3D"qtdSeparateBR"
          id=3D"yui_3_16_0_1_1419806870697_1414222" dir=3D"ltr">Ah OK. =C2=
=A0This
          is a significant change. =C2=A0Can we make using the cancellation
          token optional? </div>
      </div>
    </blockquote>
    Not really. Any protocol needs to define the cancellation token
    (according to RFC 2244) and any mechanism implementation (or SASL
    framework library) that doesn't complete in 1 round trip need to be
    able to handle it.<br>
    <br>
    I think it is Ok not to change the spec, but it would be a good idea
    to point out that standard SASL cancellation token can still be
    used. Adding an example would be even better.<br>
    <blockquote
cite=3D"mid:906184359.4479100.1420434861170.JavaMail.yahoo@jws106131.mail.bf=
1.yahoo.com"
      type=3D"cite">
      <div style=3D"color:#000; background-color:#fff;
        font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial,
        Lucida Grande, sans-serif;font-size:12px">
        <div class=3D"qtdSeparateBR"
          id=3D"yui_3_16_0_1_1419806870697_1414222" dir=3D"ltr">The extant
          implementations use the current sequence.</div>
        <div class=3D"qtdSeparateBR"
          id=3D"yui_3_16_0_1_1419806870697_1414222" dir=3D"ltr"><br>
        </div>
        <div class=3D"qtdSeparateBR"
          id=3D"yui_3_16_0_1_1419806870697_1414222" dir=3D"ltr">-bill<br>
          <br>
        </div>
        <div class=3D"yahoo_quoted" style=3D"display: block;"
          id=3D"yui_3_16_0_1_1419806870697_1414214">
          <div style=3D"font-family: HelveticaNeue, Helvetica Neue,
            Helvetica, Arial, Lucida Grande, sans-serif; font-size:
            12px;" id=3D"yui_3_16_0_1_1419806870697_1414213">
            <div style=3D"font-family: HelveticaNeue, Helvetica Neue,
              Helvetica, Arial, Lucida Grande, sans-serif; font-size:
              16px;" id=3D"yui_3_16_0_1_1419806870697_1414212">
              <div dir=3D"ltr" id=3D"yui_3_16_0_1_1419806870697_1414220"> <f=
ont
                  id=3D"yui_3_16_0_1_1419806870697_1414219" face=3D"Arial"
                  size=3D"2"> On Sunday, January 4, 2015 3:37 AM, Alexey
                  Melnikov <a class=3D"moz-txt-link-rfc2396E" href=3D"mailto=
:alexey.melnikov@isode.com">&lt;alexey.melnikov@isode.com&gt;</a> wrote:<br>
                </font> </div>
              <br>
              <br>
              <div class=3D"y_msg_container"
                id=3D"yui_3_16_0_1_1419806870697_1414211">Hi Bill,<br
                  clear=3D"none">
                <div class=3D"yqt4192359203" id=3D"yqtfd94690"><br
                    clear=3D"none">
                  &gt; On 3 Jan 2015, at 00:56, Bill Mills &lt;<a
                    moz-do-not-send=3D"true" shape=3D"rect"
                    ymailto=3D"mailto:wmills_92105@yahoo.com"
                    href=3D"mailto:wmills_92105@yahoo.com">wmills_92105@yaho=
o.com</a>&gt;
                  wrote:<br clear=3D"none">
                  &gt; <br clear=3D"none">
                  &gt; 3.2.3 and an explicit message:=C2=A0 Long ago in the
                  life of this doc I was told that some implementations
                  may not support an empty message, so we put the single
                  character message there to have an explicit payload.=C2=A0
                  I'm a bit leery of changing this now since there are
                  implementations in play that use it this way.</div>
                <br clear=3D"none">
                <br clear=3D"none">
                I didn't suggest you should be sending empty message. I
                said you should be using SASL cancellation token, which
                is a mandatory RFC 4422 feature.<br clear=3D"none">
                <br clear=3D"none">
                Any implementation would have to support this mode of
                operation anyway, because a SASL client can cancel any
                exchange.</div>
            </div>
          </div>
        </div>
      </div>
    </blockquote>
    <br>
  </body>
</html>

--------------010708070102020505040000--


From nobody Mon Jan  5 06:29:47 2015
Return-Path: <brian@innovationslab.net>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E6701A8869; Mon,  5 Jan 2015 06:29:44 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Nml273p3DdlJ; Mon,  5 Jan 2015 06:29:43 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 4C63F1A8864; Mon,  5 Jan 2015 06:29:41 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: "Brian Haberman" <brian@innovationslab.net>
To: The IESG <iesg@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.0.p1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150105142941.32750.5359.idtracker@ietfa.amsl.com>
Date: Mon, 05 Jan 2015 06:29:41 -0800
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/vbRnVDyBbSeqDZMmua-HNkQF7wM
Cc: kitten@ietf.org, kitten-chairs@tools.ietf.org, draft-ietf-kitten-cammac.all@tools.ietf.org
Subject: [kitten] Brian Haberman's No Objection on draft-ietf-kitten-cammac-00: (with COMMENT)
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Jan 2015 14:29:44 -0000

Brian Haberman has entered the following ballot position for
draft-ietf-kitten-cammac-00: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to http://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
http://datatracker.ietf.org/doc/draft-ietf-kitten-cammac/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

I agree with Barry's suggested changes.



From nobody Mon Jan  5 12:05:51 2015
Return-Path: <michikos@microsoft.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E54CC1A9028 for <kitten@ietfa.amsl.com>; Mon,  5 Jan 2015 12:05:43 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H51oYdiR6GZQ for <kitten@ietfa.amsl.com>; Mon,  5 Jan 2015 12:05:41 -0800 (PST)
Received: from na01-by2-obe.outbound.protection.outlook.com (mail-by2on0114.outbound.protection.outlook.com [207.46.100.114]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8565B1A8980 for <kitten@ietf.org>; Mon,  5 Jan 2015 11:56:34 -0800 (PST)
Received: from BL2PR03MB212.namprd03.prod.outlook.com (10.255.230.151) by BL2PR03MB209.namprd03.prod.outlook.com (10.255.230.140) with Microsoft SMTP Server (TLS) id 15.1.49.12; Mon, 5 Jan 2015 19:56:32 +0000
Received: from BL2PR03MB212.namprd03.prod.outlook.com ([169.254.15.71]) by BL2PR03MB212.namprd03.prod.outlook.com ([169.254.15.71]) with mapi id 15.01.0049.002; Mon, 5 Jan 2015 19:56:32 +0000
From: Michiko Short <michikos@microsoft.com>
To: Benjamin Kaduk <kaduk@MIT.EDU>, "kitten@ietf.org" <kitten@ietf.org>
Thread-Topic: [kitten] Call for Adoption: draft-short-pkinit-freshness
Thread-Index: AQHQH7wyh6qmVhgi4UiXEgxo2C+BMJyyA6mA
Date: Mon, 5 Jan 2015 19:56:32 +0000
Message-ID: <BL2PR03MB21268049C15DD9C68587F3BD0580@BL2PR03MB212.namprd03.prod.outlook.com>
References: <alpine.GSO.1.10.1412011612390.23489@multics.mit.edu> <alpine.GSO.1.10.1412241554580.23489@multics.mit.edu>
In-Reply-To: <alpine.GSO.1.10.1412241554580.23489@multics.mit.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [2001:4898:80e8:ed31::3]
authentication-results: spf=none (sender IP is ) smtp.mailfrom=michikos@microsoft.com; 
x-dmarcaction: None
x-microsoft-antispam: BCL:0;PCL:0;RULEID:(3005003);SRVR:BL2PR03MB209;
x-forefront-prvs: 0447DB1C71
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(13464003)(52044002)(377454003)(51704005)(189002)(24454002)(199003)(164054003)(2171001)(19580405001)(15975445007)(86612001)(19580395003)(2900100001)(87936001)(64706001)(20776003)(2656002)(99396003)(77156002)(46102003)(2501002)(62966003)(122556002)(40100003)(76576001)(230783001)(2950100001)(68736005)(120916001)(97736003)(4396001)(21056001)(105586002)(106356001)(99286002)(106116001)(107046002)(101416001)(92566001)(50986999)(54606007)(54206007)(54356999)(102836002)(31966008)(86362001)(33656002)(76176999)(74316001)(3826002); DIR:OUT; SFP:1102; SCL:1; SRVR:BL2PR03MB209; H:BL2PR03MB212.namprd03.prod.outlook.com; FPR:; SPF:None; MLV:sfv; PTR:InfoNoRecords; MX:1; A:1; LANG:en; 
received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts)
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.onmicrosoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 05 Jan 2015 19:56:32.7788 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL2PR03MB209
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/UgZdoQVjSgFXd2lNm1LF5KTXL8Y
Cc: "kitten-chairs@tools.ietf.org" <kitten-chairs@tools.ietf.org>
Subject: Re: [kitten] Call for Adoption: draft-short-pkinit-freshness
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Jan 2015 20:05:44 -0000

Will do. I should have a new draft in the next week or two.=20

Thanks,
Michiko Short


-----Original Message-----
From: Benjamin Kaduk [mailto:kaduk@MIT.EDU]=20
Sent: Wednesday, December 24, 2014 12:57 PM
To: kitten@ietf.org
Cc: kitten-chairs@tools.ietf.org; Michiko Short
Subject: Re: [kitten] Call for Adoption: draft-short-pkinit-freshness

Thanks to all who responded.

Michiko, please submit the next revision as draft-ietf-kitten-pkinit-freshn=
ess-00.

Thanks,

Ben

On Mon, 1 Dec 2014, Benjamin Kaduk wrote:

> The chairs are considering adopting draft-short-pkinit-freshness [0]=20
> as a kitten draft.  We would like to solicit comments on whether to=20
> adopt this draft.  Since it updates RFC 4556, it seems clear that it=20
> needs to be standards-track, but feel free to comment on that as well, if=
 you wish.
>
> Please submit comments by December 19th, 2014, either to the chairs or=20
> to the list.
>
> -Ben, for the kitten co-chairs
>
> [0] https://tools.ietf.org/html/draft-short-pkinit-freshness-00
>
> _______________________________________________
> Kitten mailing list
> Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten
>


From nobody Tue Jan  6 11:06:50 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B48021A1B38 for <kitten@ietfa.amsl.com>; Tue,  6 Jan 2015 11:06:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZXOdQ7TC3CCR for <kitten@ietfa.amsl.com>; Tue,  6 Jan 2015 11:06:47 -0800 (PST)
Received: from nm41-vm9.bullet.mail.bf1.yahoo.com (nm41-vm9.bullet.mail.bf1.yahoo.com [216.109.114.138]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CCA971A036F for <kitten@ietf.org>; Tue,  6 Jan 2015 11:06:46 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1420571206; bh=BAN2R/ttZKF829s1LFanEsoHeKSyV8Vyna4KXAISVjo=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=YtRxJqvVleqkfFMU3bGJ1hgff4CbtfCZwb55c2devQy+hZQ01at+p+Ik+GxIxjCb3mn5MgDeR8Z+Dx9R6tXf8D2faaklUt9beW17Hkyc3fBeEjF1JAlOXFG30xgYLi8mF5PyuXqtCkurqapQNJiWRh5Bs54WE/C2P3IdvJ36EuH8S44Dmvd7KcESKysZSxTXZBVv3jULTNMDELDJIzHBx3D8o6vMKQV6mHi/40qX62kiedhcDLEvG1vxZoUNb1+paCeaP+TgLpkonhJuyoh8Qw/E8njV09JG2vuBgiVfUEEkdIA7sd84vlpCYvQ4EF1NH6eyC2XxKeZRhGSAhsBvjA==
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s2048; d=yahoo.com; b=cErrfjGUtxc3GUSk/6+Qxppzy0+aq9Y/XEJ55qIA8AE5ksJ91DrFDuKxYAHgxTMl+9qHPRzlwvtTxWwEIirKGCjUlcjY23zMN/GmaQzAYRrBlHCNzU+QrPCu69PomSFiQCiz1KtuQ2C9yoGh2zbrHUI2m2aRBjOob1Bjs4j9VoPQh1r3ZhfSX53ZCQkZxOY6cDQB1kGvn5b7Te13kTeWj7HXroumO3+BE2chVOd2a7Te8iABLnb+d+TkG6IvITHMep9b26nuGtjgC15f7/yuYKAS49O/yvGPYzSWcdDMWDgv7dqzYLRpkDd1/OcwoZQHwWkVwS6JOXUff8m7AhOg5w==;
Received: from [98.139.215.142] by nm41.bullet.mail.bf1.yahoo.com with NNFMP;  06 Jan 2015 19:06:46 -0000
Received: from [98.139.212.249] by tm13.bullet.mail.bf1.yahoo.com with NNFMP;  06 Jan 2015 19:06:46 -0000
Received: from [127.0.0.1] by omp1058.mail.bf1.yahoo.com with NNFMP; 06 Jan 2015 19:06:46 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 67002.62424.bm@omp1058.mail.bf1.yahoo.com
X-YMail-OSG: rekiJYYVM1lEbQgdpPy7TyU_7KNni0KaMC0szDLAlbZzMvlsiuXDYwK0n2Jk0Io NIZE2.w5i17s.hW8xsp76zctrkuA0c_.Cql8elLsaGq8wE4WfOt_DbyMY0PELieKCIXdcDAZSn0K tNFtbQsZcYAkpW_oMHOFmQ7fyUwpb86gHDSQ51riBNYAXKm8DuBaLuh_o4bCgVTG1bCnhEHGMQZe I.Pu4uAKo7VKbly_MknVJ0spjf12m6l_Or0Ipo0NqsLwhGFct.zIwuHBHHM1vHDK6dKFe.mRSbif lYfpbrz.o_RDsz3GGiOCWcQhym1PckUuonqq0RRVMR5gjIQcJSqGYFPatofrR1DRtu8eioSVVLTv qHbRhmYDFfczoASr3k1iH_WWiYZeIuOrmBHkLxDTBBol7oLorrvi8MDQHFiZPGEEJPkRejvfi7LF zyFPrYhyKoLMlQPHOiF_.yJcjy8oYTzS5JgTCRL90D0yNjQ4SetJXvOaBAz9lWHcecqfqJ14WidQ e8SHH1gKT
Received: by 76.13.27.133; Tue, 06 Jan 2015 19:06:45 +0000 
Date: Tue, 6 Jan 2015 19:06:45 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Alexey Melnikov <alexey.melnikov@isode.com>
Message-ID: <1740622945.5399192.1420571205123.JavaMail.yahoo@jws10672.mail.bf1.yahoo.com>
In-Reply-To: <54AA8627.6020002@isode.com>
References: <54AA8627.6020002@isode.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_5399191_106811079.1420571205119"
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/KLpHEF0G0h-uPbOcQX_iNwGAhZY
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Jan 2015 19:06:48 -0000

------=_Part_5399191_106811079.1420571205119
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Can you point me at an exampel of a cancellation token?=20

     On Monday, January 5, 2015 4:41 AM, Alexey Melnikov <alexey.melnikov@i=
sode.com> wrote:
  =20

  On 05/01/2015 05:14, Bill Mills wrote:
=20
   Ah OK. =C2=A0This is a significant change. =C2=A0Can we make using the c=
ancellation token optional?  =20
 Not really. Any protocol needs to define the cancellation token (according=
 to RFC 2244) and any mechanism implementation (or SASL framework library) =
that doesn't complete in 1 round trip need to be able to handle it.
=20
 I think it is Ok not to change the spec, but it would be a good idea to po=
int out that standard SASL cancellation token can still be used. Adding an =
example would be even better.
=20
  The extant implementations use the current sequence.=20
  -bill
=20
       On Sunday, January 4, 2015 3:37 AM, Alexey Melnikov <alexey.melnikov=
@isode.com> wrote:
  =20
=20
 Hi Bill,
=20
 > On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:
 >=20
 > 3.2.3 and an explicit message:=C2=A0 Long ago in the life of this doc I =
was told that some implementations may not support an empty message, so we =
put the single  character message there to have an explicit payload.=C2=A0 =
I'm a bit leery of changing this now since there are implementations in pla=
y that use it this way.=20
=20
 I didn't suggest you should be sending empty message. I said you should be=
 using SASL cancellation token, which is a mandatory RFC 4422 feature.
=20
 Any implementation would have to support this mode of operation anyway, be=
cause a SASL client can cancel any exchange.    =20
=20
=20

   
------=_Part_5399191_106811079.1420571205119
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit

<html><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:12px"><div dir="ltr"><span>Can you point me at an exampel of a cancellation token?</span></div> <div class="qtdSeparateBR"><br><br></div><div class="yahoo_quoted" style="display: block;"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 12px;"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div dir="ltr"> <font size="2" face="Arial"> On Monday, January 5, 2015 4:41 AM, Alexey Melnikov &lt;alexey.melnikov@isode.com&gt; wrote:<br> </font> </div>  <br><br> <div class="y_msg_container"><div id="yiv0593615287"><div>
    On 05/01/2015 05:14, Bill Mills wrote:<br clear="none">
    <blockquote type="cite">
      <div style="color:#000;background-color:#fff;font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:12px;">
        <div><span></span></div>
        <div class="yiv0593615287qtdSeparateBR" dir="ltr" id="yiv0593615287yui_3_16_0_1_1419806870697_1414222">Ah OK. &nbsp;This
          is a significant change. &nbsp;Can we make using the cancellation
          token optional? </div>
      </div>
    </blockquote>
    Not really. Any protocol needs to define the cancellation token
    (according to RFC 2244) and any mechanism implementation (or SASL
    framework library) that doesn't complete in 1 round trip need to be
    able to handle it.<br clear="none">
    <br clear="none">
    I think it is Ok not to change the spec, but it would be a good idea
    to point out that standard SASL cancellation token can still be
    used. Adding an example would be even better.<div class="yiv0593615287yqt1376411281" id="yiv0593615287yqtfd12097"><br clear="none">
    <blockquote type="cite">
      <div style="color:#000;background-color:#fff;font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:12px;">
        <div class="yiv0593615287qtdSeparateBR" dir="ltr" id="yiv0593615287yui_3_16_0_1_1419806870697_1414222">The extant
          implementations use the current sequence.</div>
        <div class="yiv0593615287qtdSeparateBR" dir="ltr" id="yiv0593615287yui_3_16_0_1_1419806870697_1414222"><br clear="none">
        </div>
        <div class="yiv0593615287qtdSeparateBR" dir="ltr" id="yiv0593615287yui_3_16_0_1_1419806870697_1414222">-bill<br clear="none">
          <br clear="none">
        </div>
        <div class="yiv0593615287yahoo_quoted" id="yiv0593615287yui_3_16_0_1_1419806870697_1414214" style="display: block;">
          <div id="yiv0593615287yui_3_16_0_1_1419806870697_1414213" style="font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:12px;">
            <div id="yiv0593615287yui_3_16_0_1_1419806870697_1414212" style="font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:16px;">
              <div dir="ltr" id="yiv0593615287yui_3_16_0_1_1419806870697_1414220"> <font id="yiv0593615287yui_3_16_0_1_1419806870697_1414219" face="Arial" size="2"> On Sunday, January 4, 2015 3:37 AM, Alexey
                  Melnikov <a rel="nofollow" shape="rect" class="yiv0593615287moz-txt-link-rfc2396E" ymailto="mailto:alexey.melnikov@isode.com" target="_blank" href="mailto:alexey.melnikov@isode.com">&lt;alexey.melnikov@isode.com&gt;</a> wrote:<br clear="none">
                </font> </div>
              <br clear="none">
              <br clear="none">
              <div class="yiv0593615287y_msg_container" id="yiv0593615287yui_3_16_0_1_1419806870697_1414211">Hi Bill,<br clear="none">
                <div class="yiv0593615287yqt4192359203" id="yiv0593615287yqtfd94690"><br clear="none">
                  &gt; On 3 Jan 2015, at 00:56, Bill Mills &lt;<a rel="nofollow" shape="rect" ymailto="mailto:wmills_92105@yahoo.com" target="_blank" href="mailto:wmills_92105@yahoo.com">wmills_92105@yahoo.com</a>&gt;
                  wrote:<br clear="none">
                  &gt; <br clear="none">
                  &gt; 3.2.3 and an explicit message:&nbsp; Long ago in the
                  life of this doc I was told that some implementations
                  may not support an empty message, so we put the single
                  character message there to have an explicit payload.&nbsp;
                  I'm a bit leery of changing this now since there are
                  implementations in play that use it this way.</div>
                <br clear="none">
                <br clear="none">
                I didn't suggest you should be sending empty message. I
                said you should be using SASL cancellation token, which
                is a mandatory RFC 4422 feature.<br clear="none">
                <br clear="none">
                Any implementation would have to support this mode of
                operation anyway, because a SASL client can cancel any
                exchange.</div>
            </div>
          </div>
        </div>
      </div>
    </blockquote>
    <br clear="none">
  </div></div></div><br><br></div>  </div> </div>  </div> </div></body></html>
------=_Part_5399191_106811079.1420571205119--


From nobody Tue Jan  6 11:09:24 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E16AE1A1B38 for <kitten@ietfa.amsl.com>; Tue,  6 Jan 2015 11:09:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ij1XUphKgR8q for <kitten@ietfa.amsl.com>; Tue,  6 Jan 2015 11:09:14 -0800 (PST)
Received: from nm14-vm0.bullet.mail.bf1.yahoo.com (nm14-vm0.bullet.mail.bf1.yahoo.com [98.139.213.164]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3FC0D1A0277 for <kitten@ietf.org>; Tue,  6 Jan 2015 11:09:14 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1420571353; bh=GAW9zC7r0awGVrtMNlbgYqfL4pQpvAc0kDmqkD0apZQ=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=glfg+8fQjFPtCaX/seH/rQS39CdprxOsgUYY++tQMBwHmi72gEC7GzVdqCHHpafVNLx6MHeLKlIsWIkHi3Ssl6MkXoHLaCkZUQGV4TruqU6eB9WjLGf2wXcar/SAvvZI3tu/JOENV5Q7DZsLN5QPU1hAQxgMoK+gV8bnRqFbM5uVrhnvK9hOtadKqRAc8j0DXS2Pu3DID60a7eA3MJCSy2bCt8sY4yk5dS+c72R4v2KivF++/L3KIqlDnP7T+5y4+ntSyGnkgXA7h7KDME4gBNwypYPqyUJIVAZgLWTfW40XV+A+9h1IuoCONgreUGlwqNHKSJJhX86GckQGuOpAMQ==
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s2048; d=yahoo.com; b=QF/tvp7AUdqR/GHc2iytsyMIoLz/yC4eVHO8FKPSK0DkHC5Rh8sLPtZm+rVpxeS3J047ekbm6GhNKD4GCd7jZMfXaY4DtN4cgBAVuHBkgOhEsVwCYSyLp+hzOKTqOIKXE9zCT0AunvJHPGArkpkPsGu/YS0Rtw3nQqH/jLcv3av2knvPrtV8eJ/bc1jT3kzgTOiLq/Z2MAohjMolrl3GgbUwIBxPNGu7IPVSZilDWo7joq6Wjqi8PiO01lvssnAlL2CBTCF8ixm5ki8z9kMxq1DU/rD7i+hwoWutN1+2lgy6+US5EUD8ApYdRv+mNTXtlfDlGibqw6La3sqF4/BvYA==;
Received: from [98.139.214.32] by nm14.bullet.mail.bf1.yahoo.com with NNFMP; 06 Jan 2015 19:09:13 -0000
Received: from [98.139.212.195] by tm15.bullet.mail.bf1.yahoo.com with NNFMP;  06 Jan 2015 19:09:13 -0000
Received: from [127.0.0.1] by omp1004.mail.bf1.yahoo.com with NNFMP; 06 Jan 2015 19:09:02 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 856647.3859.bm@omp1004.mail.bf1.yahoo.com
X-YMail-OSG: 5kvdwtUVM1n86eQ3M4J3109OysOSvAHUydfmz49FjErfcwOM_CJpTDcSW.s0MGI i19sMb0EvF1p72X.h0CezQBvLY3PAAvVyXq9Vm44lW0W.8p3AIETCqJq_rQQbA6sh38L.tNN6XuC 0d3KvQfWFAvG43jh.zE3Xt_H5lHbOFDxN7QoqVgWy.aOrRtVvjm_yaiq0hlh3vX9JcK5YpBZ43C5 REdp_piGBd5gAG52LxTzxAFhJJHfoEfyiUtcvMn_fQgncqrIqBN0mfgtZ1RF0bFVTFRP.pyp2gd9 jq4QH9e6qRagPvyhrDQlGqihQKWzMadyr9DbmA3Rr5cqLUsOBA30FrQSM91F4pQ4S7Oc8NzcG3sZ FbFYZWkWv_SKNKHKwYm1bDvwMER5xrI8aoCH5qG2AThz2HK2VVX9aCS3x8FBbDeXFj_ig48D47vc 5stmW1d8ejohhrLixuQencHU0J5CFjhiJ1K1Yd9cmFPI66DzMHsB7URPKaA5FPmlMIKxek7fM6K4 0Y2dBVvrS
Received: by 66.196.81.120; Tue, 06 Jan 2015 19:09:02 +0000 
Date: Tue, 6 Jan 2015 19:09:01 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Alexey Melnikov <alexey.melnikov@isode.com>
Message-ID: <726434597.5416117.1420571341615.JavaMail.yahoo@jws106101.mail.bf1.yahoo.com>
In-Reply-To: <1740622945.5399192.1420571205123.JavaMail.yahoo@jws10672.mail.bf1.yahoo.com>
References: <54AA8627.6020002@isode.com> <1740622945.5399192.1420571205123.JavaMail.yahoo@jws10672.mail.bf1.yahoo.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_5416115_1332011847.1420571341605"
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/P0DnfST3uK1PDEPfPxM810zfeQY
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Jan 2015 19:09:16 -0000

------=_Part_5416115_1332011847.1420571341605
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

and you did mean 4422 not 2244 right?=20

     On Tuesday, January 6, 2015 11:06 AM, Bill Mills <wmills_92105@yahoo.c=
om> wrote:
  =20

 Can you point me at an exampel of a cancellation token?=20

     On Monday, January 5, 2015 4:41 AM, Alexey Melnikov <alexey.melnikov@i=
sode.com> wrote:
  =20

  On 05/01/2015 05:14, Bill Mills wrote:
=20
   Ah OK. =C2=A0This is a significant change. =C2=A0Can we make using the c=
ancellation token optional?  =20
 Not really. Any protocol needs to define the cancellation token (according=
 to RFC 2244) and any mechanism implementation (or SASL framework library) =
that doesn't complete in 1 round trip need to be able to handle it.
=20
 I think it is Ok not to change the spec, but it would be a good idea to po=
int out that standard SASL cancellation token can still be used. Adding an =
example would be even better.
=20
  The extant implementations use the current sequence.=20
  -bill
=20
       On Sunday, January 4, 2015 3:37 AM, Alexey Melnikov <alexey.melnikov=
@isode.com> wrote:
  =20
=20
 Hi Bill,
=20
 > On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:
 >=20
 > 3.2.3 and an explicit message:=C2=A0 Long ago in the life of this doc I =
was told that some implementations may not support an empty message, so we =
put the single  character message there to have an explicit payload.=C2=A0 =
I'm a bit leery of changing this now since there are implementations in pla=
y that use it this way.=20
=20
 I didn't suggest you should be sending empty message. I said you should be=
 using SASL cancellation token, which is a mandatory RFC 4422 feature.
=20
 Any implementation would have to support this mode of operation anyway, be=
cause a SASL client can cancel any exchange.    =20
=20
=20

   =20

   
------=_Part_5416115_1332011847.1420571341605
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div dir=3D"ltr"><span>and you did mean 4422 not 2244 right?<=
/span></div> <div class=3D"qtdSeparateBR"><br><br></div><div class=3D"yahoo=
_quoted" style=3D"display: block;"> <div style=3D"font-family: HelveticaNeu=
e, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: =
12px;"> <div style=3D"font-family: HelveticaNeue, Helvetica Neue, Helvetica=
, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div dir=3D"ltr"> <f=
ont size=3D"2" face=3D"Arial"> On Tuesday, January 6, 2015 11:06 AM, Bill M=
ills &lt;wmills_92105@yahoo.com&gt; wrote:<br> </font> </div>  <br><br> <di=
v class=3D"y_msg_container"><div id=3D"yiv4255549182"><div><div style=3D"co=
lor:#000;background-color:#fff;font-family:HelveticaNeue, Helvetica Neue, H=
elvetica, Arial, Lucida Grande, sans-serif;font-size:12px;"><div dir=3D"ltr=
"><span>Can you point me at an exampel of a cancellation token?</span></div=
> <div class=3D"yiv4255549182qtdSeparateBR"><br clear=3D"none"><br clear=3D=
"none"></div><div class=3D"yiv4255549182yqt9407845033" id=3D"yiv4255549182y=
qt99989"><div class=3D"yiv4255549182yahoo_quoted" style=3D"display: block;"=
> <div style=3D"font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial=
, Lucida Grande, sans-serif;font-size:12px;"> <div style=3D"font-family:Hel=
veticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fon=
t-size:16px;"> <div dir=3D"ltr"> <font size=3D"2" face=3D"Arial"> On Monday=
, January 5, 2015 4:41 AM, Alexey Melnikov &lt;alexey.melnikov@isode.com&gt=
; wrote:<br clear=3D"none"> </font> </div>  <br clear=3D"none"><br clear=3D=
"none"> <div class=3D"yiv4255549182y_msg_container"><div id=3D"yiv425554918=
2"><div>
    On 05/01/2015 05:14, Bill Mills wrote:<br clear=3D"none">
    <blockquote type=3D"cite">
      <div style=3D"color:#000;background-color:#fff;font-family:HelveticaN=
eue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:=
12px;">
        <div><span></span></div>
        <div class=3D"yiv4255549182qtdSeparateBR" dir=3D"ltr" id=3D"yiv4255=
549182yui_3_16_0_1_1419806870697_1414222">Ah OK. &nbsp;This
          is a significant change. &nbsp;Can we make using the cancellation
          token optional? </div>
      </div>
    </blockquote>
    Not really. Any protocol needs to define the cancellation token
    (according to RFC 2244) and any mechanism implementation (or SASL
    framework library) that doesn't complete in 1 round trip need to be
    able to handle it.<br clear=3D"none">
    <br clear=3D"none">
    I think it is Ok not to change the spec, but it would be a good idea
    to point out that standard SASL cancellation token can still be
    used. Adding an example would be even better.<div class=3D"yiv425554918=
2yqt1376411281" id=3D"yiv4255549182yqtfd12097"><br clear=3D"none">
    <blockquote type=3D"cite">
      <div style=3D"color:#000;background-color:#fff;font-family:HelveticaN=
eue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:=
12px;">
        <div class=3D"yiv4255549182qtdSeparateBR" dir=3D"ltr" id=3D"yiv4255=
549182yui_3_16_0_1_1419806870697_1414222">The extant
          implementations use the current sequence.</div>
        <div class=3D"yiv4255549182qtdSeparateBR" dir=3D"ltr" id=3D"yiv4255=
549182yui_3_16_0_1_1419806870697_1414222"><br clear=3D"none">
        </div>
        <div class=3D"yiv4255549182qtdSeparateBR" dir=3D"ltr" id=3D"yiv4255=
549182yui_3_16_0_1_1419806870697_1414222">-bill<br clear=3D"none">
          <br clear=3D"none">
        </div>
        <div class=3D"yiv4255549182yahoo_quoted" id=3D"yiv4255549182yui_3_1=
6_0_1_1419806870697_1414214" style=3D"display:block;">
          <div id=3D"yiv4255549182yui_3_16_0_1_1419806870697_1414213" style=
=3D"font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Gra=
nde, sans-serif;font-size:12px;">
            <div id=3D"yiv4255549182yui_3_16_0_1_1419806870697_1414212" sty=
le=3D"font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida G=
rande, sans-serif;font-size:16px;">
              <div dir=3D"ltr" id=3D"yiv4255549182yui_3_16_0_1_141980687069=
7_1414220"> <font id=3D"yiv4255549182yui_3_16_0_1_1419806870697_1414219" fa=
ce=3D"Arial" size=3D"2"> On Sunday, January 4, 2015 3:37 AM, Alexey
                  Melnikov <a rel=3D"nofollow" shape=3D"rect" class=3D"yiv4=
255549182moz-txt-link-rfc2396E" ymailto=3D"mailto:alexey.melnikov@isode.com=
" target=3D"_blank" href=3D"mailto:alexey.melnikov@isode.com">&lt;alexey.me=
lnikov@isode.com&gt;</a> wrote:<br clear=3D"none">
                </font> </div>
              <br clear=3D"none">
              <br clear=3D"none">
              <div class=3D"yiv4255549182y_msg_container" id=3D"yiv42555491=
82yui_3_16_0_1_1419806870697_1414211">Hi Bill,<br clear=3D"none">
                <div class=3D"yiv4255549182yqt4192359203" id=3D"yiv42555491=
82yqtfd94690"><br clear=3D"none">
                  &gt; On 3 Jan 2015, at 00:56, Bill Mills &lt;<a rel=3D"no=
follow" shape=3D"rect" ymailto=3D"mailto:wmills_92105@yahoo.com" target=3D"=
_blank" href=3D"mailto:wmills_92105@yahoo.com">wmills_92105@yahoo.com</a>&g=
t;
                  wrote:<br clear=3D"none">
                  &gt; <br clear=3D"none">
                  &gt; 3.2.3 and an explicit message:&nbsp; Long ago in the
                  life of this doc I was told that some implementations
                  may not support an empty message, so we put the single
                  character message there to have an explicit payload.&nbsp=
;
                  I'm a bit leery of changing this now since there are
                  implementations in play that use it this way.</div>
                <br clear=3D"none">
                <br clear=3D"none">
                I didn't suggest you should be sending empty message. I
                said you should be using SASL cancellation token, which
                is a mandatory RFC 4422 feature.<br clear=3D"none">
                <br clear=3D"none">
                Any implementation would have to support this mode of
                operation anyway, because a SASL client can cancel any
                exchange.</div>
            </div>
          </div>
        </div>
      </div>
    </blockquote>
    <br clear=3D"none">
  </div></div></div><br clear=3D"none"><br clear=3D"none"></div>  </div> </=
div>  </div></div> </div></div></div><br><br></div>  </div> </div>  </div> =
</div></body></html>
------=_Part_5416115_1332011847.1420571341605--


From nobody Tue Jan  6 11:11:49 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4EE7E1A1B53 for <kitten@ietfa.amsl.com>; Tue,  6 Jan 2015 11:11:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 01tx4j7r5JYO for <kitten@ietfa.amsl.com>; Tue,  6 Jan 2015 11:11:28 -0800 (PST)
Received: from nm21.bullet.mail.bf1.yahoo.com (nm21.bullet.mail.bf1.yahoo.com [98.139.212.180]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 880661A1B49 for <kitten@ietf.org>; Tue,  6 Jan 2015 11:11:19 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1420571478; bh=WVmxI0yBKla1Lg78Ra7C03D5f0UpfWrJSTh12B3V6h8=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=ElF5gmvJWq0ZypQE+33mOqR2JLOOn3Jtuo70OFehRXake9OZ3nTPTd/pdMR5uOqEjpEZcK83DcMQweX5J4eA00gu1GSczEkq9MmEpMFIxWYSsy/JYEHKwJWp/FjfY/DJjA6wy/Jb/P3sz+jUsnmg93FJNJ6J07qSOveFD9/FIBNPn3ew5IX0FJKOqcTUTUZF9l5v7r8N96qXqr2G4kLLE7SGDb10FMDSjDEjZ+UDlFfBlSD4Z8JtG6oClFbkp2gPQdqC4hVB8L7DmlRPKc8taHUYHSqr0iqfii3kADLFfsZ15qrlBts3mTT49oucIf5V15755zdkOCYWX5bVr7EjQg==
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s2048; d=yahoo.com; b=guKF7Cf2psjssVYCzDPvY8QmqcgNOM2zj66syGHmjIUkGQUtjWLNvkXbqc/Kb6/PuCkvW168wG/SR/91X1f2EDyrV1OUet2Uo4wgDA4TLmXFNyhz4w54y1i1B0sX94p7S4rVxy/VB2++DKsOjnt45iU7QOC5r35UvwvWWb6ZGULkv+H4UpFBMhkSVnm/bzWWAv8yJOwEij6o3pL5ypfVlr7qaRrPKU5cd3DtWnDwXMPrJNX9ALxmmn9vZukxTQ+ur8sZXU1VYr+jirGfZEYJjpBUFROf2V+V1aaff9Pd2e4jl7J0vx2aH+uSilp6XvAm5rssQcHOlgMQZMbLlMzd0A==;
Received: from [98.139.215.143] by nm21.bullet.mail.bf1.yahoo.com with NNFMP;  06 Jan 2015 19:11:18 -0000
Received: from [98.139.212.246] by tm14.bullet.mail.bf1.yahoo.com with NNFMP;  06 Jan 2015 19:11:18 -0000
Received: from [127.0.0.1] by omp1055.mail.bf1.yahoo.com with NNFMP; 06 Jan 2015 19:11:18 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 669358.28753.bm@omp1055.mail.bf1.yahoo.com
X-YMail-OSG: DbwBrbwVM1lWtPV2Z00jV_EMLQ6iEq2_asfnovxyC55pI.IsrR75k.URpTPrQxm sFIp4_oyhh5u7Z1Q0cQYbTUPXCf981wn3zyqqo7.3yrnkBdHJQuFZgH0jRPo0t0Unma1lLyUDVGm 5PqJ5qQ8D3jGOhgn.log3m8llCY6_UDy75y9GY8pWSrS4ovEzJ6jCs2LM1lvXJ8zHjIrPjg_TTOi Ch514LgPNnjA7GVJ7O70NEqxzAuuVWNeBFb2nydsE0w7AwotliLUnD5R24J1U630iNcaL_vl1cTD EtxN9J9_lm04i6Rg4YzKSCcKhtCuW9mHBXI580pQFMe8rtbhELgBa517qZHN9WUK4LYoa1c5jTRY xvgypCVxNTYrUZLMNQzPl4h6FjX80sqO10OClr4tijNrsRtaZ7KdhaHvhuN7RYAWqeSCqozOtnlS xrwmVJWhy6Gz9ZBfFu71mE11qQUxwfFHHjiik3xBvDS11cxLWJ3cYaih2WAGqq.7Mi76lRVPkcNl Nc4TYEHfj
Received: by 76.13.27.197; Tue, 06 Jan 2015 19:11:18 +0000 
Date: Tue, 6 Jan 2015 19:11:17 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Alexey Melnikov <alexey.melnikov@isode.com>
Message-ID: <2127327982.5407232.1420571477757.JavaMail.yahoo@jws10604.mail.bf1.yahoo.com>
In-Reply-To: <726434597.5416117.1420571341615.JavaMail.yahoo@jws106101.mail.bf1.yahoo.com>
References: <54AA8627.6020002@isode.com> <1740622945.5399192.1420571205123.JavaMail.yahoo@jws10672.mail.bf1.yahoo.com> <726434597.5416117.1420571341615.JavaMail.yahoo@jws106101.mail.bf1.yahoo.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_5407231_83023343.1420571477750"
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/vNCiyU9OeTmdTBsdx6atD0WbxkM
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Jan 2015 19:11:30 -0000

------=_Part_5407231_83023343.1420571477750
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

never mind, you did mean 2244=20

     On Tuesday, January 6, 2015 11:09 AM, Bill Mills <wmills_92105@yahoo.c=
om> wrote:
  =20

 and you did mean 4422 not 2244 right?=20

     On Tuesday, January 6, 2015 11:06 AM, Bill Mills <wmills_92105@yahoo.c=
om> wrote:
  =20

 Can you point me at an exampel of a cancellation token?=20

     On Monday, January 5, 2015 4:41 AM, Alexey Melnikov <alexey.melnikov@i=
sode.com> wrote:
  =20

  On 05/01/2015 05:14, Bill Mills wrote:
=20
   Ah OK. =C2=A0This is a significant change. =C2=A0Can we make using the c=
ancellation token optional?  =20
 Not really. Any protocol needs to define the cancellation token (according=
 to RFC 2244) and any mechanism implementation (or SASL framework library) =
that doesn't complete in 1 round trip need to be able to handle it.
=20
 I think it is Ok not to change the spec, but it would be a good idea to po=
int out that standard SASL cancellation token can still be used. Adding an =
example would be even better.
=20
  The extant implementations use the current sequence.=20
  -bill
=20
       On Sunday, January 4, 2015 3:37 AM, Alexey Melnikov <alexey.melnikov=
@isode.com> wrote:
  =20
=20
 Hi Bill,
=20
 > On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:
 >=20
 > 3.2.3 and an explicit message:=C2=A0 Long ago in the life of this doc I =
was told that some implementations may not support an empty message, so we =
put the single  character message there to have an explicit payload.=C2=A0 =
I'm a bit leery of changing this now since there are implementations in pla=
y that use it this way.=20
=20
 I didn't suggest you should be sending empty message. I said you should be=
 using SASL cancellation token, which is a mandatory RFC 4422 feature.
=20
 Any implementation would have to support this mode of operation anyway, be=
cause a SASL client can cancel any exchange.    =20
=20
=20

   =20

   =20

   
------=_Part_5407231_83023343.1420571477750
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div id=3D"yui_3_16_0_1_1420472475524_288373" dir=3D"ltr"><sp=
an>never mind, you did mean 2244</span></div> <div class=3D"qtdSeparateBR" =
id=3D"yui_3_16_0_1_1420472475524_288371"><br><br></div><div class=3D"yahoo_=
quoted" style=3D"display: block;" id=3D"yui_3_16_0_1_1420472475524_288364">=
 <div style=3D"font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial=
, Lucida Grande, sans-serif; font-size: 12px;" id=3D"yui_3_16_0_1_142047247=
5524_288363"> <div style=3D"font-family: HelveticaNeue, Helvetica Neue, Hel=
vetica, Arial, Lucida Grande, sans-serif; font-size: 16px;" id=3D"yui_3_16_=
0_1_1420472475524_288362"> <div dir=3D"ltr" id=3D"yui_3_16_0_1_142047247552=
4_288369"> <font size=3D"2" face=3D"Arial" id=3D"yui_3_16_0_1_1420472475524=
_288368"> On Tuesday, January 6, 2015 11:09 AM, Bill Mills &lt;wmills_92105=
@yahoo.com&gt; wrote:<br> </font> </div>  <br><br> <div class=3D"y_msg_cont=
ainer" id=3D"yui_3_16_0_1_1420472475524_288361"><div id=3D"yiv8701553796"><=
div id=3D"yui_3_16_0_1_1420472475524_288360"><div style=3D"color:#000;backg=
round-color:#fff;font-family:HelveticaNeue, Helvetica Neue, Helvetica, Aria=
l, Lucida Grande, sans-serif;font-size:12px;" id=3D"yui_3_16_0_1_1420472475=
524_288359"><div dir=3D"ltr"><span>and you did mean 4422 not 2244 right?</s=
pan></div> <div class=3D"yiv8701553796qtdSeparateBR"><br clear=3D"none"><br=
 clear=3D"none"></div><div class=3D"yiv8701553796yqt6072265964" id=3D"yiv87=
01553796yqt80736"><div class=3D"yiv8701553796yahoo_quoted" style=3D"display=
: block;" id=3D"yui_3_16_0_1_1420472475524_288358"> <div style=3D"font-fami=
ly:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-ser=
if;font-size:12px;" id=3D"yui_3_16_0_1_1420472475524_288357"> <div style=3D=
"font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande=
, sans-serif;font-size:16px;" id=3D"yui_3_16_0_1_1420472475524_288356"> <di=
v dir=3D"ltr"> <font size=3D"2" face=3D"Arial"> On Tuesday, January 6, 2015=
 11:06 AM, Bill Mills &lt;wmills_92105@yahoo.com&gt; wrote:<br clear=3D"non=
e"> </font> </div>  <br clear=3D"none"><br clear=3D"none"> <div class=3D"yi=
v8701553796y_msg_container" id=3D"yui_3_16_0_1_1420472475524_288355"><div i=
d=3D"yiv8701553796"><div id=3D"yui_3_16_0_1_1420472475524_288354"><div styl=
e=3D"color:#000;background-color:#fff;font-family:HelveticaNeue, Helvetica =
Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:12px;" id=3D"yu=
i_3_16_0_1_1420472475524_288353"><div dir=3D"ltr"><span>Can you point me at=
 an exampel of a cancellation token?</span></div> <div class=3D"yiv87015537=
96qtdSeparateBR"><br clear=3D"none"><br clear=3D"none"></div><div class=3D"=
yiv8701553796yqt9407845033" id=3D"yiv8701553796yqt99989"><div class=3D"yiv8=
701553796yahoo_quoted" style=3D"display:block;" id=3D"yui_3_16_0_1_14204724=
75524_288352"> <div style=3D"font-family:HelveticaNeue, Helvetica Neue, Hel=
vetica, Arial, Lucida Grande, sans-serif;font-size:12px;" id=3D"yui_3_16_0_=
1_1420472475524_288351"> <div style=3D"font-family:HelveticaNeue, Helvetica=
 Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:16px;" id=3D"y=
ui_3_16_0_1_1420472475524_288350"> <div dir=3D"ltr" id=3D"yui_3_16_0_1_1420=
472475524_288380"> <font size=3D"2" face=3D"Arial" id=3D"yui_3_16_0_1_14204=
72475524_288379"> On Monday, January 5, 2015 4:41 AM, Alexey Melnikov &lt;a=
lexey.melnikov@isode.com&gt; wrote:<br clear=3D"none"> </font> </div>  <br =
clear=3D"none"><br clear=3D"none"> <div class=3D"yiv8701553796y_msg_contain=
er" id=3D"yui_3_16_0_1_1420472475524_288349"><div id=3D"yiv8701553796"><div=
 id=3D"yui_3_16_0_1_1420472475524_288348">
    On 05/01/2015 05:14, Bill Mills wrote:<br clear=3D"none">
    <blockquote type=3D"cite" id=3D"yui_3_16_0_1_1420472475524_288383">
      <div style=3D"color:#000;background-color:#fff;font-family:HelveticaN=
eue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:=
12px;" id=3D"yui_3_16_0_1_1420472475524_288382">
        <div><span></span></div>
        <div class=3D"yiv8701553796qtdSeparateBR" dir=3D"ltr" id=3D"yiv8701=
553796yui_3_16_0_1_1419806870697_1414222">Ah OK. &nbsp;This
          is a significant change. &nbsp;Can we make using the cancellation
          token optional? </div>
      </div>
    </blockquote>
    Not really. Any protocol needs to define the cancellation token
    (according to RFC 2244) and any mechanism implementation (or SASL
    framework library) that doesn't complete in 1 round trip need to be
    able to handle it.<br clear=3D"none">
    <br clear=3D"none">
    I think it is Ok not to change the spec, but it would be a good idea
    to point out that standard SASL cancellation token can still be
    used. Adding an example would be even better.<div class=3D"yiv870155379=
6yqt1376411281" id=3D"yiv8701553796yqtfd12097"><br clear=3D"none">
    <blockquote type=3D"cite">
      <div style=3D"color:#000;background-color:#fff;font-family:HelveticaN=
eue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:=
12px;">
        <div class=3D"yiv8701553796qtdSeparateBR" dir=3D"ltr" id=3D"yiv8701=
553796yui_3_16_0_1_1419806870697_1414222">The extant
          implementations use the current sequence.</div>
        <div class=3D"yiv8701553796qtdSeparateBR" dir=3D"ltr" id=3D"yiv8701=
553796yui_3_16_0_1_1419806870697_1414222"><br clear=3D"none">
        </div>
        <div class=3D"yiv8701553796qtdSeparateBR" dir=3D"ltr" id=3D"yiv8701=
553796yui_3_16_0_1_1419806870697_1414222">-bill<br clear=3D"none">
          <br clear=3D"none">
        </div>
        <div class=3D"yiv8701553796yahoo_quoted" id=3D"yiv8701553796yui_3_1=
6_0_1_1419806870697_1414214" style=3D"display:block;">
          <div id=3D"yiv8701553796yui_3_16_0_1_1419806870697_1414213" style=
=3D"font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Gra=
nde, sans-serif;font-size:12px;">
            <div id=3D"yiv8701553796yui_3_16_0_1_1419806870697_1414212" sty=
le=3D"font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida G=
rande, sans-serif;font-size:16px;">
              <div dir=3D"ltr" id=3D"yiv8701553796yui_3_16_0_1_141980687069=
7_1414220"> <font id=3D"yiv8701553796yui_3_16_0_1_1419806870697_1414219" fa=
ce=3D"Arial" size=3D"2"> On Sunday, January 4, 2015 3:37 AM, Alexey
                  Melnikov <a rel=3D"nofollow" shape=3D"rect" class=3D"yiv8=
701553796moz-txt-link-rfc2396E" ymailto=3D"mailto:alexey.melnikov@isode.com=
" target=3D"_blank" href=3D"mailto:alexey.melnikov@isode.com">&lt;alexey.me=
lnikov@isode.com&gt;</a> wrote:<br clear=3D"none">
                </font> </div>
              <br clear=3D"none">
              <br clear=3D"none">
              <div class=3D"yiv8701553796y_msg_container" id=3D"yiv87015537=
96yui_3_16_0_1_1419806870697_1414211">Hi Bill,<br clear=3D"none">
                <div class=3D"yiv8701553796yqt4192359203" id=3D"yiv87015537=
96yqtfd94690"><br clear=3D"none">
                  &gt; On 3 Jan 2015, at 00:56, Bill Mills &lt;<a rel=3D"no=
follow" shape=3D"rect" ymailto=3D"mailto:wmills_92105@yahoo.com" target=3D"=
_blank" href=3D"mailto:wmills_92105@yahoo.com">wmills_92105@yahoo.com</a>&g=
t;
                  wrote:<br clear=3D"none">
                  &gt; <br clear=3D"none">
                  &gt; 3.2.3 and an explicit message:&nbsp; Long ago in the
                  life of this doc I was told that some implementations
                  may not support an empty message, so we put the single
                  character message there to have an explicit payload.&nbsp=
;
                  I'm a bit leery of changing this now since there are
                  implementations in play that use it this way.</div>
                <br clear=3D"none">
                <br clear=3D"none">
                I didn't suggest you should be sending empty message. I
                said you should be using SASL cancellation token, which
                is a mandatory RFC 4422 feature.<br clear=3D"none">
                <br clear=3D"none">
                Any implementation would have to support this mode of
                operation anyway, because a SASL client can cancel any
                exchange.</div>
            </div>
          </div>
        </div>
      </div>
    </blockquote>
    <br clear=3D"none">
  </div></div></div><br clear=3D"none"><br clear=3D"none"></div>  </div> </=
div>  </div></div> </div></div></div><br clear=3D"none"><br clear=3D"none">=
</div>  </div> </div>  </div></div> </div></div></div><br><br></div>  </div=
> </div>  </div> </div></body></html>
------=_Part_5407231_83023343.1420571477750--


From nobody Tue Jan  6 13:36:40 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0B9361A86F5 for <kitten@ietfa.amsl.com>; Tue,  6 Jan 2015 13:36:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Dq1SWvvAa9PB for <kitten@ietfa.amsl.com>; Tue,  6 Jan 2015 13:36:37 -0800 (PST)
Received: from nm49-vm4.bullet.mail.bf1.yahoo.com (nm49-vm4.bullet.mail.bf1.yahoo.com [216.109.115.191]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5C8591A1A1E for <kitten@ietf.org>; Tue,  6 Jan 2015 13:36:37 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1420580196; bh=I1umy8vZPZFR1q/UbH/zw1MCsB5hfSyEmCdU90nObqk=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=R7/zEwyGuY5s1dDYv+Qnz2gQFzrdw8Q8fwpcdK57en+w/C8ogZqoAh4MkyFMrNPIpbkjtYrJhlOGTkFa6f3YRYyNSio1SPyo9B98ptzlAdQZzHtce4lt8zhuFFs2T6OH7ODAEIYwzvgnCd4lYYQa7vMbFsx3fFwX8dt0HLPSlCOKltdbrtJydWz1QRqhTRIUA7UD1jejAvnRkxBh2DdVHV38fOx1uAH7bnvkqyZ4W14kfMzcGB+IVH1QSBnVdPV7kHdEs294KBYzty4AQp2Eh214GiTrMUEIBRLxF/1rzQHbOsEzTqzFMcnbT7XPcO8s/4x706fmAtCx7D5DN9gKSA==
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s2048; d=yahoo.com; b=gu0B15daeIIIJc5XZQsLA4LISqPZ8HcriBuIoIL/YnOm1z0mR+XOjm5dpK2fVVqdqGstGei4Z5y6tD6+npUcwkqT4uUU2VwXZcKJAB0tfFmn70RrcyTtgbXWji6RwxeSnztelXpydTPKFk8NW38gbrmF/vWMz2U+mhdN3GVz/Tim0VSHmjY/SVpwx2ZaPW4a8Rb0R+v/5oXZe0ThVzpFe0VHlLeD11WOl6liDFR9uNjnZ4s/JGTvXAhKBnaXyLZIrNDuPoERaEcgKI4Gp18hX1s1HdiiXuBtFOYOkCgx4z+diOwk0tkfXZMqWJ2qgK3bYNC+7pYpfgFgTqUHtTz2LQ==;
Received: from [98.139.215.143] by nm49.bullet.mail.bf1.yahoo.com with NNFMP;  06 Jan 2015 21:36:36 -0000
Received: from [98.139.212.237] by tm14.bullet.mail.bf1.yahoo.com with NNFMP;  06 Jan 2015 21:36:36 -0000
Received: from [127.0.0.1] by omp1046.mail.bf1.yahoo.com with NNFMP; 06 Jan 2015 21:36:36 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 501404.26008.bm@omp1046.mail.bf1.yahoo.com
X-YMail-OSG: wT3O.18VM1mYriQFNmmOPMpagpUPGg1DaD1H7dbhEZ_PQ8vl6eRbyY40YdlHzA8 JAnaw.6mo1YPcAGPFYheaoIIkOCq6z0RhNstTMMlGLCd8D4en51rjZUHWdEladL7nc7Ixo.R1vr_ h_AT8nuzwuyjd8ioSUxWaZCyFjdYqeL.byup2jRJgDRjdlKWQCEi4_DhSVcD_0vWS0BS4NJ7cRCD kJZkSIuRSVTx0fRVOeWMIEa2MxnhqtC5uWHfGE7AoL9kCFTEGBY2yKax1C93IGuccobWepxM49Xr _p8RYteLaYv4A56iTVppVM3SdM39L8qtchhThWublmzbe40gWqAYkAj_mw8XrpKt_BY.csZ8eihm e9OheaWqtmIniE_UpRVamj7I.5GKgGLiUKl0tSOgc7SDkIqQ0Blv8UmacHoy1AC4Y1p.ig4Qkc1o 0rx94undHn4TyKILr9zsh06U4t1oWem.vKXNDYWy95rc_bZOlni6uniZsKhtxy_pVsvxHalIQHDx xP_idrULtxpNmnfSLzzlzEvqyX4sv.xO9OqyyM_Re9YBBanOie87eHar4DfusHQjaW6TZQ6v2s0z x_DRnDrQvTk111OrH9BIl4J5qbMfhLmcrMA.1hoRjat0o9hzlwdIEnAdtFRmwcw--
Received: by 66.196.80.126; Tue, 06 Jan 2015 21:36:36 +0000 
Date: Tue, 6 Jan 2015 21:36:35 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Alexey Melnikov <alexey.melnikov@isode.com>
Message-ID: <256029732.199845.1420580195408.JavaMail.yahoo@jws106115.mail.bf1.yahoo.com>
In-Reply-To: <F4209A2F-CEB5-498B-9DA9-1C4628C64BE4@isode.com>
References: <F4209A2F-CEB5-498B-9DA9-1C4628C64BE4@isode.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_199844_1631245068.1420580195404"
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/EsuXbmjzAGrGYL-fTUIsKzrNP-s
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: [kitten] Cancel message Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Jan 2015 21:36:39 -0000

------=_Part_199844_1631245068.1420580195404
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

"=C2=A0The client MUST then send either an additional client response consi=
sting of a single %x01 (control A) character to the server in order to allo=
w the server to finish the exchange or send a SASL cancellation token as de=
fined in ACAP[RFC2244]=C2=A0section 6.3.1."=20

     On Sunday, January 4, 2015 3:37 AM, Alexey Melnikov <alexey.melnikov@i=
sode.com> wrote:
  =20

 Hi Bill,

> On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:
>=20
> 3.2.3 and an explicit message:=C2=A0 Long ago in the life of this doc I w=
as told that some implementations may not support an empty message, so we p=
ut the single character message there to have an explicit payload.=C2=A0 I'=
m a bit leery of changing this now since there are implementations in play =
that use it this way.

I didn't suggest you should be sending empty message. I said you should be =
using SASL cancellation token, which is a mandatory RFC 4422 feature.

Any implementation would have to support this mode of operation anyway, bec=
ause a SASL client can cancel any exchange.



   
------=_Part_199844_1631245068.1420580195404
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div id=3D"yui_3_16_0_1_1420579175477_6993"><span>"</span>&nb=
sp;<span style=3D"font-family: verdana, helvetica, arial, sans-serif; font-=
size: 13px;" class=3D"">The client MUST then send either an additional clie=
nt response consisting of a single %x01 (control A) character to the server=
 in order to allow the server to finish the exchange or send a SASL cancell=
ation token as defined in ACAP</span><a href=3D"https://us-mg0.mail.yahoo.c=
om/neo/launch?.rand=3D1lc7cfbnjsq0p#RFC2244" style=3D"font-family: verdana,=
 helvetica, arial, sans-serif; font-size: 13px; text-decoration: none; back=
ground-color: rgb(255, 255, 255);" class=3D"">[RFC2244]</a><span style=3D"f=
ont-family: verdana, helvetica, arial, sans-serif; font-size: 13px;" class=
=3D"">&nbsp;</span><span style=3D"font-family: verdana, helvetica, arial, s=
ans-serif; font-size: 13px;" class=3D"">section 6.3.1."</span></div> <div c=
lass=3D"qtdSeparateBR"><br><br></div><div class=3D"yahoo_quoted" style=3D"d=
isplay: block;"> <div style=3D"font-family: HelveticaNeue, Helvetica Neue, =
Helvetica, Arial, Lucida Grande, sans-serif; font-size: 12px;"> <div style=
=3D"font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Gr=
ande, sans-serif; font-size: 16px;"> <div dir=3D"ltr"> <font size=3D"2" fac=
e=3D"Arial"> On Sunday, January 4, 2015 3:37 AM, Alexey Melnikov &lt;alexey=
.melnikov@isode.com&gt; wrote:<br> </font> </div>  <br><br> <div class=3D"y=
_msg_container">Hi Bill,<br clear=3D"none"><div class=3D"yqt7536736220" id=
=3D"yqtfd36038"><br clear=3D"none">&gt; On 3 Jan 2015, at 00:56, Bill Mills=
 &lt;<a shape=3D"rect" ymailto=3D"mailto:wmills_92105@yahoo.com" href=3D"ma=
ilto:wmills_92105@yahoo.com">wmills_92105@yahoo.com</a>&gt; wrote:<br clear=
=3D"none">&gt; <br clear=3D"none">&gt; 3.2.3 and an explicit message:&nbsp;=
 Long ago in the life of this doc I was told that some implementations may =
not support an empty message, so we put the single character message there =
to have an explicit payload.&nbsp; I'm a bit leery of changing this now sin=
ce there are implementations in play that use it this way.</div><br clear=
=3D"none"><br clear=3D"none">I didn't suggest you should be sending empty m=
essage. I said you should be using SASL cancellation token, which is a mand=
atory RFC 4422 feature.<br clear=3D"none"><br clear=3D"none">Any implementa=
tion would have to support this mode of operation anyway, because a SASL cl=
ient can cancel any exchange.<div class=3D"yqt7536736220" id=3D"yqtfd53837"=
><br clear=3D"none"><br clear=3D"none"></div><br><br></div>  </div> </div> =
 </div> </div></body></html>
------=_Part_199844_1631245068.1420580195404--


From nobody Tue Jan  6 13:37:52 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 40D651A1AA7 for <kitten@ietfa.amsl.com>; Tue,  6 Jan 2015 13:37:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.791
X-Spam-Level: *
X-Spam-Status: No, score=1.791 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, J_CHICKENPOX_41=0.6, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yZCUhH9g7lJH for <kitten@ietfa.amsl.com>; Tue,  6 Jan 2015 13:37:50 -0800 (PST)
Received: from nm1-vm1.bullet.mail.bf1.yahoo.com (nm1-vm1.bullet.mail.bf1.yahoo.com [98.139.213.163]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DD5001A1A1E for <kitten@ietf.org>; Tue,  6 Jan 2015 13:37:49 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1420580269; bh=jvSmLH2hz8ZR0AaozAdX4lJo0Rn+ysun0gR0oes3J20=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=EcWfWnEmbwhfl9+JB2JAdZbirtFOs4stH7aA7y0hPifvQBXI4ntbzgWlfJlrzP2N7YsxwFlUsn3F7UDILtwFMRDukPRoDm9GyDNDqCxc12PzEp2u5pbWNfW7kBUAKL0URgjIQDAGospPTymyPIHlBCV1e2Cl5ggUN+pqP2ScbxMq1Bp+ecZp65Ka9mXgnqNxcegFvBNfDoFw9xDnjYcXYGlLm/LlpWL8FJGV+zeJoPLw80XWORdk283lB7i5GuQHoY49W1n3gu0KYWabLVK0UrcXPlx2VcCDfsZPJXEZmNK3iHSgs0HNKeP0d5DSD9KTY8uBOBP3ZwO+XmxJbNtllg==
Received: from [66.196.81.172] by nm1.bullet.mail.bf1.yahoo.com with NNFMP; 06 Jan 2015 21:37:49 -0000
Received: from [98.139.212.224] by tm18.bullet.mail.bf1.yahoo.com with NNFMP;  06 Jan 2015 21:37:49 -0000
Received: from [127.0.0.1] by omp1033.mail.bf1.yahoo.com with NNFMP; 06 Jan 2015 21:37:49 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 142791.24683.bm@omp1033.mail.bf1.yahoo.com
X-YMail-OSG: JoogHpYVM1nXXAnlhjKrxVWarEVbufpds3lqMXqjUbzZSJoxeFEiEnGUDdosVsV AoWJAW9slo4CmvJI91AfuAXaomCWxfsrjwEzpGqeY4jua_XLBSO07BPA18r1shLfcAme2JBSBFX3 6N8ptgh5SoQrP33mpF.BVt5fJuWRl7Bg36yvYJeUq3ZLS4ipx1RTP.zxUTRwxwjM8XBj.LeQpOPc roM9HBHLHuNIBgHuA.U6To0C.VgGMWtvfZuNKPQ_sAmvlMJ.upaN0EuJ_r9NBfnC_U4yOxXmNOhB OMKDLteuA1vrxxuLi4mgE0nylG6Io0To5weobN6PGedXidIs_gCdw5q28T6lA0F4a8KRR_QNoYB9 98BpNZHJZDP7UO41nsadbmMIxYWJlfYtda_cg.KjDEySaLZ754X.zT6tTzToS5NWUyxllGFDGPhl 05XQJtxwjbtzikmLnPfoLRjT3AgN6uwsponjvNiQNGdLeFbEWLlczWkovs9l7JSRMeP2ThMo0Cd3 .oUKYVcqB
Received: by 76.13.27.48; Tue, 06 Jan 2015 21:37:48 +0000 
Date: Tue, 6 Jan 2015 21:37:48 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Alexey Melnikov <alexey.melnikov@isode.com>
Message-ID: <1305287583.200513.1420580268309.JavaMail.yahoo@jws106115.mail.bf1.yahoo.com>
In-Reply-To: <78174425-E391-4E6D-85DD-99D3B3A715EC@isode.com>
References: <78174425-E391-4E6D-85DD-99D3B3A715EC@isode.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_200512_443064476.1420580268304"
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/-qW_NrQDRGJSr4By1FlDIR8sOf8
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: [kitten] TLS reqmt Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Jan 2015 21:37:51 -0000

------=_Part_200512_443064476.1420580268304
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Added the proposed text.=20

     On Sunday, January 4, 2015 3:41 AM, Alexey Melnikov <alexey.melnikov@i=
sode.com> wrote:
  =20

 Hi Bill,
On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:


On requiring TLS and adding STARTTLS to the examples: your'e not happy with=
 the current "Note that line=C2=A0 breaks are inserted for readability and =
the underlying TLS establishment is not shown either."? =C2=A0I'd prefer to=
 add text saying something like "These Bearer token examples assume encrypt=
ed transport, if the underlying connection is not already TLS then STARTTLS=
 MUST be used as required in the Bearer Token specification.".

Yes, that would work and I think your expanded text is better.

 =C2=A0I can also easily specify that this is IMAP over 995

993

or SMTP over 465.

I suggest you don't do that, because neither port 993 nor 465 are registere=
d with IANA. I know it is not your problem, but there is no point in potent=
ially getting this document delayed by this.


   
------=_Part_200512_443064476.1420580268304
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div id=3D"yui_3_16_0_1_1420579175477_8440" dir=3D"ltr"><span=
 id=3D"yui_3_16_0_1_1420579175477_8551">Added the proposed text.</span></di=
v> <div class=3D"qtdSeparateBR"><br><br></div><div class=3D"yahoo_quoted" s=
tyle=3D"display: block;"> <div style=3D"font-family: HelveticaNeue, Helveti=
ca Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 12px;"> <d=
iv style=3D"font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, L=
ucida Grande, sans-serif; font-size: 16px;"> <div dir=3D"ltr"> <font size=
=3D"2" face=3D"Arial"> On Sunday, January 4, 2015 3:41 AM, Alexey Melnikov =
&lt;alexey.melnikov@isode.com&gt; wrote:<br> </font> </div>  <br><br> <div =
class=3D"y_msg_container"><div id=3D"yiv7799931705"><div><div>Hi Bill,</div=
><div><br clear=3D"none">On 3 Jan 2015, at 00:56, Bill Mills &lt;<a rel=3D"=
nofollow" shape=3D"rect" ymailto=3D"mailto:wmills_92105@yahoo.com" target=
=3D"_blank" href=3D"mailto:wmills_92105@yahoo.com">wmills_92105@yahoo.com</=
a>&gt; wrote:<br clear=3D"none"><br clear=3D"none"></div><blockquote type=
=3D"cite">On requiring TLS and adding STARTTLS to the examples: your'e not =
happy with the current "<span class=3D"yiv7799931705" style=3D"font-size:12=
px;">Note that line&nbsp;</span><span class=3D"yiv7799931705" style=3D"font=
-size:12px;white-space:pre;">=09</span><span id=3D"yiv7799931705yui_3_16_0_=
1_1419806870697_724221" style=3D"font-size:12px;">breaks are inserted for r=
eadability and the underlying TLS establishment is not shown either."? &nbs=
p;I'd prefer to add text saying something like "These Bearer token examples=
 assume encrypted transport, if the underlying connection is not already TL=
S then STARTTLS MUST be used as required in the Bearer Token specification.=
".</span></blockquote><div><br clear=3D"none"></div>Yes, that would work an=
d I think your expanded text is better.<div><br clear=3D"none"><blockquote =
type=3D"cite"><span id=3D"yiv7799931705yui_3_16_0_1_1419806870697_724221" s=
tyle=3D"font-size:12px;"> &nbsp;I can also easily specify that this is IMAP=
 over 995</span></blockquote><div><br clear=3D"none"></div>993<div class=3D=
"yiv7799931705yqt2201602498" id=3D"yiv7799931705yqtfd57121"><br clear=3D"no=
ne"><blockquote type=3D"cite"><span id=3D"yiv7799931705yui_3_16_0_1_1419806=
870697_724221" style=3D"font-size:12px;">or SMTP over 465.</span></blockquo=
te></div><br clear=3D"none"></div><div>I suggest you don't do that, because=
 neither port 993 nor 465 are registered with IANA. I know it is not your p=
roblem, but there is no point in potentially getting this document delayed =
by this.</div><div class=3D"yiv7799931705yqt2201602498" id=3D"yiv7799931705=
yqtfd19188"><div><br clear=3D"none"></div></div></div></div><br><br></div> =
 </div> </div>  </div> </div></body></html>
------=_Part_200512_443064476.1420580268304--


From nobody Tue Jan  6 13:39:23 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5EBA01A8712 for <kitten@ietfa.amsl.com>; Tue,  6 Jan 2015 13:39:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id W_8k--_DP5An for <kitten@ietfa.amsl.com>; Tue,  6 Jan 2015 13:39:20 -0800 (PST)
Received: from nm1-vm1.bullet.mail.bf1.yahoo.com (nm1-vm1.bullet.mail.bf1.yahoo.com [98.139.213.163]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D49E31A1A1E for <kitten@ietf.org>; Tue,  6 Jan 2015 13:39:19 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1420580359; bh=G8Js+hG8DxtQQe6A0S5lF4M3my2f4/zYmVJl6W9yWio=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=i/QIJSEgDtjy/IbnKjVJEuOrLYFnN4qerRZJV2BS9Ucq+TlMWkfqi6Jk43F3gXbThGiiz4Fap31LV5wI7v1kKVpdu0td7WQElEICHESaDygT2Gxj/Chos1jX7EqkjPQJ2Q6YEh/2/i98MwZDob0QvQponUBMIaQ/cN6LwvzLWsYeEYabCsCTGluBq/AVcImsRQO2Xm4wcpJkdgzrgU4upORuWBOVDl+XiE0Lo4pkPMsnar7wGFqgiDvz6sjOvJcI1xxqxpsKRNoPzq5GLupPwWm99faaaXfqjfIslBbMZxmxr6NBNmmbogaoA3xrETI2Tp3RDct9PZTaCnyz81ysIQ==
Received: from [66.196.81.173] by nm1.bullet.mail.bf1.yahoo.com with NNFMP; 06 Jan 2015 21:39:19 -0000
Received: from [98.139.212.199] by tm19.bullet.mail.bf1.yahoo.com with NNFMP;  06 Jan 2015 21:39:19 -0000
Received: from [127.0.0.1] by omp1008.mail.bf1.yahoo.com with NNFMP; 06 Jan 2015 21:39:19 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 41037.81260.bm@omp1008.mail.bf1.yahoo.com
X-YMail-OSG: 4yHYJ30VM1lTcA5Oj3GzmBQB7DFlL8qu.zGAnAGeqwShuF8STj03EL1bbu4rveZ f7_wm6zd8OWJI24E9.Z2Inxc6aHjcAXrZJorOHST2Dp.VqCbQhz0E8eKJL0CpHLlbSIqti2W3s9q 32SwnmoZt3acTquwhdormjq9rwHKTYBX4KiQrMHBrAQxFnhZpgQR9Dn7TO_2vGiQ2TK_xYHvidoQ 4tsaRAIBTeFhK2xPd8YZSygtXS4AfrD3Far07nXEQpdz1TF3g9O53uL.8E7UdvZ.7fxI.UFeqfMn 7CgF6PR4u9EJdIVt7UE4C8DyHn1cQMC6SFsMYmT3QjI7R7pT3xWxHq7RmLS7PIhcjWLcnUu6ra8. _vj4frj682qfBYdNvENkDsYupToWmQ2uxVxtIE79q9x9riZaau01lR5E_2upsls.hGjL2uGT3Pf. aC5RBbvVkxwJprhi7Afvt7Qdq9K2g1DfjJffRIAgvXX._bDKpSNstPXMtwtdN0eG8jyNX62EvPFD G8MIgIRSEJNeQDAAM12B8nsq2v9rxRcN6QLF0mzq3IIXk5EipE6y0BWNMbUNyENrpJk4KbtKsJbo rGie4t4OFTgp7iYU8O2IPqnZpeE2DvKTX.dhxwZ4Q7jH8zD2P0ps8ZE3mibBLZg--
Received: by 76.13.26.137; Tue, 06 Jan 2015 21:39:18 +0000 
Date: Tue, 6 Jan 2015 21:39:18 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Alexey Melnikov <alexey.melnikov@isode.com>
Message-ID: <1925662348.5489214.1420580358172.JavaMail.yahoo@jws106149.mail.bf1.yahoo.com>
In-Reply-To: <0FBE45D4-68AE-46D8-B42E-A1DAA8557F2F@isode.com>
References: <0FBE45D4-68AE-46D8-B42E-A1DAA8557F2F@isode.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_5489213_650318303.1420580358165"
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/5ZT7G_mgkpdLwalCAPU2g8TbJZs
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Jan 2015 21:39:21 -0000

------=_Part_5489213_650318303.1420580358165
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Updated that section:
"The URL for a document following the OpenID Provider Configuration Informa=
tion schema as described in OpenID Connect Discovery (OIDCD)=C2=A0[OpenID.D=
iscovery]=C2=A0section 3 that is appropriate for the user. As specified in =
OIDCD this will have the "https" URL scheme.=C2=A0"=20

     On Sunday, January 4, 2015 3:46 AM, Alexey Melnikov <alexey.melnikov@i=
sode.com> wrote:
  =20

 Hi Bill,

> On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:
>=20
> re 3.2.2 and the OpendID configuration URL.=C2=A0 That spec requires "htt=
ps" explicitly already.=C2=A0 Repeat that here?=C2=A0 Easy to cite that spe=
c and say HTTPS is required but I usually try not to repeat things defined =
other places.

I would prefer if you add "as per XXX spec, this is always "https" URL". Th=
is might be obvious for somebody who knows OpenID specs in details, but I t=
hink this sort reminder would help implementors who don't have time to rese=
arch this in details.

Best Regards,
Alexey


   
------=_Part_5489213_650318303.1420580358165
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div id=3D"yui_3_16_0_1_1420579175477_14582"><span class=3D""=
 style=3D"border-collapse: separate; font-family: Arial; border-spacing: 0p=
x; font-size: medium;" id=3D"yui_3_16_0_1_1420579175477_14603"><span class=
=3D"" style=3D"font-family: verdana, helvetica, arial, sans-serif; font-siz=
e: 13px; " id=3D"yui_3_16_0_1_1420579175477_14602">Updated that section:</s=
pan></span></div><div id=3D"yui_3_16_0_1_1420579175477_14582"><span class=
=3D"" style=3D"border-collapse: separate; font-family: Arial; border-spacin=
g: 0px; font-size: medium;"><span class=3D"" style=3D"font-family: verdana,=
 helvetica, arial, sans-serif; font-size: 13px; "><br></span></span></div><=
div id=3D"yui_3_16_0_1_1420579175477_14582"><span class=3D"" style=3D"borde=
r-collapse: separate; font-family: Arial; border-spacing: 0px; font-size: m=
edium;" id=3D"yui_3_16_0_1_1420579175477_14604"><span class=3D"" style=3D"f=
ont-family: verdana, helvetica, arial, sans-serif; font-size: 13px; " id=3D=
"yui_3_16_0_1_1420579175477_14605">"The URL for a document following the Op=
enID Provider Configuration Information schema as described in OpenID Conne=
ct Discovery (OIDCD)&nbsp;<a href=3D"https://us-mg0.mail.yahoo.com/neo/laun=
ch?.rand=3D1lc7cfbnjsq0p#OpenID.Discovery" style=3D"text-decoration: none; =
" class=3D"">[OpenID.Discovery]</a>&nbsp;section 3 that is appropriate for =
the user. As specified in OIDCD this will have the "https" URL scheme.&nbsp=
;"</span></span><span></span></div> <div class=3D"qtdSeparateBR" id=3D"yui_=
3_16_0_1_1420579175477_14549"><br><br></div><div class=3D"yahoo_quoted" sty=
le=3D"display: block;" id=3D"yui_3_16_0_1_1420579175477_14545"> <div style=
=3D"font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Gr=
ande, sans-serif; font-size: 12px;" id=3D"yui_3_16_0_1_1420579175477_14544"=
> <div style=3D"font-family: HelveticaNeue, Helvetica Neue, Helvetica, Aria=
l, Lucida Grande, sans-serif; font-size: 16px;" id=3D"yui_3_16_0_1_14205791=
75477_14543"> <div dir=3D"ltr" id=3D"yui_3_16_0_1_1420579175477_14546"> <fo=
nt size=3D"2" face=3D"Arial" id=3D"yui_3_16_0_1_1420579175477_14547"> On Su=
nday, January 4, 2015 3:46 AM, Alexey Melnikov &lt;alexey.melnikov@isode.co=
m&gt; wrote:<br> </font> </div>  <br><br> <div class=3D"y_msg_container" id=
=3D"yui_3_16_0_1_1420579175477_14542">Hi Bill,<br clear=3D"none"><br clear=
=3D"none">&gt; On 3 Jan 2015, at 00:56, Bill Mills &lt;<a shape=3D"rect" ym=
ailto=3D"mailto:wmills_92105@yahoo.com" href=3D"mailto:wmills_92105@yahoo.c=
om">wmills_92105@yahoo.com</a>&gt; wrote:<br clear=3D"none">&gt; <br clear=
=3D"none">&gt; re 3.2.2 and the OpendID configuration URL.&nbsp; That spec =
requires "https" explicitly already.&nbsp; Repeat that here?&nbsp; Easy to =
cite that spec and say HTTPS is required but I usually try not to repeat th=
ings defined other places.<br clear=3D"none"><br clear=3D"none">I would pre=
fer if you add "as per XXX spec, this is always "https" URL". This might be=
 obvious for somebody who knows OpenID specs in details, but I think this s=
ort reminder would help implementors who don't have time to research this i=
n details.<br clear=3D"none"><br clear=3D"none">Best Regards,<div class=3D"=
yqt6976547613" id=3D"yqtfd39527"><br clear=3D"none">Alexey<br clear=3D"none=
"></div><br><br></div>  </div> </div>  </div> </div></body></html>
------=_Part_5489213_650318303.1420580358165--


From nobody Wed Jan  7 09:20:22 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A2B411A0081; Wed,  7 Jan 2015 09:20:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uHBvDjKK7XXS; Wed,  7 Jan 2015 09:20:06 -0800 (PST)
Received: from dmz-mailsec-scanner-7.mit.edu (dmz-mailsec-scanner-7.mit.edu [18.7.68.36]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B0BED1A004B; Wed,  7 Jan 2015 09:20:00 -0800 (PST)
X-AuditID: 12074424-f791c6d000000d25-23-54ad6abf2594
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-7.mit.edu (Symantec Messaging Gateway) with SMTP id E8.59.03365.FBA6DA45; Wed,  7 Jan 2015 12:19:59 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id t07HJwCA005922; Wed, 7 Jan 2015 12:19:59 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t07HJvBB003016 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 7 Jan 2015 12:19:58 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t07HJuGU012448; Wed, 7 Jan 2015 12:19:56 -0500 (EST)
Date: Wed, 7 Jan 2015 12:19:56 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: iesg@ietf.org
Message-ID: <alpine.GSO.1.10.1501071214260.23489@multics.mit.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrFIsWRmVeSWpSXmKPExsUixCmqrbs/a22IwbQWTYsZfyYyWxzdvIrF gcljyZKfTAGMUVw2Kak5mWWpRfp2CVwZD981sRYsZKm4unUdcwPjWeYuRk4OCQETicN7PrFB 2GISF+6tB7OFBBYzSUx84drFyAVkb2CU6FyxgxnCOcgk8eLcXVaIqnqJ+d3TmLoYOThYBLQk Jl2oAAmzCahIzHyzEWyQiICgxM5rk8FsZgFhifXnZoAtFhYwlmh62sUOYvMKOErM+fqKCcQW FdCRWL1/CgtEXFDi5MwnLBC9WhLLp29jmcDIPwtJahaS1AJGplWMsim5Vbq5iZk5xanJusXJ iXl5qUW65nq5mSV6qSmlmxhBwcbuorKDsfmQ0iFGAQ5GJR7egr41IUKsiWXFlbmHGCU5mJRE eZ9krg0R4kvKT6nMSCzOiC8qzUktPsQowcGsJMLrmgyU401JrKxKLcqHSUlzsCiJ8276wRci JJCeWJKanZpakFoEk5Xh4FCS4D0LMlSwKDU9tSItM6cEIc3EwQkynAdo+F+QGt7igsTc4sx0 iPwpRl2OBe37ZzIJseTl56VKifMeBykSACnKKM2DmwNLEq8YxYHeEuY9BFLFA0wwcJNeAS1h AlqStXw1yJKSRISUVAOjg8wbg8cSPxb9SvYK9y3c07n7WUig4oYFdgdXnVS9cPXGrKyPkvO4 9Pk6S19dOGz5VLLvU01ZwdaU6t/qLMf8bfrkbsT/O1/zh+HRuebFD051LrPwbzt3PvvlJF2r Gf2sJmtDlOc+v37xT8/UpGpDV4146a/LGDasnxD+cuGGmyHh0UebLBL6lViKMxINtZiLihMB pK6cK+0CAAA=
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/6HXqtpl8TTNGqKPCO0sNe-kZQhk
Cc: kitten@ietf.org
Subject: [kitten] pending edits for draft-ietf-kitten-cammac
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Jan 2015 17:20:14 -0000

Hi all,

The authors have staged some (basically editorial) changes in response to
the Gen-ART and OPS-DIR reviews, as well as Barry's suggested changes, but
plan to defer submitting a new revision until after tomorrow's IESG call.

The new full text is at [0], and a diff to the -00 which is on the ballot
is at [1].

-Ben

[0] http://web.mit.edu/tlyu/cammac/draft-ietf-kitten-cammac-01.txt

[1] https://tools.ietf.org/rfcdiff?url2=http://web.mit.edu/tlyu/cammac/draft-ietf-kitten-cammac-01.txt&url1=draft-ietf-kitten-cammac-00


From nobody Wed Jan  7 09:58:03 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E3DE41A00B0 for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 09:58:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 39FE-g0I4doX for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 09:58:00 -0800 (PST)
Received: from dmz-mailsec-scanner-1.mit.edu (dmz-mailsec-scanner-1.mit.edu [18.9.25.12]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D3ED31A00A9 for <kitten@ietf.org>; Wed,  7 Jan 2015 09:57:58 -0800 (PST)
X-AuditID: 1209190c-f79e46d000000eb2-da-54ad73a540a8
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-1.mit.edu (Symantec Messaging Gateway) with SMTP id 44.C2.03762.5A37DA45; Wed,  7 Jan 2015 12:57:57 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id t07HvuTM013946; Wed, 7 Jan 2015 12:57:56 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t07HvscE025271 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 7 Jan 2015 12:57:55 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t07HvrdH017250; Wed, 7 Jan 2015 12:57:53 -0500 (EST)
Date: Wed, 7 Jan 2015 12:57:53 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Bill Mills <wmills_92105@yahoo.com>
In-Reply-To: <1925662348.5489214.1420580358172.JavaMail.yahoo@jws106149.mail.bf1.yahoo.com>
Message-ID: <alpine.GSO.1.10.1501071251500.23489@multics.mit.edu>
References: <0FBE45D4-68AE-46D8-B42E-A1DAA8557F2F@isode.com> <1925662348.5489214.1420580358172.JavaMail.yahoo@jws106149.mail.bf1.yahoo.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrHIsWRmVeSWpSXmKPExsUixCmqrLu0eG2IwZaJYhYzVhdZHN28isXi W9d1ZgdmjyVLfjJ5nGo29Jg16zBTAHMUl01Kak5mWWqRvl0CV8bpeUdYC5rYKn5MrW1gfMDS xcjJISFgIvHs71soW0ziwr31bF2MXBxCAouZJLYdWs0E4WxglNj06QkrhHOQSaJn73KgMg4g p16ia5MKSDeLgJbEvs7Z7CA2m4CKxMw3G8FKRATUJZq/e4OYzAKxEksOJYFUCAuESnz5uJsN xOYUiJbofTgTzOYVcJRobb4PtambUeLMri9gx4kK6Eis3j+FBaJIUOLkzCdgNjPQ2uXTt7FM YBSchSQ1C0lqASPTKkbZlNwq3dzEzJzi1GTd4uTEvLzUIl1DvdzMEr3UlNJNjOCgleTZwfjm oNIhRgEORiUe3oK+NSFCrIllxZW5hxglOZiURHlji9aGCPEl5adUZiQWZ8QXleakFh9ilOBg VhLhdU0GyvGmJFZWpRblw6SkOViUxHk3/eALERJITyxJzU5NLUgtgsnKcHAoSfB+AxkqWJSa nlqRlplTgpBm4uAEGc4DNFypGGR4cUFibnFmOkT+FKMux4L2/TOZhFjy8vNSpcQhBgmAFGWU 5sHNgSWbV4ziQG8J81aDVPEAExXcpFdAS5iAlmQtXw2ypCQRISXVwFha/P+lwyShzkOFwQWp KT+6LmxmY3zzvoNhibgPU+M/pYKF9q/dRPrm/ZpaZ5cjVNumEr9sU9hF8675vxdt6uft0Qj5 9zPx+WuG8ELnAs8MPUW/Tp5HztvZ9d/Pa+Ts+z8jOnCFwN6nBllsmxnX7Tp0T2/hVwHOnwum J17hzfzjH5DzhjdyhRJLcUaioRZzUXEiAJjdmocRAwAA
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/quqsR9bQNrJi1Z4QtkO0kFcrtBs
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Jan 2015 17:58:02 -0000

Bill, Alexey,

Thanks for working through these comments (I'm still catching up after the
holidays) -- I do agree with Alexey that having the examples right is very
important.

Looking through this thread, I don't see a response to one of Alexey's
comments, though:

% client_resp    = (gs2-header kvsep 0*kvpair kvsep) / kvsep
%
% Did you mean that the whole client response can be just a single separator
% character? I think this is not compatible with GS2 framing. If you only meant to
% allow that for failed authentication, I suggest you add a comment and point to
% section 3.2.3.

If I correctly remember how things work, I think that Alexey is right that
this is only allowed for failed authentication, so a comment is needed
here.

-Ben


From nobody Wed Jan  7 10:11:37 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D8BD31A0270 for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 10:11:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qugHu6qQCCN8 for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 10:11:33 -0800 (PST)
Received: from dmz-mailsec-scanner-8.mit.edu (dmz-mailsec-scanner-8.mit.edu [18.7.68.37]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D79881A1A90 for <kitten@ietf.org>; Wed,  7 Jan 2015 10:05:44 -0800 (PST)
X-AuditID: 12074425-f798e6d000000d1a-e7-54ad7573a27e
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-8.mit.edu (Symantec Messaging Gateway) with SMTP id E7.3A.03354.3757DA45; Wed,  7 Jan 2015 13:05:39 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id t07I5crd015429 for <kitten@ietf.org>; Wed, 7 Jan 2015 13:05:39 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t07I5aYA029722 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Wed, 7 Jan 2015 13:05:38 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t07I5avE018212; Wed, 7 Jan 2015 13:05:36 -0500 (EST)
Date: Wed, 7 Jan 2015 13:05:36 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
Message-ID: <alpine.GSO.1.10.1501071258380.23489@multics.mit.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFjrFIsWRmVeSWpSXmKPExsUixCmqrFtcujbE4MQKEYujm1exODB6LFny kymAMYrLJiU1J7MstUjfLoEr49bx9awFFxkrPt/wbWBcxNjFyMkhIWAicW/1fjYIW0ziwr31 QDYXh5DAYiaJRV/PMkM4xxglVv+/AZW5ziRx9th2FpAWIYF6idkP/7GC2CwCWhKnbl0Di7MJ qEjMfLMRbKyIgLDE7q3vmEFsYQF5icfXJoDFeQUcJS792glmiwroSKzeP4UFIi4ocXLmEzCb GWjm8unbWCYw8s1CkpqFJLWAkWkVo2xKbpVubmJmTnFqsm5xcmJeXmqRroVebmaJXmpK6SZG UDCxu6juYJxwSOkQowAHoxIPb0HfmhAh1sSy4srcQ4ySHExKorysJWtDhPiS8lMqMxKLM+KL SnNSiw8xSnAwK4nwuiYD5XhTEiurUovyYVLSHCxK4rybfvCFCAmkJ5akZqemFqQWwWRlODiU JHgzQYYKFqWmp1akZeaUIKSZODhBhvMADRcCqeEtLkjMLc5Mh8ifYtTlWNC+fyaTEEtefl6q lDivDkiRAEhRRmke3BxYEnjFKA70ljBvMkgVDzCBwE16BbSECWhJ1vLVIEtKEhFSUg2Mrft5 LD/5n7pwo1VWaJ+gyekJFxtOHf2wPmB73gtp7mu/OcU33ff953b8737zTsuXXB9qz8jc3zMn 88Y+RaaydId6Neb2drWX24u4xRe/CNzUyaK/SD3re2Klm+Dx3OqsqkPfMo6/jGzISL1z6ovg F8nsDRZ533mbMr08xCMtu5OFnxv2frJWYinOSDTUYi4qTgQAyrnRyd0CAAA=
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/t1ftyFXnke3dPKsZ842J4GyEiPY
Subject: [kitten] IETF 92 - Agenda items
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Jan 2015 18:11:35 -0000

Hi all,

IETF 92 is March 22-27 in Dallas.  Please provide any agenda items for a
Dallas session, either to the list or to the co-chairs, no later than
Tuesday, January 20, 2015.

-Ben
kitten co-chair


From nobody Wed Jan  7 10:15:04 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7AF6B1A0233 for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 10:14:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wGAaOIBznn0R for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 10:14:54 -0800 (PST)
Received: from nm11-vm1.bullet.mail.bf1.yahoo.com (nm11-vm1.bullet.mail.bf1.yahoo.com [98.139.213.152]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4F2BC1A0270 for <kitten@ietf.org>; Wed,  7 Jan 2015 10:12:02 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1420654321; bh=3HzGKvFL9rhDFGn8gJ2F8wbSVN6JGDpZnpe1bR40JLU=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=uEUn1dGofFpGCPp4wXUwyeV3EI9wwR80qx8PM7ty8nexxuZ+jEpGLS+B8TG4DHxQufbxLVcSWf8lmCxdH8c2XLwqWUZR4SZTmFAF1e8gJi0PDXeOUScT2BkzgZJPWRaeA4BlIPLEVG6IATHI2eObzc89raUGUs3dvwPredtbWXvzozz6eLBJJwEiMz9wIpj9fqsy28Hf3rWgS6jWP3j62G3l2b+qUdlECk3Aj1nXYEarsa7EZ731yTwuJL6PCEW0y8zxUhCJ725iD4EwebFlwtbNsdJpYM0lcVuAiOQvjmS1M2wPM0DuWQRkXs+cnsy2RQCCcGuITAvN4blG6Xfe3Q==
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s2048; d=yahoo.com; b=oFqHkHYgMPiyIG8FhOnn1502+qK/3lbW7KebFPuzvI/73ccLMYYBF3dSTVH2x4Y//MiskKdJ+uzXyeud0Grv/bjRvkTGjpR9Awft7Rvc6vTn2ljjR5Sbmlqgf51X31Rdv06wjj0jbQGF9C1HvIqFfHKyQjIQ3fD9/zSPK75+2F+q0+zxA2YfyRWyr/Gn4+ZZ56CyYGHhUvDDx4uQyK9rhFfsYMEQZeou+Nwpb2DWja9sZaMo/Ra8RdYR66MywyqdgCBs0zeZelfwneDHsZi/G+OQJEChwXY9VLNq1W7JH/U8ETBRgQhNK/8g0dI2rMok+IwiZPnLzE2fWTuydcF/tw==;
Received: from [66.196.81.170] by nm11.bullet.mail.bf1.yahoo.com with NNFMP; 07 Jan 2015 18:12:01 -0000
Received: from [98.139.212.198] by tm16.bullet.mail.bf1.yahoo.com with NNFMP;  07 Jan 2015 18:12:01 -0000
Received: from [127.0.0.1] by omp1007.mail.bf1.yahoo.com with NNFMP; 07 Jan 2015 18:12:01 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 430951.97250.bm@omp1007.mail.bf1.yahoo.com
X-YMail-OSG: 0XezCAQVM1lOl0.aexgNq1heaUIaCxRd727yPdNgKxeru_855yZ3sqevrgddRL7 p5m2u65CD8qfXyqXeAGMlzy0tVmhG.ge2MuvDeP1ONOp_P4i0rrvq6GXtcLPZA17auW8fwVv3jkE EFT9X2_3.kzvHubasaXL6F5oFeukMQ4xVGD.0Rab2onvGgpDtQbIowQcZnuQoSMYIV7JtB0SDi_v A86fL00L7yyvPvYXunR0HYaLHOk8B8ZwCpcjx5JI3M9OzR_bVHPhlDotLY0d0tyUIbmhB65pHvCl EuYzjrZTla4LbBvVRnDJZNqUUO6ZHMHZ4VU3hoORAdVr9xrWL3dnKFmawoldskQWme.kiFPVXvmH OdkYbmyWrlrdCMMLlRDXYHO3L2gttU9NJ4y3XNmOVMcw7GCFysyWeXzQknMZjdm94Ra5cq5CfE8b 7zaeGpIswzlLhPV9mWmOtA870l9xXyx.OdtW8uKVAabG.oMM3YCXGj8vWyno4C6OaQL6qG5Is_az bQJXS_PgEUR_._9ysQY0_KFcUk9gEHIGG
Received: by 76.13.26.107; Wed, 07 Jan 2015 18:12:01 +0000 
Date: Wed, 7 Jan 2015 18:12:00 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Benjamin Kaduk <kaduk@MIT.EDU>
Message-ID: <788717600.945785.1420654320660.JavaMail.yahoo@jws10603.mail.bf1.yahoo.com>
In-Reply-To: <alpine.GSO.1.10.1501071251500.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1501071251500.23489@multics.mit.edu>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_945784_1004062929.1420654320654"
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/Vm4a_pi7r8MUfcd9ZhnyBZGVBaY
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Jan 2015 18:14:55 -0000

------=_Part_945784_1004062929.1420654320654
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Added=C2=A0
"The client response consisting of only a single kvsep is used only when au=
thentication fails, and is only valid in that context. If sent as the first=
 message from the client the server MAY simply fail the authentication with=
out returning discovery information since there is no user or server name i=
ndication."
=20

     On Wednesday, January 7, 2015 9:57 AM, Benjamin Kaduk <kaduk@MIT.EDU> =
wrote:
  =20

 Bill, Alexey,

Thanks for working through these comments (I'm still catching up after the
holidays) -- I do agree with Alexey that having the examples right is very
important.

Looking through this thread, I don't see a response to one of Alexey's
comments, though:

% client_resp=C2=A0 =C2=A0 =3D (gs2-header kvsep 0*kvpair kvsep) / kvsep
%
% Did you mean that the whole client response can be just a single separato=
r
% character? I think this is not compatible with GS2 framing. If you only m=
eant to
% allow that for failed authentication, I suggest you add a comment and poi=
nt to
% section 3.2.3.

If I correctly remember how things work, I think that Alexey is right that
this is only allowed for failed authentication, so a comment is needed
here.

-Ben



   
------=_Part_945784_1004062929.1420654320654
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div><span></span></div><div class=3D"" style=3D""><span clas=
s=3D"" style=3D"white-space:pre">Added&nbsp;</span></div><div class=3D"" st=
yle=3D""><span class=3D"" style=3D"white-space:pre"><br></span></div><div c=
lass=3D"" style=3D""><span class=3D"" style=3D"white-space:pre">"The client=
 response consisting of only a single kvsep is used only when authenticatio=
n fails,=20
=09and is only valid in that context.  If sent as the first message from th=
e client the server MAY
=09simply fail the authentication without returning discovery information s=
ince there is no user or
=09server name indication."</span></div><div class=3D"" style=3D"" id=3D"yu=
i_3_16_0_1_1420590006095_123661"><br></div> <div class=3D"qtdSeparateBR"><b=
r><br></div><div class=3D"yahoo_quoted" style=3D"display: block;"> <div sty=
le=3D"font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida =
Grande, sans-serif; font-size: 12px;"> <div style=3D"font-family: Helvetica=
Neue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-siz=
e: 16px;"> <div dir=3D"ltr"> <font size=3D"2" face=3D"Arial"> On Wednesday,=
 January 7, 2015 9:57 AM, Benjamin Kaduk &lt;kaduk@MIT.EDU&gt; wrote:<br> <=
/font> </div>  <br><br> <div class=3D"y_msg_container">Bill, Alexey,<br cle=
ar=3D"none"><br clear=3D"none">Thanks for working through these comments (I=
'm still catching up after the<br clear=3D"none">holidays) -- I do agree wi=
th Alexey that having the examples right is very<br clear=3D"none">importan=
t.<br clear=3D"none"><br clear=3D"none">Looking through this thread, I don'=
t see a response to one of Alexey's<br clear=3D"none">comments, though:<br =
clear=3D"none"><br clear=3D"none">% client_resp&nbsp; &nbsp; =3D (gs2-heade=
r kvsep 0*kvpair kvsep) / kvsep<br clear=3D"none">%<br clear=3D"none">% Did=
 you mean that the whole client response can be just a single separator<br =
clear=3D"none">% character? I think this is not compatible with GS2 framing=
. If you only meant to<br clear=3D"none">% allow that for failed authentica=
tion, I suggest you add a comment and point to<br clear=3D"none">% section =
3.2.3.<br clear=3D"none"><br clear=3D"none">If I correctly remember how thi=
ngs work, I think that Alexey is right that<br clear=3D"none">this is only =
allowed for failed authentication, so a comment is needed<div class=3D"yqt0=
017837180" id=3D"yqtfd80093"><br clear=3D"none">here.</div><br clear=3D"non=
e"><br clear=3D"none">-Ben<div class=3D"yqt0017837180" id=3D"yqtfd79180"><b=
r clear=3D"none"><br clear=3D"none"></div><br><br></div>  </div> </div>  </=
div> </div></body></html>
------=_Part_945784_1004062929.1420654320654--


From nobody Wed Jan  7 12:41:46 2015
Return-Path: <barryleiba@gmail.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BCB131A1AB4; Wed,  7 Jan 2015 12:41:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.277
X-Spam-Level: 
X-Spam-Status: No, score=-1.277 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id c-4HK4sdlcX3; Wed,  7 Jan 2015 12:41:40 -0800 (PST)
Received: from mail-lb0-x231.google.com (mail-lb0-x231.google.com [IPv6:2a00:1450:4010:c04::231]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CF9281A00FA; Wed,  7 Jan 2015 12:41:39 -0800 (PST)
Received: by mail-lb0-f177.google.com with SMTP id b6so1698878lbj.22; Wed, 07 Jan 2015 12:41:38 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:sender:in-reply-to:references:date:message-id:subject :from:to:cc:content-type; bh=n4XmkmdF0XWdv2ny4VzlRgbCCKZsuiY30ZW/Ky7R9Fs=; b=V1XeIBj+B1JhcEgqKCh25tAqi3wcEimkYOWF1Tus/Ao8uvH6KO/WfydrIEJt2lJUgl G7sp1iMSnuB9RTIcsAw8eyFBL7D9apGfq/vzj/SjBW596e67/APrXt/Tm+/5M8fPKHHv hgn0POUrEnNnBAfWRDIcGR7T5MaEval+gYIKi6bcuANofVFW3UlCu67m8PWPu2o2kfMY Jl6eKUEO8r9zqY+Iw0z2cnftVObfDJlqVIXww0FhS0ziNctiUePsPT32yromdOXe19J7 6DmLogO+eEd/sIerh6TJ0N/J1ClSnQLnu86d5YGBLhWTDbUEz3WXA/KEtc98vNI/GQ+V r93A==
MIME-Version: 1.0
X-Received: by 10.152.22.67 with SMTP id b3mr8219107laf.82.1420663298057; Wed, 07 Jan 2015 12:41:38 -0800 (PST)
Sender: barryleiba@gmail.com
Received: by 10.152.127.168 with HTTP; Wed, 7 Jan 2015 12:41:37 -0800 (PST)
In-Reply-To: <alpine.GSO.1.10.1501071214260.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1501071214260.23489@multics.mit.edu>
Date: Thu, 8 Jan 2015 04:41:37 +0800
X-Google-Sender-Auth: NzbfD78KulJrlkEFYT16HRk0pus
Message-ID: <CALaySJ+aRTBQjDF=izMZtS1DaJnB3=Yr5cqUPe2HzOpnd985Vw@mail.gmail.com>
From: Barry Leiba <barryleiba@computer.org>
To: Benjamin Kaduk <kaduk@mit.edu>
Content-Type: multipart/alternative; boundary=089e0158b86e39ecad050c15f366
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/YdmVUScf6ZFEtAYc90poJjPhZWY
Cc: "kitten@ietf.org" <kitten@ietf.org>, "iesg@ietf.org" <iesg@ietf.org>
Subject: Re: [kitten] pending edits for draft-ietf-kitten-cammac
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Jan 2015 20:41:41 -0000

--089e0158b86e39ecad050c15f366
Content-Type: text/plain; charset=ISO-8859-1

Thanks for that, Ben: I think the change to Section 6 is helpful.

Barry

On Thursday, January 8, 2015, Benjamin Kaduk <kaduk@mit.edu> wrote:

> Hi all,
>
> The authors have staged some (basically editorial) changes in response to
> the Gen-ART and OPS-DIR reviews, as well as Barry's suggested changes, but
> plan to defer submitting a new revision until after tomorrow's IESG call.
>
> The new full text is at [0], and a diff to the -00 which is on the ballot
> is at [1].
>
> -Ben
>
> [0] http://web.mit.edu/tlyu/cammac/draft-ietf-kitten-cammac-01.txt
>
> [1]
> https://tools.ietf.org/rfcdiff?url2=http://web.mit.edu/tlyu/cammac/draft-ietf-kitten-cammac-01.txt&url1=draft-ietf-kitten-cammac-00
>
>

--089e0158b86e39ecad050c15f366
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Thanks for that, Ben: I think the change to Section 6 is helpful.<div><br><=
/div><div>Barry<br><br>On Thursday, January 8, 2015, Benjamin Kaduk &lt;<a =
href=3D"mailto:kaduk@mit.edu">kaduk@mit.edu</a>&gt; wrote:<br><blockquote c=
lass=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;=
padding-left:1ex">Hi all,<br>
<br>
The authors have staged some (basically editorial) changes in response to<b=
r>
the Gen-ART and OPS-DIR reviews, as well as Barry&#39;s suggested changes, =
but<br>
plan to defer submitting a new revision until after tomorrow&#39;s IESG cal=
l.<br>
<br>
The new full text is at [0], and a diff to the -00 which is on the ballot<b=
r>
is at [1].<br>
<br>
-Ben<br>
<br>
[0] <a href=3D"http://web.mit.edu/tlyu/cammac/draft-ietf-kitten-cammac-01.t=
xt" target=3D"_blank">http://web.mit.edu/tlyu/cammac/draft-ietf-kitten-camm=
ac-01.txt</a><br>
<br>
[1] <a href=3D"https://tools.ietf.org/rfcdiff?url2=3Dhttp://web.mit.edu/tly=
u/cammac/draft-ietf-kitten-cammac-01.txt&amp;url1=3Ddraft-ietf-kitten-camma=
c-00" target=3D"_blank">https://tools.ietf.org/rfcdiff?url2=3Dhttp://web.mi=
t.edu/tlyu/cammac/draft-ietf-kitten-cammac-01.txt&amp;url1=3Ddraft-ietf-kit=
ten-cammac-00</a><br>
<br>
</blockquote></div>

--089e0158b86e39ecad050c15f366--


From nobody Wed Jan  7 13:12:14 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EEE9A1A1BA4 for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 13:12:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RBA5A_a3-UKv for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 13:12:10 -0800 (PST)
Received: from dmz-mailsec-scanner-5.mit.edu (dmz-mailsec-scanner-5.mit.edu [18.7.68.34]) by ietfa.amsl.com (Postfix) with ESMTP id E6BF61A1B9C for <kitten@ietf.org>; Wed,  7 Jan 2015 13:12:07 -0800 (PST)
X-AuditID: 12074422-f79476d000000d9e-0f-54ada1267d4c
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-5.mit.edu (Symantec Messaging Gateway) with SMTP id D7.CD.03486.621ADA45; Wed,  7 Jan 2015 16:12:06 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id t07LC5xQ021212; Wed, 7 Jan 2015 16:12:06 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t07LC3uN013587 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 7 Jan 2015 16:12:05 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t07LC3D3011901; Wed, 7 Jan 2015 16:12:03 -0500 (EST)
Date: Wed, 7 Jan 2015 16:12:03 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: "Cantor, Scott" <cantor.2@osu.edu>
In-Reply-To: <8C695AC1-CC85-46AC-8D0A-9494514D03B7@osu.edu>
Message-ID: <alpine.GSO.1.10.1501071423250.23489@multics.mit.edu>
References: <20141229171240.971.24324.idtracker@ietfa.amsl.com> <8C695AC1-CC85-46AC-8D0A-9494514D03B7@osu.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrDIsWRmVeSWpSXmKPExsUixG6nrqu2cG2IwaHlWhYtR8Qtjm5exeLA 5LFkyU8mj+ary9kDmKK4bFJSczLLUov07RK4Mj7c/MBS8I2rYvu5JcwNjDc5uhg5OSQETCR2 LT3DAmGLSVy4t56ti5GLQ0hgMZPEzUcrWSGcDYwSr6+vhnIOMkmcaj0F1iIkUC9x5Mk+RhCb RUBLouHKEXYQm01ARWLmm41sILaIgJrE6gVvmUFsZgF1iW9n3oDVCwu4S3Q/PAI2h1PAWuLD qy2sIDavgKPEse7fjBDz8yT2LN0OFhcV0JFYvX8KC0SNoMTJmU9YIGZqSSyfvo1lAqPgLCSp WUhSCxiZVjHKpuRW6eYmZuYUpybrFicn5uWlFuma6uVmluilppRuYgQHqovSDsafB5UOMQpw MCrx8Bb0rQkRYk0sK67MPcQoycGkJMp7bNbaECG+pPyUyozE4oz4otKc1OJDjBIczEoivGvb gHK8KYmVValF+TApaQ4WJXHeTT/4QoQE0hNLUrNTUwtSi2CyMhwcShK8F+YDNQoWpaanVqRl 5pQgpJk4OEGG8wANXwBSw1tckJhbnJkOkT/FqCglDtEsAJLIKM2D64UlkleM4kCvCPMeBani ASYhuO5XQIOZgAZnLV8NMrgkESEl1cDIPruhoPqX2A6t8vKwLhU5lde792o/5s5SuVjMLttS YdBzq4VBLPRHxmrPlB8Tnh7Jb96peqerwkZ91zTuAL4nMXviq2xK9qX2vZztktuy+NPdU1mq RQtNRBkenOrpWP55s2uPSE36xyPXXT5c9r1xXOyNpucijdRJy4VWRQby1lQ3703JWK7EUpyR aKjFXFScCAD7HQ40/wIAAA==
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/Z6Vx-Us_p0UB28DklZ3VotUp1x0
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-sasl-saml-ec-12.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Jan 2015 21:12:12 -0000

On Mon, 29 Dec 2014, Cantor, Scott wrote:

> Apologies for the 9 month delay, but I've finally produced a new draft in
> response to comments from Sam and others back in March (thread name
> comments on draft-ietf-kitten-sasl-saml-ec, started by Sam).
>
> Most importantly, this corrects a normative error by changing the
> dependency on the 4161 enctype names into numbers.
>
> I attempted to address all of the comments in one form or another, but
> it's been long enough that this needs a fresh review anyway.

Thanks for the updates.

Looking at the diff, I get the sense that for the service names, you want
people to use the text that would be input to gss_import_name() -- the
actual gss_name_t should not be involved in processing at all.  It might
be helpful to call that out.  (It also means that applications will not
need to know about the GSS_C_NT_HOSTBASED_SERVICE symbol, though you
probably still want to include that string in the discussion in the text.)



Skimming through the document itself, "without relying on flawed
commercial TLS infrastructure" may be true, but may also engender some
objections.  I make no recommendation for or against the text at this
time.

Nothing really jumps out at me from that, so it seems ready for a more
in-depth review as far as I can tell.  I'm not sure how soon I'll have
time for that, of course...

-Ben


From nobody Wed Jan  7 13:27:12 2015
Return-Path: <cantor.2@osu.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2EFCC1A3BA6 for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 13:27:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mS3EWPOqR0WE for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 13:27:08 -0800 (PST)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1on0767.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc10::767]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 67CFF1A6F04 for <kitten@ietf.org>; Wed,  7 Jan 2015 13:26:57 -0800 (PST)
Received: from BN1BFFO11FD018.protection.gbl (10.58.144.33) by BN1BFFO11HUB007.protection.gbl (10.58.144.154) with Microsoft SMTP Server (TLS) id 15.1.49.13; Wed, 7 Jan 2015 21:26:33 +0000
Received: from cio-tnc-pf08.osuad.osu.edu (164.107.81.222) by BN1BFFO11FD018.mail.protection.outlook.com (10.58.144.81) with Microsoft SMTP Server (TLS) id 15.1.49.13 via Frontend Transport; Wed, 7 Jan 2015 21:26:33 +0000
Received: from CIO-KRC-HT01.osuad.osu.edu (cio-krc-ht01.osuad.osu.edu [164.107.81.37]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by cio-tnc-pf08.osuad.osu.edu (Postfix) with ESMTPS id BAF4E2E0079; Wed,  7 Jan 2015 16:26:32 -0500 (EST)
Received: from CIO-TNC-D2MBX02.osuad.osu.edu ([fe80::3960:dd86:ba2:ad26]) by CIO-KRC-HT01.osuad.osu.edu ([fe80::6d8f:7dea:5691:1620%12]) with mapi id 14.03.0174.001; Wed, 7 Jan 2015 16:26:31 -0500
From: "Cantor, Scott" <cantor.2@osu.edu>
To: Benjamin Kaduk <kaduk@MIT.EDU>
Thread-Topic: [kitten] I-D Action: draft-ietf-kitten-sasl-saml-ec-12.txt
Thread-Index: AQHQI4qwAwQZaeL2pUuLaUQBlv7iU5ym0i6AgA63uID//7A4AA==
Date: Wed, 7 Jan 2015 21:26:31 +0000
Message-ID: <9156E125-CF0E-44BE-A7BC-F7506444E5F0@osu.edu>
References: <20141229171240.971.24324.idtracker@ietfa.amsl.com> <8C695AC1-CC85-46AC-8D0A-9494514D03B7@osu.edu> <alpine.GSO.1.10.1501071423250.23489@multics.mit.edu>
In-Reply-To: <alpine.GSO.1.10.1501071423250.23489@multics.mit.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [128.146.94.10]
Content-Type: text/plain; charset="utf-8"
Content-ID: <D3F4CA7338986A49AC071F58DE74AC84@osu.edu>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-EOPAttributedMessage: 0
Received-SPF: Pass (protection.outlook.com: domain of osu.edu designates 164.107.81.222 as permitted sender) receiver=protection.outlook.com; client-ip=164.107.81.222; helo=cio-tnc-pf08.osuad.osu.edu;
Authentication-Results: spf=pass (sender IP is 164.107.81.222) smtp.mailfrom=cantor.2@osu.edu; 
X-Forefront-Antispam-Report: CIP:164.107.81.222; CTRY:US; IPV:NLI; EFV:NLI; SFV:NSPM; SFS:(10019020)(979002)(6009001)(438002)(479174004)(51704005)(377454003)(199003)(24454002)(189002)(19580405001)(19580395003)(66066001)(82746002)(6806004)(106466001)(109096001)(107046002)(50986999)(86362001)(76176999)(54356999)(92566001)(36756003)(120916001)(31966008)(88552001)(4396001)(87936001)(2900100001)(50466002)(2171001)(20776003)(64706001)(83716003)(47776003)(2656002)(21056001)(62966003)(99396003)(102836002)(23676002)(77156002)(89122001)(106116001)(230783001)(90282001)(93346002)(75432002)(46102003)(33656002)(2950100001)(104396002)(969003)(989001)(999001)(1009001)(1019001); DIR:OUT; SFP:1102; SCL:1; SRVR:BN1BFFO11HUB007; H:cio-tnc-pf08.osuad.osu.edu;  FPR:; SPF:Pass; MLV:ovrnspm; PTR:cio-tnc-pf08.osuad.osu.edu; A:1; MX:1; LANG:en; 
X-Microsoft-Antispam: UriScan:;
X-Microsoft-Antispam: BCL:0;PCL:0;RULEID:;SRVR:BN1BFFO11HUB007;
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(601004); SRVR:BN1BFFO11HUB007; 
X-Forefront-PRVS: 044968D9E1
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:; SRVR:BN1BFFO11HUB007; 
X-OriginatorOrg: osu.edu
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 07 Jan 2015 21:26:33.3847 (UTC)
X-MS-Exchange-CrossTenant-Id: b4d138ca-1815-4a9b-a3a7-130a33b1e692
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=b4d138ca-1815-4a9b-a3a7-130a33b1e692; Ip=[164.107.81.222]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN1BFFO11HUB007
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/QCQ4LyNcPc7Eb8LgVn3M-h9gjCk
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-sasl-saml-ec-12.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Jan 2015 21:27:11 -0000

T24gMS83LzE1LCA5OjEyIFBNLCAiQmVuamFtaW4gS2FkdWsiIDxrYWR1a0BNSVQuRURVPiB3cm90
ZToNCg0KDQo+DQo+TG9va2luZyBhdCB0aGUgZGlmZiwgSSBnZXQgdGhlIHNlbnNlIHRoYXQgZm9y
IHRoZSBzZXJ2aWNlIG5hbWVzLCB5b3Ugd2FudA0KPnBlb3BsZSB0byB1c2UgdGhlIHRleHQgdGhh
dCB3b3VsZCBiZSBpbnB1dCB0byBnc3NfaW1wb3J0X25hbWUoKSAtLSB0aGUNCj5hY3R1YWwgZ3Nz
X25hbWVfdCBzaG91bGQgbm90IGJlIGludm9sdmVkIGluIHByb2Nlc3NpbmcgYXQgYWxsLiAgSXQg
bWlnaHQNCj5iZSBoZWxwZnVsIHRvIGNhbGwgdGhhdCBvdXQuICAoSXQgYWxzbyBtZWFucyB0aGF0
IGFwcGxpY2F0aW9ucyB3aWxsIG5vdA0KPm5lZWQgdG8ga25vdyBhYm91dCB0aGUgR1NTX0NfTlRf
SE9TVEJBU0VEX1NFUlZJQ0Ugc3ltYm9sLCB0aG91Z2ggeW91DQo+cHJvYmFibHkgc3RpbGwgd2Fu
dCB0byBpbmNsdWRlIHRoYXQgc3RyaW5nIGluIHRoZSBkaXNjdXNzaW9uIGluIHRoZSB0ZXh0LikN
Cg0KVGhhdCBzb3VuZHMgY29ycmVjdCB0byBtZS4gSSdtIGdvaW5nIGZvciB0aGUgbWluaW11bSBv
ZiBwb3NzaWJsZSBpbXBlZGFuY2UgDQptaXNtYXRjaGVzLg0KDQo+Tm90aGluZyByZWFsbHkganVt
cHMgb3V0IGF0IG1lIGZyb20gdGhhdCwgc28gaXQgc2VlbXMgcmVhZHkgZm9yIGEgbW9yZQ0KPmlu
LWRlcHRoIHJldmlldyBhcyBmYXIgYXMgSSBjYW4gdGVsbC4gIEknbSBub3Qgc3VyZSBob3cgc29v
biBJJ2xsIGhhdmUNCj50aW1lIGZvciB0aGF0LCBvZiBjb3Vyc2UuLi4NCg0KVGhhbmsgeW91LiBJ
J2xsIGZpbGUgdGhpcyBwcm9wb3NlZCBjaGFuZ2UgZm9yIG5vdyBhbmQgaW5jbHVkZSBpdCB3aGVu
IEkgZG8gDQphbm90aGVyIHJvdW5kIG9mIGNoYW5nZXMuDQoNCi0tIFNjb3R0DQoNCg==


From nobody Wed Jan  7 17:59:24 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E2DE71A1A7D for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 17:59:22 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4ZhLpunaeNBe for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 17:59:21 -0800 (PST)
Received: from dmz-mailsec-scanner-4.mit.edu (dmz-mailsec-scanner-4.mit.edu [18.9.25.15]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BBA481A036F for <kitten@ietf.org>; Wed,  7 Jan 2015 17:59:20 -0800 (PST)
X-AuditID: 1209190f-f79716d000000d1a-29-54ade477a69a
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-4.mit.edu (Symantec Messaging Gateway) with SMTP id E0.43.03354.774EDA45; Wed,  7 Jan 2015 20:59:19 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id t081xITg021357; Wed, 7 Jan 2015 20:59:19 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t081xGnl019682 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 7 Jan 2015 20:59:18 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t081xGvR018115; Wed, 7 Jan 2015 20:59:16 -0500 (EST)
Date: Wed, 7 Jan 2015 20:59:16 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Bill Mills <wmills_92105@yahoo.com>
In-Reply-To: <788717600.945785.1420654320660.JavaMail.yahoo@jws10603.mail.bf1.yahoo.com>
Message-ID: <alpine.GSO.1.10.1501072058410.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1501071251500.23489@multics.mit.edu> <788717600.945785.1420654320660.JavaMail.yahoo@jws10603.mail.bf1.yahoo.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: MULTIPART/MIXED; BOUNDARY="-559023410-1160042819-1420682356=:23489"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFupileLIzCtJLcpLzFFi42IRYrdT1y1/sjbEoHGassWM1UUWRzevYrH4 1nWd2YHZY8mSn0wep5oNPWbNOswUwBzFZZOSmpNZllqkb5fAlXFryiu2giV8FTfXX2FvYFzB 3cXIySEhYCLxvfs1I4QtJnHh3nq2LkYuDiGBxUwSfyduZYVwNjBKLNrewQjhHGSS2Ph/M1iL kEC9xNvf99lAbBYBLYklm3axgthsAioSM99sBIpzcIgIqEs0f/cGMZkFYiWWHEoCqRAWCJX4 8nE3WAWnQIRE0yRlEJNXwFHi/mt1iEW9jBL93y+ygJSLCuhIrN4/BczmFRCUODnzCZjNLBAo sej0dMYJjIKzkKRmIUlB2OoSBz5dhLK1Je7fbGNbwMiyilE2JbdKNzcxM6c4NVm3ODkxLy+1 SNdELzezRC81pXQTIyjIOSX5dzB+O6h0iFGAg1GJh/fD/bUhQqyJZcWVuYcYJTmYlER5N4CE +JLyUyozEosz4otKc1KLDzFKcDArifB2nQXK8aYkVlalFuXDpKQ5WJTEeTf94AsREkhPLEnN Tk0tSC2CycpwcChJ8IY+BmoULEpNT61Iy8wpQUgzcXCCDOcBGn7hEcjw4oLE3OLMdIj8KUZF KXHeCSDNAiCJjNI8uF5YEnrFKA70ijDvM5AqHmACg+t+BTSYCWhw1vLVIINLEhFSUg2MrAcU Xu31inVWfKdmc/D53aupMjIrD39YsoP34XlZz03vrvG1Zh8syi74vXBra6Pqmz/z/750chAp KWTxSlZqj7++7uHWgnpdn+Nucr8fPFRb0FzQfOPcv3UO66JZODsz/rCKfNAurjx3/1rWPbvj xnuurqw7VZe8YEen2fzFC11j14aeLFyipsRSnJFoqMVcVJwIAPo/or8dAwAA
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/gxnv4ZzOZpmHmmy6mZTFZLSVo6I
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Jan 2015 01:59:23 -0000

  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

---559023410-1160042819-1420682356=:23489
Content-Type: TEXT/PLAIN; charset=UTF-8
Content-Transfer-Encoding: QUOTED-PRINTABLE

Seems reasonable here; let's see what it looks like in the next revision.
(Do you keep your working copy somewhere public?  I have forgotten.)

Thanks,

Ben

On Wed, 7 Jan 2015, Bill Mills wrote:

> Added=C2=A0
> "The client response consisting of only a single kvsep is used only when =
authentication fails, and is only valid in that context. If sent as the fir=
st message from the client the server MAY simply fail the authentication wi=
thout returning discovery information since there is no user or server name=
 indication."
>
>
>      On Wednesday, January 7, 2015 9:57 AM, Benjamin Kaduk <kaduk@MIT.EDU=
> wrote:
>
>
>  Bill, Alexey,
>
> Thanks for working through these comments (I'm still catching up after th=
e
> holidays) -- I do agree with Alexey that having the examples right is ver=
y
> important.
>
> Looking through this thread, I don't see a response to one of Alexey's
> comments, though:
>
> % client_resp=C2=A0 =C2=A0 =3D (gs2-header kvsep 0*kvpair kvsep) / kvsep
> %
> % Did you mean that the whole client response can be just a single separa=
tor
> % character? I think this is not compatible with GS2 framing. If you only=
 meant to
> % allow that for failed authentication, I suggest you add a comment and p=
oint to
> % section 3.2.3.
>
> If I correctly remember how things work, I think that Alexey is right tha=
t
> this is only allowed for failed authentication, so a comment is needed
> here.
>
> -Ben
>
>
>
>
>
---559023410-1160042819-1420682356=:23489--


From nobody Wed Jan  7 22:40:48 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CEC601A8864 for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 22:40:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qxFvmYRvUi3I for <kitten@ietfa.amsl.com>; Wed,  7 Jan 2015 22:40:45 -0800 (PST)
Received: from nm24-vm0.bullet.mail.bf1.yahoo.com (nm24-vm0.bullet.mail.bf1.yahoo.com [98.139.213.161]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3A55B1A885A for <kitten@ietf.org>; Wed,  7 Jan 2015 22:40:42 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1420699242; bh=J/CmclJXfj8lg5ej+QPqXdeyWNZDOWz4ke4Q6nPWmbA=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=RErzvUsu1Z4CpT765LUYqX3zcCd1CVCD/x2OB8kD4u73lxpWYMpjcuk8MMo1DXfBAStCaYUtNceQrOG6ZWWRo17RDjXns/G+pfBZMOOmYMy75x7Y6WXM/+5lPQI90E6U2WrR2m+W4+fqWPcR2HzQwJFvqxMiEM8KZysA8OKVy0gbTBiv8MhJ4VpAfnK0/KZeqhgJe2UkehkRY49CVC13QCk4hod2Q+LwOt5tZG5H1d6m4sASzxQPIVOcQ5WTzN+V67MaFMN+IXMwi3C8tlUIniZM5tSz4tz5T63SbRbfrXyMF8JwhucDCzCCXJ/Fd6UCnI5oTCM7XIU7vukZxlPTCw==
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s2048; d=yahoo.com; b=jHxKyNs/6jvnDq+eZwEbVq+olIEE2I++dvFYak0ulYgeQJboaYC28iNsUmiUMPs7MQwTtFIuza26W07BarAJWhApXuj1g44J+pbH4zd/15Q7+LtMasskzQPZOzLOfi8H4ow51udXdKrGt47pd2jnxw8m3HI5Z42YV2909NiQVhbB9HAuv9nhQGSg5Xub0OTb38nWzM+tUx6JBlG+AnUXdmvZL402LzGpIeU+XPP6g/W4hDTQKoA6bDOkPH+/jIiIQrcO8Pv6SiUNLpn5qWwGaNAda19PrX0JjmfLkpTWobtZTpmhCCsIDHJLGZmZEWEKk3suNF4+C3v5B9h9cuvzGA==;
Received: from [66.196.81.170] by nm24.bullet.mail.bf1.yahoo.com with NNFMP; 08 Jan 2015 06:40:42 -0000
Received: from [98.139.215.253] by tm16.bullet.mail.bf1.yahoo.com with NNFMP;  08 Jan 2015 06:40:42 -0000
Received: from [127.0.0.1] by omp1066.mail.bf1.yahoo.com with NNFMP; 08 Jan 2015 06:40:42 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 321878.43189.bm@omp1066.mail.bf1.yahoo.com
X-YMail-OSG: oND1vVwVM1lV7lHjhAZi52t4ToJ0pTcnKSTDWWTCSP0iS5miwg_UaR1iuGTd_rQ djo1ZyuwuKH.jSwmaDL8N9Yq7Mvspzw6mYYlYWRWEg.Gvn7R8.KYi5jw4h6uavgl.xSA2vSLPgdY dhH5Z0HvPJkaN_iEr5.HgirxfP_5yO_n_hD3lqlZYEt0KsA4Xx6fvR60EuL7r5.s57RprkiLZfnU YzJqQ5a0olhCMEpsN8O3KIc2eQkqfaal61u9cjyU1bJqVnjVia6CGcbhJG279mcr3IMuQh7AB6PV 8e3isFiiwSd3dT43TSYupuHGp8rOSGS2bVCcXkEaabu8ARpG3uuJCtwU1IVxKOfc.ZJrHhr3EM6F rssjDuu8EnXoni0MrmmIXs2PW_RWz2mrb26BgGKtOYiBvUkD04_2lhQIJgre6qfV_mnLBgcw5FLT 7ZDiAa1dRn59VsXU0B.uAQ3D9RjOTnjqEWER0iabxQ7ODKdJznWvJMHsdtJWQO0NAQIgboJruEJr HCYJ71xBcjIUigChUpul.9RvY0x5l_ijDJSTgXkcHR8jRq0ptnf42zmUGQKZncPr.UhTryvS.g_2 k91lxYxE4zPG7VtXvr1VZuh1B.hvE0qA3t17ZHtgQ3vIeozmM61lUFyUK72Us23YMnDJQiSE1vXK wHvht2LwZwkA0L4gEr7LtjlKdnnlIwfFU7UREeFuXa4sMiGc_ZcPsbmGgXQMvZrlChgsefrf6M3Z TxBqAEQ7bTOMNJdB8UHsdT972UxB7_Zlp9XR6TBw.oB66Sz61q1NGHY6wQ6qlBA_stcQMiG9NfXV dr65r2Yn3Ta_pXn6k0ozH0XY1vN.8uk.7C.K8yqgpbwwKwBIYgf40Ng--
Received: by 76.13.26.159; Thu, 08 Jan 2015 06:40:41 +0000 
Date: Thu, 8 Jan 2015 06:40:41 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Benjamin Kaduk <kaduk@MIT.EDU>
Message-ID: <1360746483.6267464.1420699241445.JavaMail.yahoo@jws10696.mail.bf1.yahoo.com>
In-Reply-To: <alpine.GSO.1.10.1501072058410.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1501072058410.23489@multics.mit.edu>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_6267463_1473810422.1420699241442"
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/puGG3AKLMlQuEJRp4qa9ffypk8U
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Jan 2015 06:40:47 -0000

------=_Part_6267463_1473810422.1420699241442
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

I didn't before.
http://htmlpreview.github.io/?https://github.com/sweetums/idrafts/blob/mast=
er/draft-ietf-kitten-sasl-oauth-19.html
=20

     On Wednesday, January 7, 2015 5:59 PM, Benjamin Kaduk <kaduk@MIT.EDU> =
wrote:
  =20

 Seems reasonable here; let's see what it looks like in the next revision.
(Do you keep your working copy somewhere public?=C2=A0 I have forgotten.)

Thanks,

Ben

On Wed, 7 Jan 2015, Bill Mills wrote:

> Added=C2=A0
> "The client response consisting of only a single kvsep is used only when =
authentication fails, and is only valid in that context. If sent as the fir=
st message from the client the server MAY simply fail the authentication wi=
thout returning discovery information since there is no user or server name=
 indication."
>
>
>=C2=A0 =C2=A0 =C2=A0 On Wednesday, January 7, 2015 9:57 AM, Benjamin Kaduk=
 <kaduk@MIT.EDU> wrote:
>
>
>=C2=A0 Bill, Alexey,
>
> Thanks for working through these comments (I'm still catching up after th=
e
> holidays) -- I do agree with Alexey that having the examples right is ver=
y
> important.
>
> Looking through this thread, I don't see a response to one of Alexey's
> comments, though:
>
> % client_resp=C2=A0 =C2=A0 =3D (gs2-header kvsep 0*kvpair kvsep) / kvsep
> %
> % Did you mean that the whole client response can be just a single separa=
tor
> % character? I think this is not compatible with GS2 framing. If you only=
 meant to
> % allow that for failed authentication, I suggest you add a comment and p=
oint to
> % section 3.2.3.
>
> If I correctly remember how things work, I think that Alexey is right tha=
t
> this is only allowed for failed authentication, so a comment is needed
> here.
>
> -Ben
>
>
>
>
>

   
------=_Part_6267463_1473810422.1420699241442
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div dir=3D"ltr"><span>I didn't before.</span></div><div dir=
=3D"ltr"><span><br></span></div><div dir=3D"ltr" id=3D"yui_3_16_0_1_1420590=
006095_228139"><span id=3D"yui_3_16_0_1_1420590006095_228138"><a href=3D"ht=
tp://htmlpreview.github.io/?https://github.com/sweetums/idrafts/blob/master=
/draft-ietf-kitten-sasl-oauth-19.html" id=3D"yui_3_16_0_1_1420590006095_228=
137">http://htmlpreview.github.io/?https://github.com/sweetums/idrafts/blob=
/master/draft-ietf-kitten-sasl-oauth-19.html</a><br></span></div> <div clas=
s=3D"qtdSeparateBR"><br><br></div><div class=3D"yahoo_quoted" style=3D"disp=
lay: block;"> <div style=3D"font-family: HelveticaNeue, Helvetica Neue, Hel=
vetica, Arial, Lucida Grande, sans-serif; font-size: 12px;"> <div style=3D"=
font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande=
, sans-serif; font-size: 16px;"> <div dir=3D"ltr"> <font size=3D"2" face=3D=
"Arial"> On Wednesday, January 7, 2015 5:59 PM, Benjamin Kaduk &lt;kaduk@MI=
T.EDU&gt; wrote:<br> </font> </div>  <br><br> <div class=3D"y_msg_container=
">Seems reasonable here; let's see what it looks like in the next revision.=
<br clear=3D"none">(Do you keep your working copy somewhere public?&nbsp; I=
 have forgotten.)<br clear=3D"none"><br clear=3D"none">Thanks,<br clear=3D"=
none"><br clear=3D"none">Ben<br clear=3D"none"><div class=3D"yqt8933880216"=
 id=3D"yqtfd91356"><br clear=3D"none">On Wed, 7 Jan 2015, Bill Mills wrote:=
<br clear=3D"none"><br clear=3D"none">&gt; Added&nbsp;<br clear=3D"none">&g=
t; "The client response consisting of only a single kvsep is used only when=
 authentication fails, and is only valid in that context. If sent as the fi=
rst message from the client the server MAY simply fail the authentication w=
ithout returning discovery information since there is no user or server nam=
e indication."<br clear=3D"none">&gt;<br clear=3D"none">&gt;<br clear=3D"no=
ne">&gt;&nbsp; &nbsp; &nbsp; On Wednesday, January 7, 2015 9:57 AM, Benjami=
n Kaduk &lt;<a shape=3D"rect" ymailto=3D"mailto:kaduk@MIT.EDU" href=3D"mail=
to:kaduk@MIT.EDU">kaduk@MIT.EDU</a>&gt; wrote:<br clear=3D"none">&gt;<br cl=
ear=3D"none">&gt;<br clear=3D"none">&gt;&nbsp; Bill, Alexey,<br clear=3D"no=
ne">&gt;<br clear=3D"none">&gt; Thanks for working through these comments (=
I'm still catching up after the<br clear=3D"none">&gt; holidays) -- I do ag=
ree with Alexey that having the examples right is very<br clear=3D"none">&g=
t; important.<br clear=3D"none">&gt;<br clear=3D"none">&gt; Looking through=
 this thread, I don't see a response to one of Alexey's<br clear=3D"none">&=
gt; comments, though:<br clear=3D"none">&gt;<br clear=3D"none">&gt; % clien=
t_resp&nbsp; &nbsp; =3D (gs2-header kvsep 0*kvpair kvsep) / kvsep<br clear=
=3D"none">&gt; %<br clear=3D"none">&gt; % Did you mean that the whole clien=
t response can be just a single separator<br clear=3D"none">&gt; % characte=
r? I think this is not compatible with GS2 framing. If you only meant to<br=
 clear=3D"none">&gt; % allow that for failed authentication, I suggest you =
add a comment and point to<br clear=3D"none">&gt; % section 3.2.3.<br clear=
=3D"none">&gt;<br clear=3D"none">&gt; If I correctly remember how things wo=
rk, I think that Alexey is right that<br clear=3D"none">&gt; this is only a=
llowed for failed authentication, so a comment is needed<br clear=3D"none">=
&gt; here.<br clear=3D"none">&gt;<br clear=3D"none">&gt; -Ben<br clear=3D"n=
one">&gt;<br clear=3D"none">&gt;<br clear=3D"none">&gt;<br clear=3D"none">&=
gt;<br clear=3D"none">&gt;</div><br><br></div>  </div> </div>  </div> </div=
></body></html>
------=_Part_6267463_1473810422.1420699241442--


From nobody Thu Jan  8 01:49:54 2015
Return-Path: <alexey.melnikov@isode.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9CC681ACCFE for <kitten@ietfa.amsl.com>; Thu,  8 Jan 2015 01:49:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.008
X-Spam-Level: 
X-Spam-Status: No, score=-2.008 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Mv77cBhegYN1 for <kitten@ietfa.amsl.com>; Thu,  8 Jan 2015 01:49:51 -0800 (PST)
Received: from waldorf.isode.com (ext-bt.isode.com [217.34.220.158]) by ietfa.amsl.com (Postfix) with ESMTP id B40C91ACCF5 for <kitten@ietf.org>; Thu,  8 Jan 2015 01:49:50 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1420710589; d=isode.com; s=selector; i=@isode.com; bh=bv1Z30duj6FD9qr22uwYPHthKPk92UqCLdM7luCn0tk=; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version: In-Reply-To:References:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description; b=InGx9vK5AlP8eh3oVbzhGVRIk6j9aqdspMqNyYS4ow+MsZf1bIkVJlC2rt9oGnAx9nF0Iu SI0GyYGpWBZCd8Peb5lcsDhs1vptcWIoXoyn3kIfawOatMfGyR/2VNFjQlMpd9vGIStDyP Cm4aoGWnQnsVBKgd7xrn3a905CYrNZg=;
Received: from [10.37.106.100] ((unknown) [94.116.143.33])  by waldorf.isode.com (submission channel) via TCP with ESMTPSA  id <VK5SvQAKaFEo@waldorf.isode.com>; Thu, 8 Jan 2015 09:49:49 +0000
X-SMTP-Protocol-Errors: PIPELINING
From: Alexey Melnikov <alexey.melnikov@isode.com>
X-Mailer: iPad Mail (12B435)
In-Reply-To: <256029732.199845.1420580195408.JavaMail.yahoo@jws106115.mail.bf1.yahoo.com>
Date: Thu, 8 Jan 2015 09:54:36 +0000
Message-Id: <6CF6884C-C9A7-440D-BC8A-7B6A7F0EECBB@isode.com>
References: <F4209A2F-CEB5-498B-9DA9-1C4628C64BE4@isode.com> <256029732.199845.1420580195408.JavaMail.yahoo@jws106115.mail.bf1.yahoo.com>
To: Bill Mills <wmills_92105@yahoo.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary=Apple-Mail-494086A4-CE50-405D-A73F-2603FF99A967
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/kRKE5kZObYdgI4sPYRhPqZh63wY
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Cancel message Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Jan 2015 09:49:52 -0000

--Apple-Mail-494086A4-CE50-405D-A73F-2603FF99A967
Content-Type: text/plain;
	charset=us-ascii
Content-Transfer-Encoding: quoted-printable

Hi Bill,

> On 6 Jan 2015, at 21:36, Bill Mills <wmills_92105@yahoo.com> wrote:
>=20
> " The client MUST then send either an additional client response consistin=
g of a single %x01 (control A) character to the server in order to allow the=
 server to finish the exchange or send a SASL cancellation token as defined i=
n ACAP[RFC2244] section 6.3.1."

Actually I meant RFC 4422 (SASL). ACAP has cancellation token, but so does I=
MAP, SMTP, LDAP,...

If you like, I send you an IMAP example.
>=20
>=20
> On Sunday, January 4, 2015 3:37 AM, Alexey Melnikov <alexey.melnikov@isode=
.com> wrote:
>=20
>=20
> Hi Bill,
>=20
> > On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:
> >=20
> > 3.2.3 and an explicit message:  Long ago in the life of this doc I was t=
old that some implementations may not support an empty message, so we put th=
e single character message there to have an explicit payload.  I'm a bit lee=
ry of changing this now since there are implementations in play that use it t=
his way.
>=20
>=20
> I didn't suggest you should be sending empty message. I said you should be=
 using SASL cancellation token, which is a mandatory RFC 4422 feature.
>=20
> Any implementation would have to support this mode of operation anyway, be=
cause a SASL client can cancel any exchange.
>=20
>=20
>=20
>=20

--Apple-Mail-494086A4-CE50-405D-A73F-2603FF99A967
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><div>Hi Bill,<br></div><div><br>On 6 Jan 20=
15, at 21:36, Bill Mills &lt;<a href=3D"mailto:wmills_92105@yahoo.com">wmill=
s_92105@yahoo.com</a>&gt; wrote:<br><br></div><blockquote type=3D"cite"><div=
><div style=3D"color:#000; background-color:#fff; font-family:HelveticaNeue,=
 Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:12px"=
><div id=3D"yui_3_16_0_1_1420579175477_6993"><span>"</span>&nbsp;<span style=
=3D"font-family: verdana, helvetica, arial, sans-serif; font-size: 13px;" cl=
ass=3D"">The client MUST then send either an additional client response cons=
isting of a single %x01 (control A) character to the server in order to allo=
w the server to finish the exchange or send a SASL cancellation token as def=
ined in ACAP</span><a href=3D"https://us-mg0.mail.yahoo.com/neo/launch?.rand=
=3D1lc7cfbnjsq0p#RFC2244" style=3D"font-family: verdana, helvetica, arial, s=
ans-serif; font-size: 13px; text-decoration: none; background-color: rgb(255=
, 255, 255);" class=3D"">[RFC2244]</a><span style=3D"font-family: verdana, h=
elvetica, arial, sans-serif; font-size: 13px;" class=3D"">&nbsp;</span><span=
 style=3D"font-family: verdana, helvetica, arial, sans-serif; font-size: 13p=
x;" class=3D"">section 6.3.1."</span></div></div></div></blockquote><div><br=
></div>Actually I meant RFC 4422 (SASL). ACAP has cancellation token, but so=
 does IMAP, SMTP, LDAP,...<div><br></div><div>If you like, I send you an IMA=
P example.<br><blockquote type=3D"cite"><div><div style=3D"color:#000; backg=
round-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Aria=
l, Lucida Grande, sans-serif;font-size:12px"> <div class=3D"qtdSeparateBR"><=
br><br></div><div class=3D"yahoo_quoted" style=3D"display: block;"> <div sty=
le=3D"font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida G=
rande, sans-serif; font-size: 12px;"> <div style=3D"font-family: HelveticaNe=
ue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 1=
6px;"> <div dir=3D"ltr"> <font size=3D"2" face=3D"Arial"> On Sunday, January=
 4, 2015 3:37 AM, Alexey Melnikov &lt;<a href=3D"mailto:alexey.melnikov@isod=
e.com">alexey.melnikov@isode.com</a>&gt; wrote:<br> </font> </div>  <br><br>=
 <div class=3D"y_msg_container">Hi Bill,<br clear=3D"none"><div class=3D"yqt=
7536736220" id=3D"yqtfd36038"><br clear=3D"none">&gt; On 3 Jan 2015, at 00:5=
6, Bill Mills &lt;<a shape=3D"rect" ymailto=3D"mailto:wmills_92105@yahoo.com=
" href=3D"mailto:wmills_92105@yahoo.com">wmills_92105@yahoo.com</a>&gt; wrot=
e:<br clear=3D"none">&gt; <br clear=3D"none">&gt; 3.2.3 and an explicit mess=
age:&nbsp; Long ago in the life of this doc I was told that some implementat=
ions may not support an empty message, so we put the single character messag=
e there to have an explicit payload.&nbsp; I'm a bit leery of changing this n=
ow since there are implementations in play that use it this way.</div><br cl=
ear=3D"none"><br clear=3D"none">I didn't suggest you should be sending empty=
 message. I said you should be using SASL cancellation token, which is a man=
datory RFC 4422 feature.<br clear=3D"none"><br clear=3D"none">Any implementa=
tion would have to support this mode of operation anyway, because a SASL cli=
ent can cancel any exchange.<div class=3D"yqt7536736220" id=3D"yqtfd53837"><=
br clear=3D"none"><br clear=3D"none"></div><br><br></div>  </div> </div>  </=
div> </div></div></blockquote></div></body></html>=

--Apple-Mail-494086A4-CE50-405D-A73F-2603FF99A967--


From nobody Thu Jan  8 08:05:50 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E7A201A8702 for <kitten@ietfa.amsl.com>; Thu,  8 Jan 2015 08:05:44 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MvpSrDoGISIr for <kitten@ietfa.amsl.com>; Thu,  8 Jan 2015 08:05:43 -0800 (PST)
Received: from nm7.bullet.mail.bf1.yahoo.com (nm7.bullet.mail.bf1.yahoo.com [98.139.212.166]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4B2751A8546 for <kitten@ietf.org>; Thu,  8 Jan 2015 08:05:41 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1420733140; bh=fDIclCs/YHJjamE2gOLU1RkTjhXif9HqcQhRC8v1qcU=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=loyZHQxhjC1vboCETlolp3UWK5EItlwCyr3NUvNo8XY3Vy/PRxy/KdL8yeohw9kGFgms9jVuuL/8wH86iUlLJjV2MvyWTAgFFqYdYeDoDQ6Qj6lWXmQOlqCiVsDwxLWXREKQoTlWtjE6hsXlQgzGZFfjXww4IDOV1VJALlFTx6MMiJx81BcesRGD2msk0qrrvXKM4FZDLzHw8XRgC1Toya9EYxeEm9Aym3i2OT3+LGNkQ52+FsD7azShUZEXH0WoVlk7a6rAAeQO+7liAzUSto09Naj7+1t5uT4xc7GNLz3H9KwyBSEhwl+2/ltJpGs7+mHV8SQ+uCUV6vN55UjP5A==
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s2048; d=yahoo.com; b=sqB1rX6pc66O6llByrHBUgrdY7vadO/1S+RU019kvWlxSmjljw7treIer3LpUA1hqSGlbQnLsWppTzozpIn/91XZYZHvbeEuy6aXwy+4mlBWdlEdVLv/ZbismCMAVfZ3LZSuu5AvpnWiqV8zVoActndOo82iL35rWWrXnjKlzCrUz/6GclBUCr0ww7QF5YPz0G0l/aH3W8dxZF9PifECxGYYjeoZF4YbFyNu83J13j2b9XtA9LvDaiO045YMs8tVttXlxUfY0d/42ThJArQ+hJEf+GrR7SLpmjNZu2EHDpCejSIQ+awz8NBAAntfsz0+6KFp0wvpTZmBxVNhzRiBIw==;
Received: from [98.139.215.141] by nm7.bullet.mail.bf1.yahoo.com with NNFMP; 08 Jan 2015 16:05:40 -0000
Received: from [98.139.212.215] by tm12.bullet.mail.bf1.yahoo.com with NNFMP;  08 Jan 2015 16:05:40 -0000
Received: from [127.0.0.1] by omp1024.mail.bf1.yahoo.com with NNFMP; 08 Jan 2015 16:05:40 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 451472.34517.bm@omp1024.mail.bf1.yahoo.com
X-YMail-OSG: PPzuEIsVM1n4cr9vvqt8_YygVMSoa2U1KA6e3pwSMYkJhBsV7rpurpXFH8YkZZe EuG5WmISZwYJz26Fjre.Gj7p.rSymNflRwOf86YJeR2y9VI_n6mVpA2oahNNLM5IzW7G8kxJH37P _0ylxqcmZEVRdaArFbB9z8qjDvgcrO2EdCRkRXul8PKcD7i75GPM20rwlyG3gW65O.pw8ymRIPQU ybs8aSLiEwY5A75jcEHHaEKTA7UMH3yur9b1jF9GCXXN3VLvWdZLn3XbuTFjKpertwYcX0SxfySe Xnw3Ub8.XfMw640loEEEk_K39PdgtfFvObeJx8ZDBnQY4ompzVXZtZF5a6Z4QAJyhGzKnvtPz3iQ y6xFjnpVLMCnkgNcPMZBvW8mcSC6QPhgBPQMr5PG.dj7LiWzzRtw8UlBlmbhQVPZBxQKcj088xeS OpC.tCXSYG3.fBe9NNe2z5UI3oOH56gMkCRRa6JdAhbG8ttyY.50eYK95wUbrLPhEkRC9mKHCxpD HzdlTVErf1cVsNJHP35ZR9x.0ViSA7ONLZZ9Se_qlPCOiSH0LkrdS59iWE_IUiOGWwBJcYToMBUS vbeoMyPKTjakWaieeT52_MQ4CpkFtoIiQVieFtKFlubhIw0bmT_oPXdUYR.FAePetQbi8CA--
Received: by 66.196.80.115; Thu, 08 Jan 2015 16:05:40 +0000 
Date: Thu, 8 Jan 2015 16:05:38 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Alexey Melnikov <alexey.melnikov@isode.com>
Message-ID: <333970036.3242875.1420733138671.JavaMail.yahoo@jws10602g.mail.bf1.yahoo.com>
In-Reply-To: <6CF6884C-C9A7-440D-BC8A-7B6A7F0EECBB@isode.com>
References: <6CF6884C-C9A7-440D-BC8A-7B6A7F0EECBB@isode.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_3242874_795511151.1420733138667"
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/ZYGAHu9dcSYMC8oMSntCLk42g9o>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Cancel message Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Jan 2015 16:05:45 -0000

------=_Part_3242874_795511151.1420733138667
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

You're talking about 3.5 in 4422? =C2=A0To me it looks like the single kvse=
p message looks exactly like the abort message that needs to be defined by =
the protocol?=20

     On Thursday, January 8, 2015 1:49 AM, Alexey Melnikov <alexey.melnikov=
@isode.com> wrote:
  =20

 Hi Bill,

On 6 Jan 2015, at 21:36, Bill Mills <wmills_92105@yahoo.com> wrote:


"=C2=A0The client MUST then send either an additional client response consi=
sting of a single %x01 (control A) character to the server in order to allo=
w the server to finish the exchange or send a SASL cancellation token as de=
fined in ACAP[RFC2244]=C2=A0section 6.3.1."

Actually I meant RFC 4422 (SASL). ACAP has cancellation token, but so does =
IMAP, SMTP, LDAP,...
If you like, I send you an IMAP example.

=20

     On Sunday, January 4, 2015 3:37 AM, Alexey Melnikov <alexey.melnikov@i=
sode.com> wrote:
  =20

 Hi Bill,

> On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:
>=20
> 3.2.3 and an explicit message:=C2=A0 Long ago in the life of this doc I w=
as told that some implementations may not support an empty message, so we p=
ut the single character message there to have an explicit payload.=C2=A0 I'=
m a bit leery of changing this now since there are implementations in play =
that use it this way.

I didn't suggest you should be sending empty message. I said you should be =
using SASL cancellation token, which is a mandatory RFC 4422 feature.

Any implementation would have to support this mode of operation anyway, bec=
ause a SASL client can cancel any exchange.



   =20


   
------=_Part_3242874_795511151.1420733138667
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div dir=3D"ltr"><span>You're talking about 3.5 in 4422? &nbs=
p;To me it looks like the single kvsep message looks exactly like the abort=
 message that needs to be defined by the protocol?</span></div> <div class=
=3D"qtdSeparateBR"><br><br></div><div class=3D"yahoo_quoted" style=3D"displ=
ay: block;"> <div style=3D"font-family: HelveticaNeue, Helvetica Neue, Helv=
etica, Arial, Lucida Grande, sans-serif; font-size: 12px;"> <div style=3D"f=
ont-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande,=
 sans-serif; font-size: 16px;"> <div dir=3D"ltr"> <font size=3D"2" face=3D"=
Arial"> On Thursday, January 8, 2015 1:49 AM, Alexey Melnikov &lt;alexey.me=
lnikov@isode.com&gt; wrote:<br> </font> </div>  <br><br> <div class=3D"y_ms=
g_container"><div id=3D"yiv2467469197"><div><div>Hi Bill,<br clear=3D"none"=
></div><div><br clear=3D"none">On 6 Jan 2015, at 21:36, Bill Mills &lt;<a r=
el=3D"nofollow" shape=3D"rect" ymailto=3D"mailto:wmills_92105@yahoo.com" ta=
rget=3D"_blank" href=3D"mailto:wmills_92105@yahoo.com">wmills_92105@yahoo.c=
om</a>&gt; wrote:<br clear=3D"none"><br clear=3D"none"></div><blockquote ty=
pe=3D"cite"><div><div style=3D"color:#000;background-color:#fff;font-family=
:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif=
;font-size:12px;"><div id=3D"yiv2467469197yui_3_16_0_1_1420579175477_6993">=
<span>"</span>&nbsp;<span class=3D"yiv2467469197" style=3D"font-family:verd=
ana, helvetica, arial, sans-serif;font-size:13px;">The client MUST then sen=
d either an additional client response consisting of a single %x01 (control=
 A) character to the server in order to allow the server to finish the exch=
ange or send a SASL cancellation token as defined in ACAP</span><a rel=3D"n=
ofollow" shape=3D"rect" class=3D"yiv2467469197" target=3D"_blank" href=3D"h=
ttps://us-mg0.mail.yahoo.com/neo/launch?.rand=3D1lc7cfbnjsq0p#RFC2244" styl=
e=3D"font-family:verdana, helvetica, arial, sans-serif;font-size:13px;text-=
decoration:none;background-color:rgb(255, 255, 255);">[RFC2244]</a><span cl=
ass=3D"yiv2467469197" style=3D"font-family:verdana, helvetica, arial, sans-=
serif;font-size:13px;">&nbsp;</span><span class=3D"yiv2467469197" style=3D"=
font-family:verdana, helvetica, arial, sans-serif;font-size:13px;">section =
6.3.1."</span></div></div></div></blockquote><div><br clear=3D"none"></div>=
Actually I meant RFC 4422 (SASL). ACAP has cancellation token, but so does =
IMAP, SMTP, LDAP,...<div><br clear=3D"none"></div><div>If you like, I send =
you an IMAP example.<div class=3D"yiv2467469197yqt0978937274" id=3D"yiv2467=
469197yqtfd43836"><br clear=3D"none"><blockquote type=3D"cite"><div><div st=
yle=3D"color:#000;background-color:#fff;font-family:HelveticaNeue, Helvetic=
a Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:12px;"> <div =
class=3D"yiv2467469197qtdSeparateBR"><br clear=3D"none"><br clear=3D"none">=
</div><div class=3D"yiv2467469197yahoo_quoted" style=3D"display: block;"> <=
div style=3D"font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, L=
ucida Grande, sans-serif;font-size:12px;"> <div style=3D"font-family:Helvet=
icaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-s=
ize:16px;"> <div dir=3D"ltr"> <font size=3D"2" face=3D"Arial"> On Sunday, J=
anuary 4, 2015 3:37 AM, Alexey Melnikov &lt;<a rel=3D"nofollow" shape=3D"re=
ct" ymailto=3D"mailto:alexey.melnikov@isode.com" target=3D"_blank" href=3D"=
mailto:alexey.melnikov@isode.com">alexey.melnikov@isode.com</a>&gt; wrote:<=
br clear=3D"none"> </font> </div>  <br clear=3D"none"><br clear=3D"none"> <=
div class=3D"yiv2467469197y_msg_container">Hi Bill,<br clear=3D"none"><div =
class=3D"yiv2467469197yqt7536736220" id=3D"yiv2467469197yqtfd36038"><br cle=
ar=3D"none">&gt; On 3 Jan 2015, at 00:56, Bill Mills &lt;<a rel=3D"nofollow=
" shape=3D"rect" ymailto=3D"mailto:wmills_92105@yahoo.com" target=3D"_blank=
" href=3D"mailto:wmills_92105@yahoo.com">wmills_92105@yahoo.com</a>&gt; wro=
te:<br clear=3D"none">&gt; <br clear=3D"none">&gt; 3.2.3 and an explicit me=
ssage:&nbsp; Long ago in the life of this doc I was told that some implemen=
tations may not support an empty message, so we put the single character me=
ssage there to have an explicit payload.&nbsp; I'm a bit leery of changing =
this now since there are implementations in play that use it this way.</div=
><br clear=3D"none"><br clear=3D"none">I didn't suggest you should be sendi=
ng empty message. I said you should be using SASL cancellation token, which=
 is a mandatory RFC 4422 feature.<br clear=3D"none"><br clear=3D"none">Any =
implementation would have to support this mode of operation anyway, because=
 a SASL client can cancel any exchange.<div class=3D"yiv2467469197yqt753673=
6220" id=3D"yiv2467469197yqtfd53837"><br clear=3D"none"><br clear=3D"none">=
</div><br clear=3D"none"><br clear=3D"none"></div>  </div> </div>  </div> <=
/div></div></blockquote></div></div></div></div><br><br></div>  </div> </di=
v>  </div> </div></body></html>
------=_Part_3242874_795511151.1420733138667--


From nobody Thu Jan  8 10:01:33 2015
Return-Path: <ietf-secretariat-reply@ietf.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E84501A8F40 for <kitten@ietfa.amsl.com>; Thu,  8 Jan 2015 10:00:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 01X_l2MB793v; Thu,  8 Jan 2015 10:00:24 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 4CBA71A8AF9; Thu,  8 Jan 2015 10:00:24 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
To: kitten@ietf.org, kitten-chairs@tools.ietf.org, draft-ietf-kitten-cammac.all@tools.ietf.org, kaduk@mit.edu
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.0.p6
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150108180024.6689.18286.idtracker@ietfa.amsl.com>
Date: Thu, 08 Jan 2015 10:00:24 -0800
From: IETF Secretariat <ietf-secretariat-reply@ietf.org>
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/NOa6FwG40zyza_1PTZy8SMgic3E>
X-Mailman-Approved-At: Thu, 08 Jan 2015 10:01:28 -0800
Subject: [kitten] ID Tracker State Update Notice: <draft-ietf-kitten-cammac-00.txt>
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Jan 2015 18:00:26 -0000

IESG state changed to Approved-announcement to be sent::Revised I-D Needed from IESG Evaluation
ID Tracker URL: http://datatracker.ietf.org/doc/draft-ietf-kitten-cammac/


From nobody Thu Jan  8 10:08:20 2015
Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D61C71A01F0 for <kitten@ietfa.amsl.com>; Thu,  8 Jan 2015 10:08:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7W89tIW6eL1e for <kitten@ietfa.amsl.com>; Thu,  8 Jan 2015 10:08:15 -0800 (PST)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A75DE1A0163 for <kitten@ietf.org>; Thu,  8 Jan 2015 10:08:15 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id 712AABEB2; Thu,  8 Jan 2015 18:08:13 +0000 (GMT)
X-Virus-Scanned: Debian amavisd-new at scss.tcd.ie
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3LEilE03aTAr; Thu,  8 Jan 2015 18:08:11 +0000 (GMT)
Received: from [10.87.48.73] (unknown [86.46.23.193]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id 5D976BE02; Thu,  8 Jan 2015 18:08:11 +0000 (GMT)
Message-ID: <54AEC78B.8060706@cs.tcd.ie>
Date: Thu, 08 Jan 2015 18:08:11 +0000
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: Benjamin Kaduk <kaduk@MIT.EDU>, "kitten@ietf.org" <kitten@ietf.org>
References: <20150108180024.6689.51763.idtracker@ietfa.amsl.com>
In-Reply-To: <20150108180024.6689.51763.idtracker@ietfa.amsl.com>
X-Forwarded-Message-Id: <20150108180024.6689.51763.idtracker@ietfa.amsl.com>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/oMbSkzz0B7glpJppO7ZFChNQwf4>
Subject: [kitten] Fwd: <draft-ietf-kitten-cammac-00.txt> updated by Cindy Morgan
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Jan 2015 18:08:19 -0000

So this one is approved now as soon as you post the rev and I
check that out and tell 'em to fire ahead.

Thanks,
S.


-------- Forwarded Message --------
Subject: <draft-ietf-kitten-cammac-00.txt> updated by Cindy Morgan
Date: Thu, 08 Jan 2015 10:00:24 -0800
From: DraftTracker Mail System <iesg-secretary@ietf.org>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>


Please DO NOT reply to this email.

I-D: <draft-ietf-kitten-cammac-00.txt>
ID Tracker URL: http://datatracker.ietf.org/doc/draft-ietf-kitten-cammac/

IESG state changed to Approved-announcement to be sent::Revised I-D
Needed from IESG Evaluation




From nobody Thu Jan  8 10:29:07 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 052DD1A0084; Thu,  8 Jan 2015 10:29:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9DaCxqo2fYg9; Thu,  8 Jan 2015 10:29:02 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 761C61A0039; Thu,  8 Jan 2015 10:29:02 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.0.p6
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150108182902.28967.25587.idtracker@ietfa.amsl.com>
Date: Thu, 08 Jan 2015 10:29:02 -0800
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/xpu1eGlq36Ld1P0W4kQSDAUlEQk>
Cc: kitten@ietf.org
Subject: [kitten] I-D Action: draft-ietf-kitten-cammac-01.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Jan 2015 18:29:04 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Common Authentication Technology Next Generation Working Group of the IETF.

        Title           : Kerberos Authorization Data Container Authenticated by Multiple MACs
        Authors         : Simo Sorce
                          Tom Yu
                          Thomas Hardjono
	Filename        : draft-ietf-kitten-cammac-01.txt
	Pages           : 9
	Date            : 2015-01-08

Abstract:
   This document specifies a Kerberos Authorization Data container that
   supersedes AD-KDC-ISSUED.  It allows for multiple Message
   Authentication Codes (MACs) or signatures to authenticate the
   contained Authorization Data elements.  The multiple MACs are needed
   to mitigate shortcomings in the existing AD-KDC-ISSUED container.
   This document updates RFC 4120.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-kitten-cammac/

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-kitten-cammac-01

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=draft-ietf-kitten-cammac-01


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Thu Jan  8 10:29:09 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 68A6F1A0084 for <kitten@ietfa.amsl.com>; Thu,  8 Jan 2015 10:29:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0pM6Ji3CyrsN; Thu,  8 Jan 2015 10:29:04 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id B691F1A0055; Thu,  8 Jan 2015 10:29:02 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: kitten@ietf.org, kitten-chairs@tools.ietf.org, draft-ietf-kitten-cammac.all@tools.ietf.org, kaduk@mit.edu, stephen.farrell@cs.tcd.ie
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.0.p6
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150108182902.28967.5385.idtracker@ietfa.amsl.com>
Date: Thu, 08 Jan 2015 10:29:02 -0800
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/jbOLnm2FcweWTVha_5FJIGeHAbY>
Subject: [kitten] New Version Notification - draft-ietf-kitten-cammac-01.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Jan 2015 18:29:05 -0000

A new version (-01) has been submitted for draft-ietf-kitten-cammac:
http://www.ietf.org/internet-drafts/draft-ietf-kitten-cammac-01.txt

Sub state has been changed to AD Followup from Revised ID Needed


The IETF datatracker page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-kitten-cammac/

Diff from previous version:
http://www.ietf.org/rfcdiff?url2=draft-ietf-kitten-cammac-01

Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

IETF Secretariat.


From nobody Thu Jan  8 10:40:41 2015
Return-Path: <stephen@tolerantnetworks.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6DD591A00A2; Thu,  8 Jan 2015 10:38:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Dupa6TuvZf1h; Thu,  8 Jan 2015 10:38:12 -0800 (PST)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 77CBA1A0089; Thu,  8 Jan 2015 10:38:12 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id E049EBEEC; Thu,  8 Jan 2015 18:38:10 +0000 (GMT)
X-Virus-Scanned: Debian amavisd-new at scss.tcd.ie
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1WUQF6Yfek3W; Thu,  8 Jan 2015 18:38:10 +0000 (GMT)
Received: from [10.87.48.73] (unknown [86.46.23.193]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id CF490BEE9; Thu,  8 Jan 2015 18:38:09 +0000 (GMT)
Message-ID: <54AECE91.70107@tolerantnetworks.com>
Date: Thu, 08 Jan 2015 18:38:09 +0000
From: Stephen Farrell <stephen@tolerantnetworks.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: IESG <iesg@ietf.org>, "draft-ietf-kitten-cammac.all@tools.ietf.org" <draft-ietf-kitten-cammac.all@tools.ietf.org>,  "kitten@ietf.org" <kitten@ietf.org>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/Cb5YenG9c_Ep6IVFhTNZviVFRdk>
X-Mailman-Approved-At: Thu, 08 Jan 2015 10:40:39 -0800
Subject: [kitten] Approved: draft-ietf-kitten-cammac-01
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Jan 2015 18:38:14 -0000

Dear secretariat (bcc'd),

draft-ietf-kitten-cammac-01 is approved - please do tell
the RFC editor,

Thanks,
S.


From nobody Fri Jan  9 04:18:37 2015
Return-Path: <alexey.melnikov@isode.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 874411A8789 for <kitten@ietfa.amsl.com>; Fri,  9 Jan 2015 04:18:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.008
X-Spam-Level: 
X-Spam-Status: No, score=-2.008 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Oc1iauH5FXD6 for <kitten@ietfa.amsl.com>; Fri,  9 Jan 2015 04:18:22 -0800 (PST)
Received: from waldorf.isode.com (ext-bt.isode.com [217.34.220.158]) by ietfa.amsl.com (Postfix) with ESMTP id B7ED81A8786 for <kitten@ietf.org>; Fri,  9 Jan 2015 04:18:21 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1420805901; d=isode.com; s=selector; i=@isode.com; bh=HOM5N8Y8+CqGb39gtIEv6eMEVe84ZCUiLItMWUwf71o=; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version: In-Reply-To:References:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description; b=QoAI32HoxppKh6sRoEizkbGGA5gStvU3KoOJGNyNoVsDCNhAmWh4WXnj0lOHm+112I4inO oIebMJzQUdGuK4A3G9VoqVoOBziEngGJOWadeU5d3tvYKvhrqflZpSVwFe105qpBuXbgXO 7ZKebr7nfAnYDi5rFXiXWeh3rY8/DYQ=;
Received: from [10.37.109.107] ((unknown) [94.117.105.137])  by waldorf.isode.com (submission channel) via TCP with ESMTPSA  id <VK=HCwAKaIdr@waldorf.isode.com>; Fri, 9 Jan 2015 12:18:20 +0000
X-SMTP-Protocol-Errors: NORDNS PIPELINING
From: Alexey Melnikov <alexey.melnikov@isode.com>
X-Mailer: iPad Mail (12B435)
In-Reply-To: <333970036.3242875.1420733138671.JavaMail.yahoo@jws10602g.mail.bf1.yahoo.com>
Date: Fri, 9 Jan 2015 12:23:14 +0000
Message-Id: <98CD0AB3-E3B3-42D1-AB3F-3E581FCAD571@isode.com>
References: <6CF6884C-C9A7-440D-BC8A-7B6A7F0EECBB@isode.com> <333970036.3242875.1420733138671.JavaMail.yahoo@jws10602g.mail.bf1.yahoo.com>
To: Bill Mills <wmills_92105@yahoo.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary=Apple-Mail-E807AE0C-953F-4FD2-AEA0-3CDC89ABD6A8
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/mxMnerG234n0ZFNwIGTQTn53dSw>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Cancel message Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Jan 2015 12:18:28 -0000

--Apple-Mail-E807AE0C-953F-4FD2-AEA0-3CDC89ABD6A8
Content-Type: text/plain;
	charset=us-ascii
Content-Transfer-Encoding: quoted-printable

Hi Bill,

> On 8 Jan 2015, at 16:05, Bill Mills <wmills_92105@yahoo.com> wrote:
>=20
> You're talking about 3.5 in 4422?

Yes.

> To me it looks like the single kvsep message looks exactly like the abort m=
essage that needs to be defined by the protocol?

No, it is a SASL protocol mapping construct (defined once for all mechanisms=
), you defined a SASL mechanism construct.
>=20
>=20
> On Thursday, January 8, 2015 1:49 AM, Alexey Melnikov <alexey.melnikov@iso=
de.com> wrote:
>=20
>=20
> Hi Bill,
>=20
>> On 6 Jan 2015, at 21:36, Bill Mills <wmills_92105@yahoo.com> wrote:
>>=20
>> " The client MUST then send either an additional client response consisti=
ng of a single %x01 (control A) character to the server in order to allow th=
e server to finish the exchange or send a SASL cancellation token as defined=
 in ACAP[RFC2244] section 6.3.1."
>=20
> Actually I meant RFC 4422 (SASL). ACAP has cancellation token, but so does=
 IMAP, SMTP, LDAP,...
>=20
> If you like, I send you an IMAP example.
>=20
>>=20
>>=20
>> On Sunday, January 4, 2015 3:37 AM, Alexey Melnikov <alexey.melnikov@isod=
e.com> wrote:
>>=20
>>=20
>> Hi Bill,
>>=20
>> > On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:
>> >=20
>> > 3.2.3 and an explicit message:  Long ago in the life of this doc I was t=
old that some implementations may not support an empty message, so we put th=
e single character message there to have an explicit payload.  I'm a bit lee=
ry of changing this now since there are implementations in play that use it t=
his way.
>>=20
>>=20
>> I didn't suggest you should be sending empty message. I said you should b=
e using SASL cancellation token, which is a mandatory RFC 4422 feature.
>>=20
>> Any implementation would have to support this mode of operation anyway, b=
ecause a SASL client can cancel any exchange.
>=20
>=20

--Apple-Mail-E807AE0C-953F-4FD2-AEA0-3CDC89ABD6A8
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><div>Hi Bill,</div><div><br>On 8 Jan 2015, a=
t 16:05, Bill Mills &lt;<a href=3D"mailto:wmills_92105@yahoo.com">wmills_921=
05@yahoo.com</a>&gt; wrote:<br><br></div><blockquote type=3D"cite"><div><div=
 style=3D"color:#000; background-color:#fff; font-family:HelveticaNeue, Helv=
etica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:12px"><div=
 dir=3D"ltr"><span>You're talking about 3.5 in 4422?</span></div></div></div=
></blockquote><br>Yes.<div><br><blockquote type=3D"cite"><div><div style=3D"=
color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue=
, Helvetica, Arial, Lucida Grande, sans-serif;font-size:12px"><div dir=3D"lt=
r"><span> To me it looks like the single kvsep message looks exactly like th=
e abort message that needs to be defined by the protocol?</span></div></div>=
</div></blockquote><div><br></div>No, it is a SASL protocol mapping construc=
t (defined once for all mechanisms), you defined a SASL mechanism construct.=
<br><blockquote type=3D"cite"><div><div style=3D"color:#000; background-colo=
r:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida G=
rande, sans-serif;font-size:12px"> <div class=3D"qtdSeparateBR"><br><br></di=
v><div class=3D"yahoo_quoted" style=3D"display: block;"> <div style=3D"font-=
family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans=
-serif; font-size: 12px;"> <div style=3D"font-family: HelveticaNeue, Helveti=
ca Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <di=
v dir=3D"ltr"> <font size=3D"2" face=3D"Arial"> On Thursday, January 8, 2015=
 1:49 AM, Alexey Melnikov &lt;<a href=3D"mailto:alexey.melnikov@isode.com">a=
lexey.melnikov@isode.com</a>&gt; wrote:<br> </font> </div>  <br><br> <div cl=
ass=3D"y_msg_container"><div id=3D"yiv2467469197"><div><div>Hi Bill,<br clea=
r=3D"none"></div><div><br clear=3D"none">On 6 Jan 2015, at 21:36, Bill Mills=
 &lt;<a rel=3D"nofollow" shape=3D"rect" ymailto=3D"mailto:wmills_92105@yahoo=
.com" target=3D"_blank" href=3D"mailto:wmills_92105@yahoo.com">wmills_92105@=
yahoo.com</a>&gt; wrote:<br clear=3D"none"><br clear=3D"none"></div><blockqu=
ote type=3D"cite"><div><div style=3D"color:#000;background-color:#fff;font-f=
amily:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-s=
erif;font-size:12px;"><div id=3D"yiv2467469197yui_3_16_0_1_1420579175477_699=
3"><span>"</span>&nbsp;<span class=3D"yiv2467469197" style=3D"font-family:ve=
rdana, helvetica, arial, sans-serif;font-size:13px;">The client MUST then se=
nd either an additional client response consisting of a single %x01 (control=
 A) character to the server in order to allow the server to finish the excha=
nge or send a SASL cancellation token as defined in ACAP</span><a rel=3D"nof=
ollow" shape=3D"rect" class=3D"yiv2467469197" target=3D"_blank" href=3D"http=
s://us-mg0.mail.yahoo.com/neo/launch?.rand=3D1lc7cfbnjsq0p#RFC2244" style=3D=
"font-family:verdana, helvetica, arial, sans-serif;font-size:13px;text-decor=
ation:none;background-color:rgb(255, 255, 255);">[RFC2244]</a><span class=3D=
"yiv2467469197" style=3D"font-family:verdana, helvetica, arial, sans-serif;f=
ont-size:13px;">&nbsp;</span><span class=3D"yiv2467469197" style=3D"font-fam=
ily:verdana, helvetica, arial, sans-serif;font-size:13px;">section 6.3.1."</=
span></div></div></div></blockquote><div><br clear=3D"none"></div>Actually I=
 meant RFC 4422 (SASL). ACAP has cancellation token, but so does IMAP, SMTP,=
 LDAP,...<div><br clear=3D"none"></div><div>If you like, I send you an IMAP e=
xample.<div class=3D"yiv2467469197yqt0978937274" id=3D"yiv2467469197yqtfd438=
36"><br clear=3D"none"><blockquote type=3D"cite"><div><div style=3D"color:#0=
00;background-color:#fff;font-family:HelveticaNeue, Helvetica Neue, Helvetic=
a, Arial, Lucida Grande, sans-serif;font-size:12px;"> <div class=3D"yiv24674=
69197qtdSeparateBR"><br clear=3D"none"><br clear=3D"none"></div><div class=3D=
"yiv2467469197yahoo_quoted" style=3D"display: block;"> <div style=3D"font-fa=
mily:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-se=
rif;font-size:12px;"> <div style=3D"font-family:HelveticaNeue, Helvetica Neu=
e, Helvetica, Arial, Lucida Grande, sans-serif;font-size:16px;"> <div dir=3D=
"ltr"> <font size=3D"2" face=3D"Arial"> On Sunday, January 4, 2015 3:37 AM, A=
lexey Melnikov &lt;<a rel=3D"nofollow" shape=3D"rect" ymailto=3D"mailto:alex=
ey.melnikov@isode.com" target=3D"_blank" href=3D"mailto:alexey.melnikov@isod=
e.com">alexey.melnikov@isode.com</a>&gt; wrote:<br clear=3D"none"> </font> <=
/div>  <br clear=3D"none"><br clear=3D"none"> <div class=3D"yiv2467469197y_m=
sg_container">Hi Bill,<br clear=3D"none"><div class=3D"yiv2467469197yqt75367=
36220" id=3D"yiv2467469197yqtfd36038"><br clear=3D"none">&gt; On 3 Jan 2015,=
 at 00:56, Bill Mills &lt;<a rel=3D"nofollow" shape=3D"rect" ymailto=3D"mail=
to:wmills_92105@yahoo.com" target=3D"_blank" href=3D"mailto:wmills_92105@yah=
oo.com">wmills_92105@yahoo.com</a>&gt; wrote:<br clear=3D"none">&gt; <br cle=
ar=3D"none">&gt; 3.2.3 and an explicit message:&nbsp; Long ago in the life o=
f this doc I was told that some implementations may not support an empty mes=
sage, so we put the single character message there to have an explicit paylo=
ad.&nbsp; I'm a bit leery of changing this now since there are implementatio=
ns in play that use it this way.</div><br clear=3D"none"><br clear=3D"none">=
I didn't suggest you should be sending empty message. I said you should be u=
sing SASL cancellation token, which is a mandatory RFC 4422 feature.<br clea=
r=3D"none"><br clear=3D"none">Any implementation would have to support this m=
ode of operation anyway, because a SASL client can cancel any exchange.<div c=
lass=3D"yiv2467469197yqt7536736220" id=3D"yiv2467469197yqtfd53837"><br clear=
=3D"none"><br clear=3D"none"></div><br clear=3D"none"><br clear=3D"none"></d=
iv>  </div> </div>  </div> </div></div></blockquote></div></div></div></div>=
<br><br></div>  </div> </div>  </div> </div></div></blockquote></div></body>=
</html>=

--Apple-Mail-E807AE0C-953F-4FD2-AEA0-3CDC89ABD6A8--


From nobody Fri Jan  9 15:09:56 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2BA911A1ADD for <kitten@ietfa.amsl.com>; Fri,  9 Jan 2015 15:09:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Rq5TMyvCT5LA for <kitten@ietfa.amsl.com>; Fri,  9 Jan 2015 15:09:45 -0800 (PST)
Received: from nm35-vm0.bullet.mail.bf1.yahoo.com (nm35-vm0.bullet.mail.bf1.yahoo.com [72.30.238.72]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EF91B1A1ABB for <kitten@ietf.org>; Fri,  9 Jan 2015 15:09:30 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1420844970; bh=otW/F1PLvqqhtto5C3VVLTK75+eSzrYE0LZcI6BmkP4=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=lB7dFw/ErHRjn686Nt7L1IqzYGWgpemL0GpZ06uJp/05B6SvItMWGfG2ovS78KSxZbvfCqVmHUP3YnVVP3+pVM18BECqiCR6/7zNr282YI5xWAtYvHlExOFBLfqK117VTwWks3ZzpmMih8iTPIWdl387TO2CoIpgtIOoFY9A40eYZnbyJeze6PPlv1g39vPt9o15pCszWmSTnJC0pZbeGTaDncSTlkdJdpHp/IWgRLdQW5VkXTmhXba/jlNPWqTgvWYody97MXNxk/y796qGibJop/LU7ssA93iPJ1wwPkJdR20CBmctWWx6X6Z/q0zLKUp45VkCSrT8vVFt3utazA==
Received: from [98.139.212.151] by nm35.bullet.mail.bf1.yahoo.com with NNFMP;  09 Jan 2015 23:09:30 -0000
Received: from [98.139.212.202] by tm8.bullet.mail.bf1.yahoo.com with NNFMP; 09 Jan 2015 23:09:30 -0000
Received: from [127.0.0.1] by omp1011.mail.bf1.yahoo.com with NNFMP; 09 Jan 2015 23:09:30 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 29393.74989.bm@omp1011.mail.bf1.yahoo.com
X-YMail-OSG: UGsUCGQVM1m64SGKbQJJXCP289F8PwwXfboE6G.c897CaYG_9FKv.lCb3wWODg7 wlqNTkP2T405hjYSFpzC4NMZfEwc7yYLc.UKNo2y4x3wOaF8CfWo.3q0anm51PvKVz24VCZel0zd IfSHr16WX..eJ8xks1pdZwpiE8_JWEi0E4G9pahGo8pwjUMnXle8bRXVJv0WthZi0sdymLq.nIYU dsnxgclNQQOr7FWJQkuL.WEGeMhUYWyf5pBmM0DaA.AgPRwRy27TG099BLp1uQJkb1RefEuA_uJ5 9X5fShP3iqLoJge6A05FQc08Q39WPULfpfhkuM4tv9qlf9kZ0DCjVfMo_iy2O_E8WU2jXvVu2YQI XYavmiPoBrKG7xi4I9K97OfosyMvS6ySQ8xy0uQEgB.AXm8fBiUVqLb6.0iJ3239jrmT.tvKRxDV kfS88eghcy4DoAIyucbl39mHWzzLTarwKwjhEkrvKgtSZMgDMBNgV7WK6GY2yNudUNBvzzTUpcJ2 HYxdy__357bJVmhWkwpUOUkPczzGIFwVKnIiZhdrjOl5CqDy6CruEIe9Rzxxynx09T_mX6SCSVoh l7z6s_gwbCYi_Tk5QsSX015Q7lmaxOvs1_P_eOyDA8a2aIdg7rqGbkyd6LHm5_Zcq5EZV1l4Qvvc 35UZsOi3L2vzTo_sR6FH6CttH7zPNNd5IkAmRK86S1C7pYoXus6oxD1_3WMdWrirpnPB3XNHMCM. UHjoeTiwgVNVR8LLKSDL967QPMO4Ow7lnnh_BI1I8qryqCuHmWM42mbTRyjT1Aocj2NP0vF1gFop HR5og1lLcnwjhA.e374wq9cviWXvFd38AaEPu4rW4X.a_rYW.fUwkMTV07XzXZHeD0UqQp_FWGYi KdSZM_RZhorcQX90nsGfahoyt10LQA9_BR__0fCcmxlOUjfMXCs7IYqKK1Mg-
Received: by 76.13.27.48; Fri, 09 Jan 2015 23:09:29 +0000 
Date: Fri, 9 Jan 2015 23:09:29 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Alexey Melnikov <alexey.melnikov@isode.com>
Message-ID: <867904166.498701.1420844969279.JavaMail.yahoo@jws10697.mail.bf1.yahoo.com>
In-Reply-To: <98CD0AB3-E3B3-42D1-AB3F-3E581FCAD571@isode.com>
References: <98CD0AB3-E3B3-42D1-AB3F-3E581FCAD571@isode.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_498700_2032503051.1420844969270"
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/fGsm-wcw6rLrKvhk7t98BY1vYJk>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Cancel message Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Jan 2015 23:09:47 -0000

------=_Part_498700_2032503051.1420844969270
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

OK, understanding this better. =C2=A0See the current changes in 3.2.3 and 4=
.3 with an example for IMAP in=C2=A0http://htmlpreview.github.io/?https://g=
ithub.com/sweetums/idrafts/blob/master/draft-ietf-kitten-sasl-oauth-19.html
-bill=20

     On Friday, January 9, 2015 4:19 AM, Alexey Melnikov <alexey.melnikov@i=
sode.com> wrote:
  =20

 Hi Bill,
On 8 Jan 2015, at 16:05, Bill Mills <wmills_92105@yahoo.com> wrote:


You're talking about 3.5 in 4422?

Yes.

 To me it looks like the single kvsep message looks exactly like the abort =
message that needs to be defined by the protocol?

No, it is a SASL protocol mapping construct (defined once for all mechanism=
s), you defined a SASL mechanism construct.

=20

     On Thursday, January 8, 2015 1:49 AM, Alexey Melnikov <alexey.melnikov=
@isode.com> wrote:
  =20

 Hi Bill,

On 6 Jan 2015, at 21:36, Bill Mills <wmills_92105@yahoo.com> wrote:


"=C2=A0The client MUST then send either an additional client response consi=
sting of a single %x01 (control A) character to the server in order to allo=
w the server to finish the exchange or send a SASL cancellation token as de=
fined in ACAP[RFC2244]=C2=A0section 6.3.1."

Actually I meant RFC 4422 (SASL). ACAP has cancellation token, but so does =
IMAP, SMTP, LDAP,...
If you like, I send you an IMAP example.

=20

     On Sunday, January 4, 2015 3:37 AM, Alexey Melnikov <alexey.melnikov@i=
sode.com> wrote:
  =20

 Hi Bill,

> On 3 Jan 2015, at 00:56, Bill Mills <wmills_92105@yahoo.com> wrote:
>=20
> 3.2.3 and an explicit message:=C2=A0 Long ago in the life of this doc I w=
as told that some implementations may not support an empty message, so we p=
ut the single character message there to have an explicit payload.=C2=A0 I'=
m a bit leery of changing this now since there are implementations in play =
that use it this way.

I didn't suggest you should be sending empty message. I said you should be =
using SASL cancellation token, which is a mandatory RFC 4422 feature.

Any implementation would have to support this mode of operation anyway, bec=
ause a SASL client can cancel any exchange.



   =20


   =20


   
------=_Part_498700_2032503051.1420844969270
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div dir=3D"ltr" id=3D"yui_3_16_0_1_1420744844740_278230"><sp=
an id=3D"yui_3_16_0_1_1420744844740_278229">OK, understanding this better. =
&nbsp;See the current changes in 3.2.3 and 4.3 with an example for IMAP in&=
nbsp;</span><a rel=3D"nofollow" shape=3D"rect" id=3D"yiv1922377989yui_3_16_=
0_1_1420590006095_228137" target=3D"_blank" href=3D"http://htmlpreview.gith=
ub.io/?https://github.com/sweetums/idrafts/blob/master/draft-ietf-kitten-sa=
sl-oauth-19.html" style=3D"font-size: 12.222222328186px; color: rgb(25, 106=
, 212); background-color: rgb(255, 255, 255);" class=3D"">http://htmlprevie=
w.github.io/?https://github.com/sweetums/idrafts/blob/master/draft-ietf-kit=
ten-sasl-oauth-19.html</a></div><div dir=3D"ltr" id=3D"yui_3_16_0_1_1420744=
844740_278230"><br></div><div dir=3D"ltr" id=3D"yui_3_16_0_1_1420744844740_=
278230">-bill</div> <div class=3D"qtdSeparateBR"><br><br></div><div class=
=3D"yahoo_quoted" style=3D"display: block;"> <div style=3D"font-family: Hel=
veticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; fo=
nt-size: 12px;"> <div style=3D"font-family: HelveticaNeue, Helvetica Neue, =
Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div dir=3D=
"ltr"> <font size=3D"2" face=3D"Arial"> On Friday, January 9, 2015 4:19 AM,=
 Alexey Melnikov &lt;alexey.melnikov@isode.com&gt; wrote:<br> </font> </div=
>  <br><br> <div class=3D"y_msg_container"><div id=3D"yiv8207435747"><div><=
div>Hi Bill,</div><div><br clear=3D"none">On 8 Jan 2015, at 16:05, Bill Mil=
ls &lt;<a rel=3D"nofollow" shape=3D"rect" ymailto=3D"mailto:wmills_92105@ya=
hoo.com" target=3D"_blank" href=3D"mailto:wmills_92105@yahoo.com">wmills_92=
105@yahoo.com</a>&gt; wrote:<br clear=3D"none"><br clear=3D"none"></div><bl=
ockquote type=3D"cite"><div><div style=3D"color:#000;background-color:#fff;=
font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande,=
 sans-serif;font-size:12px;"><div dir=3D"ltr"><span>You're talking about 3.=
5 in 4422?</span></div></div></div></blockquote><br clear=3D"none">Yes.<div=
><br clear=3D"none"><blockquote type=3D"cite"><div><div style=3D"color:#000=
;background-color:#fff;font-family:HelveticaNeue, Helvetica Neue, Helvetica=
, Arial, Lucida Grande, sans-serif;font-size:12px;"><div dir=3D"ltr"><span>=
 To me it looks like the single kvsep message looks exactly like the abort =
message that needs to be defined by the protocol?</span></div></div></div><=
/blockquote><div><br clear=3D"none"></div>No, it is a SASL protocol mapping=
 construct (defined once for all mechanisms), you defined a SASL mechanism =
construct.<div class=3D"yiv8207435747yqt2631389464" id=3D"yiv8207435747yqtf=
d19055"><br clear=3D"none"><blockquote type=3D"cite"><div><div style=3D"col=
or:#000;background-color:#fff;font-family:HelveticaNeue, Helvetica Neue, He=
lvetica, Arial, Lucida Grande, sans-serif;font-size:12px;"> <div class=3D"y=
iv8207435747qtdSeparateBR"><br clear=3D"none"><br clear=3D"none"></div><div=
 class=3D"yiv8207435747yahoo_quoted" style=3D"display: block;"> <div style=
=3D"font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Gra=
nde, sans-serif;font-size:12px;"> <div style=3D"font-family:HelveticaNeue, =
Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:16px;=
"> <div dir=3D"ltr"> <font size=3D"2" face=3D"Arial"> On Thursday, January =
8, 2015 1:49 AM, Alexey Melnikov &lt;<a rel=3D"nofollow" shape=3D"rect" yma=
ilto=3D"mailto:alexey.melnikov@isode.com" target=3D"_blank" href=3D"mailto:=
alexey.melnikov@isode.com">alexey.melnikov@isode.com</a>&gt; wrote:<br clea=
r=3D"none"> </font> </div>  <br clear=3D"none"><br clear=3D"none"> <div cla=
ss=3D"yiv8207435747y_msg_container"><div id=3D"yiv8207435747"><div><div>Hi =
Bill,<br clear=3D"none"></div><div><br clear=3D"none">On 6 Jan 2015, at 21:=
36, Bill Mills &lt;<a rel=3D"nofollow" shape=3D"rect" ymailto=3D"mailto:wmi=
lls_92105@yahoo.com" target=3D"_blank" href=3D"mailto:wmills_92105@yahoo.co=
m">wmills_92105@yahoo.com</a>&gt; wrote:<br clear=3D"none"><br clear=3D"non=
e"></div><blockquote type=3D"cite"><div><div style=3D"color:#000;background=
-color:#fff;font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lu=
cida Grande, sans-serif;font-size:12px;"><div id=3D"yiv8207435747yui_3_16_0=
_1_1420579175477_6993"><span>"</span>&nbsp;<span class=3D"yiv8207435747" st=
yle=3D"font-family:verdana, helvetica, arial, sans-serif;font-size:13px;">T=
he client MUST then send either an additional client response consisting of=
 a single %x01 (control A) character to the server in order to allow the se=
rver to finish the exchange or send a SASL cancellation token as defined in=
 ACAP</span><a rel=3D"nofollow" shape=3D"rect" class=3D"yiv8207435747" targ=
et=3D"_blank" href=3D"https://us-mg0.mail.yahoo.com/neo/launch?.rand=3D1lc7=
cfbnjsq0p#RFC2244" style=3D"font-family:verdana, helvetica, arial, sans-ser=
if;font-size:13px;text-decoration:none;background-color:rgb(255, 255, 255);=
">[RFC2244]</a><span class=3D"yiv8207435747" style=3D"font-family:verdana, =
helvetica, arial, sans-serif;font-size:13px;">&nbsp;</span><span class=3D"y=
iv8207435747" style=3D"font-family:verdana, helvetica, arial, sans-serif;fo=
nt-size:13px;">section 6.3.1."</span></div></div></div></blockquote><div><b=
r clear=3D"none"></div>Actually I meant RFC 4422 (SASL). ACAP has cancellat=
ion token, but so does IMAP, SMTP, LDAP,...<div><br clear=3D"none"></div><d=
iv>If you like, I send you an IMAP example.<div class=3D"yiv8207435747yqt09=
78937274" id=3D"yiv8207435747yqtfd43836"><br clear=3D"none"><blockquote typ=
e=3D"cite"><div><div style=3D"color:#000;background-color:#fff;font-family:=
HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;=
font-size:12px;"> <div class=3D"yiv8207435747qtdSeparateBR"><br clear=3D"no=
ne"><br clear=3D"none"></div><div class=3D"yiv8207435747yahoo_quoted" style=
=3D"display:block;"> <div style=3D"font-family:HelveticaNeue, Helvetica Neu=
e, Helvetica, Arial, Lucida Grande, sans-serif;font-size:12px;"> <div style=
=3D"font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Gra=
nde, sans-serif;font-size:16px;"> <div dir=3D"ltr"> <font size=3D"2" face=
=3D"Arial"> On Sunday, January 4, 2015 3:37 AM, Alexey Melnikov &lt;<a rel=
=3D"nofollow" shape=3D"rect" ymailto=3D"mailto:alexey.melnikov@isode.com" t=
arget=3D"_blank" href=3D"mailto:alexey.melnikov@isode.com">alexey.melnikov@=
isode.com</a>&gt; wrote:<br clear=3D"none"> </font> </div>  <br clear=3D"no=
ne"><br clear=3D"none"> <div class=3D"yiv8207435747y_msg_container">Hi Bill=
,<br clear=3D"none"><div class=3D"yiv8207435747yqt7536736220" id=3D"yiv8207=
435747yqtfd36038"><br clear=3D"none">&gt; On 3 Jan 2015, at 00:56, Bill Mil=
ls &lt;<a rel=3D"nofollow" shape=3D"rect" ymailto=3D"mailto:wmills_92105@ya=
hoo.com" target=3D"_blank" href=3D"mailto:wmills_92105@yahoo.com">wmills_92=
105@yahoo.com</a>&gt; wrote:<br clear=3D"none">&gt; <br clear=3D"none">&gt;=
 3.2.3 and an explicit message:&nbsp; Long ago in the life of this doc I wa=
s told that some implementations may not support an empty message, so we pu=
t the single character message there to have an explicit payload.&nbsp; I'm=
 a bit leery of changing this now since there are implementations in play t=
hat use it this way.</div><br clear=3D"none"><br clear=3D"none">I didn't su=
ggest you should be sending empty message. I said you should be using SASL =
cancellation token, which is a mandatory RFC 4422 feature.<br clear=3D"none=
"><br clear=3D"none">Any implementation would have to support this mode of =
operation anyway, because a SASL client can cancel any exchange.<div class=
=3D"yiv8207435747yqt7536736220" id=3D"yiv8207435747yqtfd53837"><br clear=3D=
"none"><br clear=3D"none"></div><br clear=3D"none"><br clear=3D"none"></div=
>  </div> </div>  </div> </div></div></blockquote></div></div></div></div><=
br clear=3D"none"><br clear=3D"none"></div>  </div> </div>  </div> </div></=
div></blockquote></div></div></div></div><br><br></div>  </div> </div>  </d=
iv> </div></body></html>
------=_Part_498700_2032503051.1420844969270--


From nobody Mon Jan 12 17:33:21 2015
Return-Path: <ietf-secretariat-reply@ietf.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BEC521A8832 for <kitten@ietfa.amsl.com>; Mon, 12 Jan 2015 17:33:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qyPyXX6yDhbi; Mon, 12 Jan 2015 17:33:13 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 2693E1A883B; Mon, 12 Jan 2015 17:33:13 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
To: kitten@ietf.org, kitten-chairs@tools.ietf.org, draft-ietf-kitten-cammac.all@tools.ietf.org, kaduk@mit.edu
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.0.p8
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150113013313.17312.30433.idtracker@ietfa.amsl.com>
Date: Mon, 12 Jan 2015 17:33:13 -0800
From: IETF Secretariat <ietf-secretariat-reply@ietf.org>
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/cGo4ZBbQ-P2eKhSghcUYbnt0mTc>
Subject: [kitten] ID Tracker State Update Notice: <draft-ietf-kitten-cammac-01.txt>
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Jan 2015 01:33:17 -0000

IESG has approved the document and state has been changed to Approved-announcement sent
ID Tracker URL: http://datatracker.ietf.org/doc/draft-ietf-kitten-cammac/


From nobody Mon Jan 12 17:33:33 2015
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A54CC1A8832; Mon, 12 Jan 2015 17:33:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.9
X-Spam-Level: 
X-Spam-Status: No, score=-101.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, USER_IN_WHITELIST=-100] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ccb9VdRA7aa1; Mon, 12 Jan 2015 17:33:19 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 4E69E1A898F; Mon, 12 Jan 2015 17:33:13 -0800 (PST)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.0.p8
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150113013313.17312.35831.idtracker@ietfa.amsl.com>
Date: Mon, 12 Jan 2015 17:33:13 -0800
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/A8SkKWs_T7CmUzifnCsybb-UKJc>
Cc: kitten mailing list <kitten@ietf.org>, kitten chair <kitten-chairs@tools.ietf.org>, RFC Editor <rfc-editor@rfc-editor.org>
Subject: [kitten] Protocol Action: 'Kerberos Authorization Data Container Authenticated by Multiple MACs' to Proposed Standard (draft-ietf-kitten-cammac-01.txt)
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Jan 2015 01:33:21 -0000

The IESG has approved the following document:
- 'Kerberos Authorization Data Container Authenticated by Multiple MACs'
  (draft-ietf-kitten-cammac-01.txt) as Proposed Standard

This document is the product of the Common Authentication Technology Next
Generation Working Group.

The IESG contact persons are Stephen Farrell and Kathleen Moriarty.

A URL of this Internet Draft is:
http://datatracker.ietf.org/doc/draft-ietf-kitten-cammac/





Technical Summary

   This document specifies a Kerberos Authorization Data
   container that supersedes AD-KDC-ISSUED.  It allows for multiple
   Message Authentication Codes (MACs) or signatures to authenticate the
   contained Authorization Data elements.  This document updates RFC
   4120.

Working Group Summary

The review process for this document was quite spread out in time, with
action occurring in occasional bursts.  Almost all of the Kerberos
experts who regularly participate in the WG have contributed to
reviewing this document at some point in its history, but not
necessarily all at the same time.  There was a lot of discussion around
the time of the initial few revisions, but then a lull in activity.
Version -05 got a lot of review comments, which resulted in some
(substantive, but relatively minor) changes to the specification.  It
was unclear what level of review those changes had received, after
essentially no comments were received during a WGLC period for the -08,
so we solicited further comments at that time, and got thorough review
from two Kerberos experts, which the shepherd believes is sufficient.
These post-WGLC reviews were largely editorial, but there were four
issues of substance that were raised, two of which received heavy
discussion.

Document Quality

There are not currently any implementations, but Red Hat and MIT plan
to collaborate to produce an implementation.  MIT has a partial
implementation of an en/decoder for the ASN.1 types.

Personnel

  The document shepherd is Benjamin Kaduk.  
  The irresponsible Area Director is Stephen Farrell.


From nobody Mon Jan 12 20:05:23 2015
Return-Path: <ietf-secretariat-reply@ietf.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 414D71A8968 for <kitten@ietfa.amsl.com>; Mon, 12 Jan 2015 20:05:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5B0unxD_kHBW; Mon, 12 Jan 2015 20:05:15 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 509FA1A89B4; Mon, 12 Jan 2015 20:05:15 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
To: kitten@ietf.org, kitten-chairs@tools.ietf.org, draft-ietf-kitten-cammac.all@tools.ietf.org, kaduk@mit.edu
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.0.p8
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150113040515.3832.1745.idtracker@ietfa.amsl.com>
Date: Mon, 12 Jan 2015 20:05:15 -0800
From: IETF Secretariat <ietf-secretariat-reply@ietf.org>
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/bTdr2AF3TqGmO_-BkG_3UAVs3SE>
Subject: [kitten] ID Tracker State Update Notice: <draft-ietf-kitten-cammac-01.txt>
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Jan 2015 04:05:18 -0000

IANA action state changed to No IC
ID Tracker URL: http://datatracker.ietf.org/doc/draft-ietf-kitten-cammac/


From nobody Tue Jan 13 02:48:34 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3ECD81A8A9C; Tue, 13 Jan 2015 02:48:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id epVazIdHP78n; Tue, 13 Jan 2015 02:48:27 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 975FA1A8836; Tue, 13 Jan 2015 02:48:27 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.0.p8
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150113104827.9793.39634.idtracker@ietfa.amsl.com>
Date: Tue, 13 Jan 2015 02:48:27 -0800
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/ZWg3Pq4mSSnnPSUVYwksDcCamyc>
Cc: kitten@ietf.org
Subject: [kitten] I-D Action: draft-ietf-kitten-gssapi-extensions-iana-09.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Jan 2015 10:48:29 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Common Authentication Technology Next Generation Working Group of the IETF.

        Title           : Namespace Considerations and Registries for GSS-API Extensions
        Authors         : Cryptonector LLC
                          Alexey Melnikov
	Filename        : draft-ietf-kitten-gssapi-extensions-iana-09.txt
	Pages           : 12
	Date            : 2015-01-13

Abstract:
   This document describes the ways in which the GSS-API may be extended
   and directs the creation of an IANA registry for various GSS-API
   namespaces.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-kitten-gssapi-extensions-iana/

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-kitten-gssapi-extensions-iana-09

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=draft-ietf-kitten-gssapi-extensions-iana-09


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Tue Jan 13 02:55:00 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6BA7E1A8A9C; Tue, 13 Jan 2015 02:54:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bnrIzPTI4-Bd; Tue, 13 Jan 2015 02:54:51 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id A79421A8A57; Tue, 13 Jan 2015 02:54:51 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.0.p8
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150113105451.17703.66818.idtracker@ietfa.amsl.com>
Date: Tue, 13 Jan 2015 02:54:51 -0800
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/yOoc_BtxIVIQ7usJA7nUISQ7fus>
Cc: kitten@ietf.org
Subject: [kitten] I-D Action: draft-ietf-kitten-gssapi-extensions-iana-10.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Jan 2015 10:54:53 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Common Authentication Technology Next Generation Working Group of the IETF.

        Title           : Namespace Considerations and Registries for GSS-API Extensions
        Authors         : Cryptonector LLC
                          Alexey Melnikov
	Filename        : draft-ietf-kitten-gssapi-extensions-iana-10.txt
	Pages           : 13
	Date            : 2015-01-13

Abstract:
   This document describes the ways in which the GSS-API may be extended
   and directs the creation of an IANA registry for various GSS-API
   namespaces.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-kitten-gssapi-extensions-iana/

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-kitten-gssapi-extensions-iana-10

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=draft-ietf-kitten-gssapi-extensions-iana-10


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Tue Jan 13 03:03:31 2015
Return-Path: <alexey.melnikov@isode.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C6C0E1A8A57 for <kitten@ietfa.amsl.com>; Tue, 13 Jan 2015 03:03:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.01
X-Spam-Level: 
X-Spam-Status: No, score=-2.01 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kafg8J3keJA2 for <kitten@ietfa.amsl.com>; Tue, 13 Jan 2015 03:03:29 -0800 (PST)
Received: from waldorf.isode.com (ext-bt.isode.com [217.34.220.158]) by ietfa.amsl.com (Postfix) with ESMTP id 8CC6E1A8836 for <kitten@ietf.org>; Tue, 13 Jan 2015 03:03:24 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1421147001; d=isode.com; s=selector; i=@isode.com; bh=jkTVxbGx8aBjAhixY3+0195ZfCYBCyMIjGL4XschCNU=; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version: In-Reply-To:References:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description; b=MS+XvCYhPMiS/XRduUn6hWpGUVl7o8XeANjtw5t4q7jKmCXCRITPDhj+UqBNKfwRqGuLFz cCdGId6CBuX/bT6y7C4ZFBzOz+ET06/gQ09XpD22QbT0Kt08xJ3OHpTDI+MHgKfVlZX+WC mPjNch+eNSLBU0bpZFI2r/hqLWZYk00=;
Received: from [192.168.0.6] (cpc5-nmal20-2-0-cust24.19-2.cable.virginm.net [92.234.84.25])  by waldorf.isode.com (submission channel) via TCP with ESMTPSA  id <VLT7dgAKaAAm@waldorf.isode.com>; Tue, 13 Jan 2015 11:03:20 +0000
X-SMTP-Protocol-Errors: PIPELINING
Message-ID: <54B4FB8B.9070101@isode.com>
Date: Tue, 13 Jan 2015 11:03:39 +0000
From: Alexey Melnikov <alexey.melnikov@isode.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:17.0) Gecko/20130620 Thunderbird/17.0.7
To: kitten@ietf.org
References: <20150113105451.17703.66818.idtracker@ietfa.amsl.com>
In-Reply-To: <20150113105451.17703.66818.idtracker@ietfa.amsl.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/0Uyz37uTc6d4TUhkkVTlP7yFmB8>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-gssapi-extensions-iana-10.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Jan 2015 11:03:31 -0000

On 13/01/2015 10:54, internet-drafts@ietf.org wrote:
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
>   This draft is a work item of the Common Authentication Technology Next Generation Working Group of the IETF.
>
>          Title           : Namespace Considerations and Registries for GSS-API Extensions
>          Authors         : Cryptonector LLC
>                            Alexey Melnikov
> 	Filename        : draft-ietf-kitten-gssapi-extensions-iana-10.txt
> 	Pages           : 13
> 	Date            : 2015-01-13
>
> Abstract:
>     This document describes the ways in which the GSS-API may be extended
>     and directs the creation of an IANA registry for various GSS-API
>     namespaces.
>
Hi,
I finally updated this document to include some example registrations as 
discussed on the mailing list.

I would like to ask chairs to start WGLC on this document.

Thank you,
Alexey



From nobody Tue Jan 13 09:10:50 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 891AE1A900A for <kitten@ietfa.amsl.com>; Tue, 13 Jan 2015 09:10:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0Rr8YDnMOw0g for <kitten@ietfa.amsl.com>; Tue, 13 Jan 2015 09:10:45 -0800 (PST)
Received: from dmz-mailsec-scanner-8.mit.edu (dmz-mailsec-scanner-8.mit.edu [18.7.68.37]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E4C941A8FD7 for <kitten@ietf.org>; Tue, 13 Jan 2015 09:10:44 -0800 (PST)
X-AuditID: 12074425-f798e6d000000d1a-d9-54b55193a586
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-8.mit.edu (Symantec Messaging Gateway) with SMTP id 07.3E.03354.39155B45; Tue, 13 Jan 2015 12:10:43 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id t0DHAgOb016556; Tue, 13 Jan 2015 12:10:43 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t0DHAe3G015403 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Tue, 13 Jan 2015 12:10:42 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t0DHAehW003641; Tue, 13 Jan 2015 12:10:40 -0500 (EST)
Date: Tue, 13 Jan 2015 12:10:40 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Alexey Melnikov <alexey.melnikov@isode.com>
In-Reply-To: <54B4FB8B.9070101@isode.com>
Message-ID: <alpine.GSO.1.10.1501131207140.23489@multics.mit.edu>
References: <20150113105451.17703.66818.idtracker@ietfa.amsl.com> <54B4FB8B.9070101@isode.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrFIsWRmVeSWpSXmKPExsUixG6nojs5cGuIwbdGNYsZq4ssjm5exeLA 5LFkyU8mj1PNhgFMUVw2Kak5mWWpRfp2CVwZG5ddZi74xllx71pOA+Mk9i5GTg4JAROJa2te QdliEhfurWfrYuTiEBJYzCRx+PklKGcjo8Sajh/MEM4hJom3N86xgbQICTQwSvw7pQViswho S+w4+IwRxGYTUJGY+WYjWI2IgL7E6lezWEBsZgFhifXnZjCD2MICwRJvT39jArE5BTQlNmzZ BxbnFXCUOL5nDyPE/DiJf/+PgvWKCuhIrN4/hQWiRlDi5MwnUDO1JJZP38YygVFwFpLULCSp BYxMqxhlU3KrdHMTM3OKU5N1i5MT8/JSi3Qt9HIzS/RSU0o3MYKD1EV1B+OEQ0qHGAU4GJV4 eHdkbwkRYk0sK67MPcQoycGkJMrb5bk1RIgvKT+lMiOxOCO+qDQntfgQowQHs5II7yNzoBxv SmJlVWpRPkxKmoNFSZx30w++ECGB9MSS1OzU1ILUIpisDAeHkgRvYABQo2BRanpqRVpmTglC momDE2Q4D9BwI5Aa3uKCxNzizHSI/ClGRSlx3l/+QAkBkERGaR5cLyyJvGIUB3pFmPcMSDsP MAHBdb8CGswENHhx+2aQwSWJCCmpBsalBlfXrF8nMI1pefW+Ce7xz13+Vj3cZ7VW+m/SygUL fghY33R8bb7e8eNW/c8HW7ZrzZv75dlZx5mPYj9q7v3xWWuezSkfw0NHvs8RyolfVcJ8+FHq piVvSvrlXroufFJr9FrAZDnr1cmVPguaXnTMOXPgzatv/mfutS1+XXJubpLQg+TbZ/lF5ymx FGckGmoxFxUnAgCHkOt5/QIAAA==
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/kp2qP4AtVQmI4IYQ_U7x2sJpaUo>
Cc: kitten@ietf.org
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-gssapi-extensions-iana-10.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Jan 2015 17:10:47 -0000

Hi Alexey,

On Tue, 13 Jan 2015, Alexey Melnikov wrote:

> On 13/01/2015 10:54, internet-drafts@ietf.org wrote:
> > A New Internet-Draft is available from the on-line Internet-Drafts
> > directories.
> >   This draft is a work item of the Common Authentication Technology Next
> > Generation Working Group of the IETF.
> >
> >          Title           : Namespace Considerations and Registries for
> > GSS-API Extensions
> >          Authors         : Cryptonector LLC
> >                            Alexey Melnikov
> > 	Filename        : draft-ietf-kitten-gssapi-extensions-iana-10.txt
> > 	Pages           : 13
> > 	Date            : 2015-01-13
> >
> > Abstract:
> >     This document describes the ways in which the GSS-API may be extended
> >     and directs the creation of an IANA registry for various GSS-API
> >     namespaces.
> >
> Hi,
> I finally updated this document to include some example registrations as
> discussed on the mailing list.

Thanks for these updates.

> I would like to ask chairs to start WGLC on this document.

We'll go ahead and put it in the queue.  The group of three bis documents
is next in the queue, but I'd have to check what else is still waiting
that might need to go before this one.

-Ben


From nobody Tue Jan 13 16:24:54 2015
Return-Path: <ietf-secretariat-reply@ietf.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F2D651B2A24 for <kitten@ietfa.amsl.com>; Tue, 13 Jan 2015 16:24:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id k1pCRxD5nhib; Tue, 13 Jan 2015 16:24:50 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 931F61ACD8A; Tue, 13 Jan 2015 16:24:50 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
To: kitten@ietf.org, kitten-chairs@tools.ietf.org, draft-ietf-kitten-cammac.all@tools.ietf.org, kaduk@mit.edu
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.0.p8
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150114002450.17563.96038.idtracker@ietfa.amsl.com>
Date: Tue, 13 Jan 2015 16:24:50 -0800
From: IETF Secretariat <ietf-secretariat-reply@ietf.org>
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/LHBb0o6Xw4haDfAIos5fZIj9Nvw>
Subject: [kitten] ID Tracker State Update Notice: <draft-ietf-kitten-cammac-01.txt>
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Jan 2015 00:24:52 -0000

IESG state changed to RFC Ed Queue from Approved-announcement sent
ID Tracker URL: http://datatracker.ietf.org/doc/draft-ietf-kitten-cammac/


From nobody Wed Jan 14 13:12:59 2015
Return-Path: <jhutz@cmu.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EFE941A9071 for <kitten@ietfa.amsl.com>; Wed, 14 Jan 2015 13:12:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.21
X-Spam-Level: 
X-Spam-Status: No, score=-4.21 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XKERqUma5c4V for <kitten@ietfa.amsl.com>; Wed, 14 Jan 2015 13:12:56 -0800 (PST)
Received: from smtp03.srv.cs.cmu.edu (smtp03.srv.cs.cmu.edu [128.2.217.202]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0FF191A906C for <kitten@ietf.org>; Wed, 14 Jan 2015 13:12:55 -0800 (PST)
Received-SPF: none (cmu.edu: No applicable sender policy available) receiver=smtp03.srv.cs.cmu.edu; identity=mailfrom; envelope-from="jhutz@cmu.edu"; helo="[128.2.193.239]"; client-ip=128.2.193.239
Received: from [128.2.193.239] (minbar.fac.cs.cmu.edu [128.2.193.239]) (authenticated bits=0) by smtp03.srv.cs.cmu.edu (8.13.6/8.13.6) with ESMTP id t0ELCo3g016785 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NO); Wed, 14 Jan 2015 16:12:51 -0500 (EST)
Message-ID: <1421269970.18482.184.camel@minbar.fac.cs.cmu.edu>
From: Jeffrey Hutzelman <jhutz@cmu.edu>
To: Nico Williams <nico@cryptonector.com>
Date: Wed, 14 Jan 2015 16:12:50 -0500
In-Reply-To: <20141220001633.GD12662@localhost>
References: <alpine.GSO.1.10.1411241330400.19231@multics.mit.edu> <20141124185114.GM3200@localhost> <alpine.GSO.1.10.1412091618550.23489@multics.mit.edu> <20141209215519.GI12979@localhost> <alpine.GSO.1.10.1412091856160.23489@multics.mit.edu> <20141210002441.GP12979@localhost> <alpine.GSO.1.10.1412101349030.23489@multics.mit.edu> <548F185E.70701@mit.edu> <5492032F.9050607@mit.edu> <20141217230505.GD9443@localhost> <20141220001633.GD12662@localhost>
Content-Type: text/plain; charset="UTF-8"
X-Mailer: Evolution 3.2.3-0ubuntu6 
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0
X-Scanned-By: mimedefang-cmuscs on 128.2.217.202
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/8V7hxUQxHe0Yd_50egj6z4jZGWo>
Cc: kitten@ietf.org, jhutz@cmu.edu
Subject: Re: [kitten] RFC2743 errata 4251
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Jan 2015 21:12:58 -0000

On Fri, 2014-12-19 at 18:16 -0600, Nico Williams wrote:
> On further thought, since context deletion tokens are obsoleted, and
> have been for a long time, we might as well say nothing about
> GSS_S_COMPLETE implying that the peer is done using its side of the
> security context.  The GSS_S_FAILURE case, however, still kinda leads to
> the caller being done.
> 
> OLD PROPOSED TEXT
> |      Though future GSS-API extensions may add new uses of asynchronous
> |      security context tokens and ways to process them, applications
> |      using the GSS-API version 2, update 1, should generally call
> |      GSS_Delete_sec_context() after calling GSS_Process_context_token(),
> |      when the latter returns GSS_S_COMPLETE or GSS_S_FAILURE.
> 
> NEW:
> |      Applications should generally call GSS_Delete_sec_context() when
> |      GSS_Process_context_token() returns GSS_S_FAILURE.

FWIW, I agree with Greg that it's not reasonable to assume, or suggest
that applications assume, that all asynchronous context tokens are
deletion tokens or mean that the context is now dead.  So, the above
change is an improvement.

However, after reading this thread, I'm not convinced we need to give
applications any guidance about calling GSS_Delete_sec_context after
processing a context token.  Nico thinks that saying "generally" makes
it OK, but I disagree.  The word "generally" here isn't an effective
weasel word; it's a particle.  If you describe what the exceptions are,
you don't need it, and if you don't, then it doesn't do you any good.
Implementors are going to read the text as if the word wasn't there.


I think it is worth noting that if we start giving new implementation
guidance to applications in an erratum, people who read it will assume
it must be important and start doing that, because otherwise, why did we
go out of our way to publish an erratum?


The purpose of errata is to fix technical or editorial errors and
omissions in the existing spec.  They are not for changing the spec or
offering new guidance.  We should stick to doing the former, and leave
the latter for a new or updated document, if it's necessary.

-- Jeff


From nobody Wed Jan 14 13:48:58 2015
Return-Path: <nico@cryptonector.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9FB591ACD33 for <kitten@ietfa.amsl.com>; Wed, 14 Jan 2015 13:48:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.666
X-Spam-Level: 
X-Spam-Status: No, score=-1.666 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, IP_NOT_FRIENDLY=0.334, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Q1XITa9M_6UI for <kitten@ietfa.amsl.com>; Wed, 14 Jan 2015 13:48:40 -0800 (PST)
Received: from homiemail-a103.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) by ietfa.amsl.com (Postfix) with ESMTP id B32AA1ACCEB for <kitten@ietf.org>; Wed, 14 Jan 2015 13:48:34 -0800 (PST)
Received: from homiemail-a103.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a103.g.dreamhost.com (Postfix) with ESMTP id 614D92005E615; Wed, 14 Jan 2015 13:48:34 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=cryptonector.com; h=date :from:to:cc:subject:message-id:references:mime-version :content-type:in-reply-to; s=cryptonector.com; bh=ks8EiVN1oAdirO 0MgoCy4yOEOjA=; b=InvldkD4i6fZq8CgCBgEEgdw+qFCSD/Ip9GnrGdRl9bgKI RzsXAybMmNPlHeDECB5QcfJFsYc07b50EpSWI1uKrF1U5KFevKf5j5D0f2NIXGBf 5a5t0JWaIv/u/dOMKq3mIf+SCfdKzro3LgZ3BLi2sp0GsskyFNUbFq/mwkf1Y=
Received: from localhost (108-207-244-174.lightspeed.austtx.sbcglobal.net [108.207.244.174]) (Authenticated sender: nico@cryptonector.com) by homiemail-a103.g.dreamhost.com (Postfix) with ESMTPA id 06EBE2005E613; Wed, 14 Jan 2015 13:48:33 -0800 (PST)
Date: Wed, 14 Jan 2015 15:48:32 -0600
From: Nico Williams <nico@cryptonector.com>
To: Jeffrey Hutzelman <jhutz@cmu.edu>
Message-ID: <20150114214827.GE16323@localhost>
References: <alpine.GSO.1.10.1412091618550.23489@multics.mit.edu> <20141209215519.GI12979@localhost> <alpine.GSO.1.10.1412091856160.23489@multics.mit.edu> <20141210002441.GP12979@localhost> <alpine.GSO.1.10.1412101349030.23489@multics.mit.edu> <548F185E.70701@mit.edu> <5492032F.9050607@mit.edu> <20141217230505.GD9443@localhost> <20141220001633.GD12662@localhost> <1421269970.18482.184.camel@minbar.fac.cs.cmu.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <1421269970.18482.184.camel@minbar.fac.cs.cmu.edu>
User-Agent: Mutt/1.5.21 (2010-09-15)
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/VgoPW_6TwHD9rBAVxPyCcvQxA4M>
Cc: kitten@ietf.org
Subject: Re: [kitten] RFC2743 errata 4251
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Jan 2015 21:48:41 -0000

Fair enough.  Thanks for reviewing this Jeff.

Nico
-- 


From nobody Wed Jan 14 14:07:47 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 95A0B1ACDE0 for <kitten@ietfa.amsl.com>; Wed, 14 Jan 2015 14:07:44 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Adymluc66uIi for <kitten@ietfa.amsl.com>; Wed, 14 Jan 2015 14:07:42 -0800 (PST)
Received: from dmz-mailsec-scanner-5.mit.edu (dmz-mailsec-scanner-5.mit.edu [18.7.68.34]) by ietfa.amsl.com (Postfix) with ESMTP id 35FEC1ACDF7 for <kitten@ietf.org>; Wed, 14 Jan 2015 14:07:07 -0800 (PST)
X-AuditID: 12074422-f79476d000000d9e-b1-54b6e88a9f48
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-5.mit.edu (Symantec Messaging Gateway) with SMTP id 9A.CF.03486.A88E6B45; Wed, 14 Jan 2015 17:07:06 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id t0EM75ZO005443; Wed, 14 Jan 2015 17:07:06 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t0EM73Ps029198 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 14 Jan 2015 17:07:05 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t0EM735K025583; Wed, 14 Jan 2015 17:07:03 -0500 (EST)
Date: Wed, 14 Jan 2015 17:07:02 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Bill Mills <wmills_92105@yahoo.com>
In-Reply-To: <867904166.498701.1420844969279.JavaMail.yahoo@jws10697.mail.bf1.yahoo.com>
Message-ID: <alpine.GSO.1.10.1501141703440.23489@multics.mit.edu>
References: <98CD0AB3-E3B3-42D1-AB3F-3E581FCAD571@isode.com> <867904166.498701.1420844969279.JavaMail.yahoo@jws10697.mail.bf1.yahoo.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: MULTIPART/MIXED; boundary="-559023410-139653005-1421273042=:23489"
Content-ID: <alpine.GSO.1.10.1501141704050.23489@multics.mit.edu>
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFlrDKsWRmVeSWpSXmKPExsUixG6nrtv1YluIQcs5dYsZq4ssjm5exWLx res6swOzx5IlP5k8TjUbesyadZgpgDmKyyYlNSezLLVI3y6BK+Pr7V7mggmcFScWfGJsYLzE 3sXIySEhYCLxfc8vNghbTOLCvfVANheHkMBiJolTUy8wgSSEBDYySjx4lAWROMQk0fX4GROE 08AocXDzViCHg4NFQFvifYsWSAObgIrEzDcb2UDCIgLqEs3fvUFMZoFYiSWHkkAqhAUyJObP fga2l1MgQmJK3wNWEJtXwFHi/awNjBBrOxglbh/2BrFFBXQkVu+fwgJRIyhxcuYTMJtZIEDi 4qSjbBDjHSW+vs+YwCg0C0nVLCRVsxCqIMK6Em9WHWSCsLUl7t9sY4OwHSVOP7/JvoCRbRWj bEpulW5uYmZOcWqybnFyYl5eapGuqV5uZoleakrpJkZwpLgo7WD8eVDpEKMAB6MSD6/Dka0h QqyJZcWVuYcYJTmYlER5y55vCxHiS8pPqcxILM6ILyrNSS0+xCjBwawkwrv0DFCONyWxsiq1 KB8mJc3BoiTOu+kHX4iQQHpiSWp2ampBahFMVoaDQ0mCtwBkqGBRanpqRVpmTglCmomDE2Q4 D9BwO5Aa3uKCxNzizHSI/ClGRSlx3haQhABIIqM0D64XlsheMYoDvSLMGwdSxQNMgnDdr4AG MwENbkjaCjK4JBEhJdXAyHl66opCxaS1Bxfd163nqhLaqaN+sucdex5zi+EJd31TR5Gbr9Zs cHqS/ayk3WLBz64Ujnvtel+tty29HDHx3T35CY2LxT/X/T7QlKy/K0/t7ozAiv51D6cEGk68 cbI/o8rlMwuDLNeysyt9wk++y9Ww/She/0GcUVj57I+U2Ka1ey88qQjfo8RSnJFoqMVcVJwI AOE6rPc/AwAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/99GgJ1EU2BAlG4R79z4vcmHuMag>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Cancel message Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Jan 2015 22:07:44 -0000

  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

---559023410-139653005-1421273042=:23489
Content-Type: TEXT/PLAIN; charset=ISO-8859-15
Content-Transfer-Encoding: QUOTED-PRINTABLE
Content-ID: <alpine.GSO.1.10.1501141704051.23489@multics.mit.edu>



On Fri, 9 Jan 2015, Bill Mills wrote:

> OK, understanding this better. =A0See the current changes in 3.2.3 and 4.=
3
> with an example for IMAP
> in=A0http://htmlpreview.github.io/?https://github.com/sweetums/idrafts/bl=
ob/master/draft-ietf-kitten-sasl-oauth-19.html

Hmm, I think the text "or send a SASL cancellation token as generally
defined in section 6.3.1" in section 3.2.3 of the linked document needs to
specify what document's section 6.3.1 it is referring to.  (This document
has no such section, and neither does RFC 4422; RFC 3501 has such a
section but it doesn't seem like what was intended.)

Alexey, are you satisfied by text that gives these two options?  Do you
think any of your comments remain unaddressed?

Thanks,

Ben
---559023410-139653005-1421273042=:23489--


From nobody Wed Jan 14 14:28:48 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 82EA51ACE92 for <kitten@ietfa.amsl.com>; Wed, 14 Jan 2015 14:28:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Hf1klv7smJsf for <kitten@ietfa.amsl.com>; Wed, 14 Jan 2015 14:28:45 -0800 (PST)
Received: from nm32-vm0.bullet.mail.bf1.yahoo.com (nm32-vm0.bullet.mail.bf1.yahoo.com [72.30.239.136]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 911491ACE94 for <kitten@ietf.org>; Wed, 14 Jan 2015 14:28:43 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1421274522; bh=HIsUc4CGMR2xjVtJvwwHNt+fNebrFFLQEPZv/lG/S+8=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=NyEfHmH16aIgJevelPFZM/xtXfvFjKUdw6QF7qwCtbPyp4afswwDeqPcCAJO0ieqUa/+Ag70XG2rFLCSW7tB79TYOZVcOQ2HHi24ZHZ2zkbBwhhlLnXbJwBU8Yf5xHujU1tpWJUoa5bn3GcO1fkuOaQdd2zoNwsPzOGgoxVPGxf5E8sL2k0P4/qXqfNcRtiJiI87L2H5YeeHrq++lzugTFNxSQGXiGM68ONK1S4q/9cRvUA6GAqum/PEdWPyP0DmVq3JqT/Xqp4uvpfPuI7oll5Mu8isldBQ7+88SPwLWeTbCookS+WT3iQdSvN3Nd5U3EoSsPPRP2teG2LkzENbsw==
Received: from [98.139.212.151] by nm32.bullet.mail.bf1.yahoo.com with NNFMP;  14 Jan 2015 22:28:42 -0000
Received: from [98.139.212.202] by tm8.bullet.mail.bf1.yahoo.com with NNFMP; 14 Jan 2015 22:28:42 -0000
Received: from [127.0.0.1] by omp1011.mail.bf1.yahoo.com with NNFMP; 14 Jan 2015 22:28:42 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 383658.48112.bm@omp1011.mail.bf1.yahoo.com
X-YMail-OSG: MLALSaoVM1mhrlsdbZLXr7qJ63ZDNICo8iCW0BwJnyXyMGXRNKhwIPnASjSZcJQ qzc502Y.gbmfFx4wPEvtL9PSidg4yOHU3ZYOn2DS_pfcCzaxEtu4vto35Pp3O82sz27vWmHhjySC OXJIl7h9eWOsczi4Bu7nzlJKmcoQQGDYWL4deVHM1VnatuXPHSpYnYqffd7NS9yWZtSk71_ogZlu EzsLnHUiqZ8V710I8B.5WBLbEtJncH93QPF3kZQ4j_vv6_GGe4CGN2xX8Li2kvEein5pIYtCfwaB rPgcXRX1mcpvIbQ3_aQMvYcSTHV0kj5_hZAthPR4PZfYnUZPkNgvMTqacfGwQkEZragHniJ0vwOK G0e.5tPSegFgoQ08lxRa3inKkJY8v1S3G2olBgOg8DXMoHMLkeGK2uz4Hh5HgAIi8rWSR46RpLxY uflZ3Q1CInhNBylkkcK_2TrMpmINOupognBRJgGz3BbwYVHBfmCsCDyWMz89ACKN8c2ddAs3KGXK eP2MBQRYUfz3CCUDcHyM.CpgBRF8N2VH0mwi55VRqvhLul1q4pTgFpJoBpILyGf_o0hf.X1Fl0ac a7zXng0Sv87ZYaqaa3zfIy8GAHxb5jZ7dcj6owKKfV5BJ8z5M_kVQudclFNakkOXhbs5h7QuggZk OOTHwj25jxMMrUBqOPsh.pICctA.PbpthLI7t1MUM1ZVv0lGr67HhFUgg_2OvYOo8Y.Qr3.w9cK3 IwSYudnjSspH1xeMxsZxWemzJU3Lpm4PprZjlTwMtQUinUQBZGPgBI8OKu4IlQLdvIEAO4bJMuhW z8s4IHt7G7.rdcdjiHF5qicdCwfGxSR1rlZ3YP8kwKprKsfSrC581kBOn
Received: by 76.13.26.136; Wed, 14 Jan 2015 22:28:41 +0000 
Date: Wed, 14 Jan 2015 22:28:41 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Benjamin Kaduk <kaduk@MIT.EDU>
Message-ID: <1700943001.631577.1421274521469.JavaMail.yahoo@jws10610.mail.bf1.yahoo.com>
In-Reply-To: <alpine.GSO.1.10.1501141703440.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1501141703440.23489@multics.mit.edu>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_631576_216030921.1421274521465"
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/ZhKBU6XvkZ9062TwY8ZPHbzRR6I>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Cancel message Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Jan 2015 22:28:46 -0000

------=_Part_631576_216030921.1421274521465
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Corrected this to "3.5 of SASL", 6.3.1 related to a previously wrongly cite=
d spec. =C2=A0Link updated.=20

     On Wednesday, January 14, 2015 2:07 PM, Benjamin Kaduk <kaduk@MIT.EDU>=
 wrote:
  =20

=20

On Fri, 9 Jan 2015, Bill Mills wrote:

> OK, understanding this better. =C2=A0See the current changes in 3.2.3 and=
 4.3
> with an example for IMAP
> in=C2=A0http://htmlpreview.github.io/?https://github.com/sweetums/idrafts=
/blob/master/draft-ietf-kitten-sasl-oauth-19.html

Hmm, I think the text "or send a SASL cancellation token as generally
defined in section 6.3.1" in section 3.2.3 of the linked document needs to
specify what document's section 6.3.1 it is referring to.=C2=A0 (This docum=
ent
has no such section, and neither does RFC 4422; RFC 3501 has such a
section but it doesn't seem like what was intended.)

Alexey, are you satisfied by text that gives these two options?=C2=A0 Do yo=
u
think any of your comments remain unaddressed?

Thanks,

Ben

   
------=_Part_631576_216030921.1421274521465
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div dir=3D"ltr" id=3D"yui_3_16_0_1_1421188191206_248189"><sp=
an id=3D"yui_3_16_0_1_1421188191206_249276">Corrected this to "3.5 of SASL"=
, 6.3.1 related to a previously wrongly cited spec. &nbsp;Link updated.</sp=
an></div> <div class=3D"qtdSeparateBR" id=3D"yui_3_16_0_1_1421188191206_249=
613"><br><br></div><div class=3D"yahoo_quoted" style=3D"display: block;" id=
=3D"yui_3_16_0_1_1421188191206_249294"> <div style=3D"font-family: Helvetic=
aNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-si=
ze: 12px;" id=3D"yui_3_16_0_1_1421188191206_249293"> <div style=3D"font-fam=
ily: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-s=
erif; font-size: 16px;" id=3D"yui_3_16_0_1_1421188191206_249292"> <div dir=
=3D"ltr" id=3D"yui_3_16_0_1_1421188191206_249611"> <font size=3D"2" face=3D=
"Arial" id=3D"yui_3_16_0_1_1421188191206_249610"> On Wednesday, January 14,=
 2015 2:07 PM, Benjamin Kaduk &lt;kaduk@MIT.EDU&gt; wrote:<br> </font> </di=
v>  <br><br> <div class=3D"y_msg_container" id=3D"yui_3_16_0_1_142118819120=
6_249291"><br clear=3D"none"><div class=3D"yqt3732499362" id=3D"yqtfd56515"=
><br clear=3D"none">On Fri, 9 Jan 2015, Bill Mills wrote:<br clear=3D"none"=
><br clear=3D"none">&gt; OK, understanding this better. &nbsp;See the curre=
nt changes in 3.2.3 and 4.3<br clear=3D"none">&gt; with an example for IMAP=
<br clear=3D"none">&gt; in&nbsp;<a shape=3D"rect" href=3D"http://htmlprevie=
w.github.io/?https://github.com/sweetums/idrafts/blob/master/draft-ietf-kit=
ten-sasl-oauth-19.html" target=3D"_blank" id=3D"yui_3_16_0_1_1421188191206_=
249606">http://htmlpreview.github.io/?https://github.com/sweetums/idrafts/b=
lob/master/draft-ietf-kitten-sasl-oauth-19.html</a></div><br clear=3D"none"=
><br clear=3D"none">Hmm, I think the text "or send a SASL cancellation toke=
n as generally<br clear=3D"none">defined in section 6.3.1" in section 3.2.3=
 of the linked document needs to<br clear=3D"none">specify what document's =
section 6.3.1 it is referring to.&nbsp; (This document<br clear=3D"none">ha=
s no such section, and neither does RFC 4422; RFC 3501 has such a<br clear=
=3D"none">section but it doesn't seem like what was intended.)<br clear=3D"=
none"><br clear=3D"none">Alexey, are you satisfied by text that gives these=
 two options?&nbsp; Do you<br clear=3D"none">think any of your comments rem=
ain unaddressed?<br clear=3D"none"><br clear=3D"none">Thanks,<br clear=3D"n=
one"><br clear=3D"none">Ben<br><br></div>  </div> </div>  </div> </div></bo=
dy></html>
------=_Part_631576_216030921.1421274521465--


From nobody Fri Jan 16 11:21:32 2015
Return-Path: <alexey.melnikov@isode.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D16FC1B2A88 for <kitten@ietfa.amsl.com>; Fri, 16 Jan 2015 11:21:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.61
X-Spam-Level: 
X-Spam-Status: No, score=-0.61 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id scbE1yxMuhaV for <kitten@ietfa.amsl.com>; Fri, 16 Jan 2015 11:21:28 -0800 (PST)
Received: from waldorf.isode.com (ext-bt.isode.com [217.34.220.158]) by ietfa.amsl.com (Postfix) with ESMTP id 5C4701B2A91 for <kitten@ietf.org>; Fri, 16 Jan 2015 11:21:28 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1421436087; d=isode.com; s=selector; i=@isode.com; bh=iEIiSxlT29zuXhktBoMUXJ8mkqSWsLrfWV60pufVBkc=; h=From:Sender:Reply-To:Subject:Date:Message-ID:To:Cc:MIME-Version: In-Reply-To:References:Content-Type:Content-Transfer-Encoding: Content-ID:Content-Description; b=SpZiegp89hhT45QHjo9k4POzYo5kSCxTNV8qELaC5k8rB//T47wzESbiZ+xqwlFoHzFZxj NDiDQ2JWtCV8dldjqjweeZaa9oJ7iuDO1XG76DkVo0uULGs8UCGDtAp2YPBopG0jZnzMJE fKfRSepUdXyyS9r5VqdePaKfa0ZwdOY=;
Received: from [172.20.1.215] (dhcp-215.isode.net [172.20.1.215])  by waldorf.isode.com (submission channel) via TCP with ESMTPSA  id <VLlktQAKaHy3@waldorf.isode.com>; Fri, 16 Jan 2015 19:21:27 +0000
Message-ID: <54B9640F.7090601@isode.com>
Date: Fri, 16 Jan 2015 19:18:39 +0000
From: Alexey Melnikov <alexey.melnikov@isode.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.2.0
To: Benjamin Kaduk <kaduk@MIT.EDU>, Bill Mills <wmills_92105@yahoo.com>
References: <98CD0AB3-E3B3-42D1-AB3F-3E581FCAD571@isode.com> <867904166.498701.1420844969279.JavaMail.yahoo@jws10697.mail.bf1.yahoo.com> <alpine.GSO.1.10.1501141703440.23489@multics.mit.edu>
In-Reply-To: <alpine.GSO.1.10.1501141703440.23489@multics.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=iso-8859-15; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/srkl0KXnZ8iQ_Z8xqcIVqiKXRWk>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Cancel message Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Jan 2015 19:21:30 -0000

Hi Ben,

On 14/01/2015 22:07, Benjamin Kaduk wrote:
> On Fri, 9 Jan 2015, Bill Mills wrote:
>
>> OK, understanding this better.  See the current changes in 3.2.3 and 4.3
>> with an example for IMAP
>> in http://htmlpreview.github.io/?https://github.com/sweetums/idrafts/blob/master/draft-ietf-kitten-sasl-oauth-19.html
> Hmm, I think the text "or send a SASL cancellation token as generally
> defined in section 6.3.1" in section 3.2.3 of the linked document needs to
> specify what document's section 6.3.1 it is referring to.  (This document
> has no such section, and neither does RFC 4422; RFC 3501 has such a
> section but it doesn't seem like what was intended.)
>
> Alexey, are you satisfied by text that gives these two options?  Do you
> think any of your comments remain unaddressed?
I am happy with the latest version that Bill produced (see his other email).


From nobody Fri Jan 16 11:52:10 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6544E1B2AE5 for <kitten@ietfa.amsl.com>; Fri, 16 Jan 2015 11:52:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.525
X-Spam-Level: *
X-Spam-Status: No, score=1.525 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, IP_NOT_FRIENDLY=0.334, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HNlQ8rsxzO2n for <kitten@ietfa.amsl.com>; Fri, 16 Jan 2015 11:52:07 -0800 (PST)
Received: from nm46-vm8.bullet.mail.gq1.yahoo.com (nm46-vm8.bullet.mail.gq1.yahoo.com [67.195.87.176]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 143C91B2AE3 for <kitten@ietf.org>; Fri, 16 Jan 2015 11:52:07 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1421437926; bh=kDJfTNWyIslvQBZnwmCaH/Rd1GeYBJaUGifRZShFPzg=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=cQPaIGgMNrPtLG1xnyeIbeq7LwxB1+nw0DGrAEsmyszQ4wlRwmGI046FSdFCxGpcvThowdPbMoYrucwIy+eBBaEbrSueF0HqDJ5xa+N7uA4XM8aY7smfoBdWF0N83if6Qy15Ebz+GCTqTbXdP4ADpn1OZe+Ib8rtF1qlDQUmE2NJiN73qjZA0RQ6DM+pjSUu0yPqG+HVSLM8VNBqbWg16JNB6Ge0CwIcGsNHAc/Kgua2rpYW4jEKm24dRzbcyYKMHecfpaxBjg1rDOHIGgA4NhAY2GqGre5FYvnjGqssCA9AQoIrIT3aUBKbngHCpYeONZRsc2eY6OV3PamMyk68FQ==
Received: from [127.0.0.1] by nm46.bullet.mail.gq1.yahoo.com with NNFMP; 16 Jan 2015 19:52:06 -0000
Received: from [216.39.60.184] by nm46.bullet.mail.gq1.yahoo.com with NNFMP; 16 Jan 2015 19:49:06 -0000
Received: from [66.196.81.171] by tm20.bullet.mail.gq1.yahoo.com with NNFMP; 16 Jan 2015 19:49:06 -0000
Received: from [98.139.212.220] by tm17.bullet.mail.bf1.yahoo.com with NNFMP;  16 Jan 2015 19:49:05 -0000
Received: from [127.0.0.1] by omp1029.mail.bf1.yahoo.com with NNFMP; 16 Jan 2015 19:48:56 -0000
X-Yahoo-Newman-Property: ymail-4
X-Yahoo-Newman-Id: 495760.75433.bm@omp1029.mail.bf1.yahoo.com
X-YMail-OSG: GOmhwo8VM1kJ1NUbz6ZI6dGeFzb3HXSjD9CHZBywV7VTISz4R554ErCO4GiHjyp OsL_ijCnlxtH9914R3FiVUxGQw8YBQN3imQAe95_kppdLpPwooFanthdRNibjBXNeSN5CRz6wdXD 3.u7gGWO0FUrcsRmt30nMkAq5cgmiiMUlT1yHJrdS84gKXeU0QSEqjwt6P1D8e5FRTw9tQ42bKwq VPc01ups60TbJWS86wHD_9NKJh8wIQOoXhwckqFxpJpNwB43bJOWQW8QkCMlFWE.yhon6R1Qv8fE 2iqkuBiB73b.M7HB2qXHRRlp2w.ptzL0_Vos3X3zcI8fgsBsFAG82zZclLpTeiFQM5VcGeK1Shw4 u8I4jkMwYNqHv4dNFmNzLuZshmlVKgIf1chM1rzURWg4.m520VJyKihtEtaxgBYw5ixHDdBPzVtM WPh5P.OUXF_6mUe7A0eG_nYL6BG0uKUA0Ze8qkvuorGd8XpyuQw4Ul7Gblwp70Iyrz4etm8JhR2Y OFwPggbuEKDbVmSltrmVW_Gr5s_sg8FH..ZeDUZ5md.T5hTlh.vDly_vFHjLfMA_r1.Blggg_YDR As7eDsaUhakepMOBBOPUoR8ia55PBSEZW5p57kWjTzSmK1xlG6XFk7E13My0VSNjNkp5hPBs.ga7 gQT69G5yyPQk9.f88RhlmcS_d6OB9luVfp8yDlMe.uMBPzKg_.Ge75oQM1X4IgFKGHj3ZX0U4IAM cidlwSI_uLJmdDMBPElPCOvL6lzoRTisnu0fRkohP6ZgHQF7dTeu7M8fRy9D..9bD8p4day_Ztig 7m9Sd29DNl8CkO4dZQWH60geUdzPIQEOFn2DzczmYpi.wyd9s.iuvlrct1bx0nVDvHw--
Received: by 66.196.80.112; Fri, 16 Jan 2015 19:48:56 +0000 
Date: Fri, 16 Jan 2015 19:48:55 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Alexey Melnikov <alexey.melnikov@isode.com>,  Benjamin Kaduk <kaduk@MIT.EDU>
Message-ID: <1248550839.2367152.1421437735766.JavaMail.yahoo@jws106120.mail.bf1.yahoo.com>
In-Reply-To: <54B9640F.7090601@isode.com>
References: <54B9640F.7090601@isode.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_2367151_1277264661.1421437735763"
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/R7gXN13CSbdQYUAgFmRYtqUcFIo>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Cancel message Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Jan 2015 19:52:08 -0000

------=_Part_2367151_1277264661.1421437735763
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Thanks for the good feedback Alexey. =C2=A0I'm much happier with it now.=20

     On Friday, January 16, 2015 11:21 AM, Alexey Melnikov <alexey.melnikov=
@isode.com> wrote:
  =20

 Hi Ben,

On 14/01/2015 22:07, Benjamin Kaduk wrote:
> On Fri, 9 Jan 2015, Bill Mills wrote:
>
>> OK, understanding this better.=C2=A0 See the current changes in 3.2.3 an=
d 4.3
>> with an example for IMAP
>> in http://htmlpreview.github.io/?https://github.com/sweetums/idrafts/blo=
b/master/draft-ietf-kitten-sasl-oauth-19.html
> Hmm, I think the text "or send a SASL cancellation token as generally
> defined in section 6.3.1" in section 3.2.3 of the linked document needs t=
o
> specify what document's section 6.3.1 it is referring to.=C2=A0 (This doc=
ument
> has no such section, and neither does RFC 4422; RFC 3501 has such a
> section but it doesn't seem like what was intended.)
>
> Alexey, are you satisfied by text that gives these two options?=C2=A0 Do =
you
> think any of your comments remain unaddressed?
I am happy with the latest version that Bill produced (see his other email)=
.



   
------=_Part_2367151_1277264661.1421437735763
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div id=3D"yui_3_16_0_1_1421282644741_294018" dir=3D"ltr"><sp=
an>Thanks for the good feedback Alexey. &nbsp;I'm much happier with it now.=
</span></div> <div class=3D"qtdSeparateBR"><br><br></div><div class=3D"yaho=
o_quoted" style=3D"display: block;"> <div style=3D"font-family: HelveticaNe=
ue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size:=
 12px;"> <div style=3D"font-family: HelveticaNeue, Helvetica Neue, Helvetic=
a, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div dir=3D"ltr"> <=
font size=3D"2" face=3D"Arial"> On Friday, January 16, 2015 11:21 AM, Alexe=
y Melnikov &lt;alexey.melnikov@isode.com&gt; wrote:<br> </font> </div>  <br=
><br> <div class=3D"y_msg_container">Hi Ben,<br clear=3D"none"><div class=
=3D"yqt2963462766" id=3D"yqtfd12206"><br clear=3D"none">On 14/01/2015 22:07=
, Benjamin Kaduk wrote:<br clear=3D"none">&gt; On Fri, 9 Jan 2015, Bill Mil=
ls wrote:<br clear=3D"none">&gt;<br clear=3D"none">&gt;&gt; OK, understandi=
ng this better.&nbsp; See the current changes in 3.2.3 and 4.3<br clear=3D"=
none">&gt;&gt; with an example for IMAP<br clear=3D"none">&gt;&gt; in <a sh=
ape=3D"rect" href=3D"http://htmlpreview.github.io/?https://github.com/sweet=
ums/idrafts/blob/master/draft-ietf-kitten-sasl-oauth-19.html" target=3D"_bl=
ank">http://htmlpreview.github.io/?https://github.com/sweetums/idrafts/blob=
/master/draft-ietf-kitten-sasl-oauth-19.html</a><br clear=3D"none">&gt; Hmm=
, I think the text "or send a SASL cancellation token as generally<br clear=
=3D"none">&gt; defined in section 6.3.1" in section 3.2.3 of the linked doc=
ument needs to<br clear=3D"none">&gt; specify what document's section 6.3.1=
 it is referring to.&nbsp; (This document<br clear=3D"none">&gt; has no suc=
h section, and neither does RFC 4422; RFC 3501 has such a<br clear=3D"none"=
>&gt; section but it doesn't seem like what was intended.)<br clear=3D"none=
">&gt;<br clear=3D"none">&gt; Alexey, are you satisfied by text that gives =
these two options?&nbsp; Do you<br clear=3D"none">&gt; think any of your co=
mments remain unaddressed?</div><br clear=3D"none">I am happy with the late=
st version that Bill produced (see his other email).<div class=3D"yqt296346=
2766" id=3D"yqtfd66998"><br clear=3D"none"><br clear=3D"none"></div><br><br=
></div>  </div> </div>  </div> </div></body></html>
------=_Part_2367151_1277264661.1421437735763--


From nobody Tue Jan 20 13:25:40 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A97611A000D for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 13:25:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id B2STfictLZP3 for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 13:25:37 -0800 (PST)
Received: from dmz-mailsec-scanner-6.mit.edu (dmz-mailsec-scanner-6.mit.edu [18.7.68.35]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F271F1A000C for <kitten@ietf.org>; Tue, 20 Jan 2015 13:25:36 -0800 (PST)
X-AuditID: 12074423-f797b6d000000cfe-3a-54bec7cf341c
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-6.mit.edu (Symantec Messaging Gateway) with SMTP id C6.D6.03326.FC7CEB45; Tue, 20 Jan 2015 16:25:35 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id t0KLPYkE031061; Tue, 20 Jan 2015 16:25:35 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t0KLPWok028276 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Tue, 20 Jan 2015 16:25:34 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t0KLPWmg001902; Tue, 20 Jan 2015 16:25:32 -0500 (EST)
Date: Tue, 20 Jan 2015 16:25:32 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
In-Reply-To: <1421269970.18482.184.camel@minbar.fac.cs.cmu.edu>
Message-ID: <alpine.GSO.1.10.1501201620290.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1411241330400.19231@multics.mit.edu> <20141124185114.GM3200@localhost> <alpine.GSO.1.10.1412091618550.23489@multics.mit.edu> <20141209215519.GI12979@localhost> <alpine.GSO.1.10.1412091856160.23489@multics.mit.edu> <20141210002441.GP12979@localhost> <alpine.GSO.1.10.1412101349030.23489@multics.mit.edu> <548F185E.70701@mit.edu> <5492032F.9050607@mit.edu> <20141217230505.GD9443@localhost> <20141220001633.GD12662@localhost> <1421269970.18482.184.camel@minbar.fac.cs.cmu.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrPIsWRmVeSWpSXmKPExsUixG6nonv++L4Qg0X3dS2Obl7FYnHq2hE2 ByaPl6fOMXosWfKTKYApissmJTUnsyy1SN8ugSvj671ZjAVNqhULp79jbWDslu1i5OSQEDCR uLn1HTOELSZx4d56ti5GLg4hgcVMEl92XGCEcDYySmxf+BTKOcQkceTiGmYIp4FR4ue+bjaQ fhYBbYkNnxtZQGw2ARWJmW82gsVFBIQldkPtYBbQlNjY1Q5mCwPZO7/eYgWxOQXsJfZ1LWAH sXkFHCVOPfwJteA3s8SOhRPBEqICOhKr909hgSgSlDg58wkLxFAtieXTt7FMYBSchSQ1C0lq ASPTKkbZlNwq3dzEzJzi1GTd4uTEvLzUIl0zvdzMEr3UlNJNjOBwdVHewfjnoNIhRgEORiUe 3per9oYIsSaWFVfmHmKU5GBSEuV9M2lfiBBfUn5KZUZicUZ8UWlOavEhRgkOZiURXt3DQDne lMTKqtSifJiUNAeLkjjvph98IUIC6YklqdmpqQWpRTBZGQ4OJQne/mNAjYJFqempFWmZOSUI aSYOTpDhPEDDN4HU8BYXJOYWZ6ZD5E8xKkqJ83aDJARAEhmleXC9sHTyilEc6BVh3l6QKh5g KoLrfgU0mAlosNiuPSCDSxIRUlINjE6fXFzNHR45JV75/Vn57KPeIFdjg9h9pd21z96+PzZP XDgnnT+wUjxRoeqkcOativvHXgu81/j3xK70sHO22u5HAXGbptVsm/n2xK5uKaa6Zx2zOHun 8pyOvLbig1iOUNHsxgOMfjqFakvzRU6wPvbX2O87Zbb71P/xURMkq82MSrtXpc88pMRSnJFo qMVcVJwIAFt0fnoCAwAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/ECWz55lZcsM0lvcFgF6aBf3rKP8>
Subject: Re: [kitten] RFC2743 errata 4251
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Jan 2015 21:25:39 -0000

On Wed, 14 Jan 2015, Jeffrey Hutzelman wrote:

> On Fri, 2014-12-19 at 18:16 -0600, Nico Williams wrote:
> > On further thought, since context deletion tokens are obsoleted, and
> > have been for a long time, we might as well say nothing about
> > GSS_S_COMPLETE implying that the peer is done using its side of the
> > security context.  The GSS_S_FAILURE case, however, still kinda leads to
> > the caller being done.
> >
> > OLD PROPOSED TEXT
> > |      Though future GSS-API extensions may add new uses of asynchronous
> > |      security context tokens and ways to process them, applications
> > |      using the GSS-API version 2, update 1, should generally call
> > |      GSS_Delete_sec_context() after calling GSS_Process_context_token(),
> > |      when the latter returns GSS_S_COMPLETE or GSS_S_FAILURE.
> >
> > NEW:
> > |      Applications should generally call GSS_Delete_sec_context() when
> > |      GSS_Process_context_token() returns GSS_S_FAILURE.
>
> FWIW, I agree with Greg that it's not reasonable to assume, or suggest
> that applications assume, that all asynchronous context tokens are
> deletion tokens or mean that the context is now dead.  So, the above
> change is an improvement.
>
> However, after reading this thread, I'm not convinced we need to give
> applications any guidance about calling GSS_Delete_sec_context after
> processing a context token.  Nico thinks that saying "generally" makes
> it OK, but I disagree.  The word "generally" here isn't an effective
> weasel word; it's a particle.  If you describe what the exceptions are,
> you don't need it, and if you don't, then it doesn't do you any good.
> Implementors are going to read the text as if the word wasn't there.
>
>
> I think it is worth noting that if we start giving new implementation
> guidance to applications in an erratum, people who read it will assume
> it must be important and start doing that, because otherwise, why did we
> go out of our way to publish an erratum?

Thank you for the input, Jeff.  I think this point has not really been
mentioned yet in our discussions, and is an important one.

> The purpose of errata is to fix technical or editorial errors and
> omissions in the existing spec.  They are not for changing the spec or
> offering new guidance.  We should stick to doing the former, and leave
> the latter for a new or updated document, if it's necessary.

I think this makes the current proposal under consideration (removing
entirely the paragraph which attempted to give applications guidance on
when to call GSS_Delete_sec_context()):

======================================================

  Section 2.2.4 says:

     o  GSS_S_FAILURE indicates that the context is recognized, but that
     the GSS_Process_context_token() operation could not be performed
     for reasons unspecified at the GSS-API level.

  It should say:

     o  GSS_S_FAILURE indicates that the context is recognized, but
     either the GSS_Process_context_token() operation could not be
     performed for reasons unspecified at the GSS-API level, or the peer
     had an error consuming the last context token sent to it.  The latter
     occurs when the local side became fully established and produced one
     last token which was sent to the peer, but the peer encountered an
     error while processing that last context token.  In either case the
     minor status code provides additional information.

     In the case of successful processing of error tokens, the minor
     status code provides information from the input token.  The display
     string outputs of GSS_Display_status() as applied to such minor
     status codes should indicate that the error originated on the remote
     peer, along with the nature of the error.  Note that there is no
     way to distinguish failures of GSS_Process_context_token() from
     error token information other than to read the human-readable status
     display strings.

     In practice, an unexpected security context token that imediately
     follows full security context establishment is very likely a
     context token conveying error information rather than a security
     context deletion token, especially since the latter are obsoleted.

     Applications using transports that may deliver messages out of
     order may continue to attempt to process per-message tokens between
     calling GSS_Process_context_token() and GSS_Delete_sec_context(),
     though there is no guarantee that processing per-message tokens will
     then succeed.

======================================================

I will send my thoughts in a separate message.

-Ben


From nobody Tue Jan 20 13:50:11 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9F9781A0027 for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 13:50:09 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id f5_JqQAn-GJX for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 13:50:08 -0800 (PST)
Received: from nm39-vm8.bullet.mail.bf1.yahoo.com (nm39-vm8.bullet.mail.bf1.yahoo.com [72.30.239.152]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0D0251A0035 for <kitten@ietf.org>; Tue, 20 Jan 2015 13:50:01 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1421790601; bh=KjAs/rSIt8D5GkyAbIT+kgvfAFqEg6UKfmvfJHt19D4=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=JZ9m72pFpUIDd8LZGWPJ5HJe0VPE7Mf/0oANpnfFWL6kulTSgtS2laV6loAQM+xhDIUD/7wdcCoJgcjt+Xhcvayqg88Nbfzk4tniJVkTpJV9DSd4JIpPMvk3XgSd/uUKfjeCexpI20k4Y2uYnAk3gpnR1iaU9JbMsZWdq6VmjJX8wMR4nOu/Ybwlozv75RLlrTtkBbQizzNPsb8hGdUvaOJGz6vZUamqyDOdhmmwNU0FTOVPXDYt5G04KE4CtI2ZnEKSxaUjOAb5prpuTpHeSweTyV8lUn+Q9EcT717o0njzALG4nJcwIAliN3Twyi+7UeeeklfvEdEa4dDSJftdlA==
Received: from [66.196.81.170] by nm39.bullet.mail.bf1.yahoo.com with NNFMP; 20 Jan 2015 21:50:01 -0000
Received: from [98.139.212.201] by tm16.bullet.mail.bf1.yahoo.com with NNFMP;  20 Jan 2015 21:50:01 -0000
Received: from [127.0.0.1] by omp1010.mail.bf1.yahoo.com with NNFMP; 20 Jan 2015 21:50:01 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 171893.23622.bm@omp1010.mail.bf1.yahoo.com
X-YMail-OSG: e14QhTgVM1nA8N1qfimzm3tCxj.Z7qMr.gZ5fgd0eCnMEB824ePSyYQz8aAjK.A 52DvT9TEAh3D2CwPZsOYxQzZTo5dOdkidjN3yRsgQbcNzzw0XFxS0GIMjhb6OUxfeIFVLivXxNtm J6FfyhtI97uyj2tcskma_K8JxQn0ltBjawWH6K6x59hi0mBqJ81fV8E3u8Pnjn.MKcTFiR6FOuri 98rLtv0NIuWWjNot9383W8ATgHd8yIIh0zLBSZV1eHH.thnsSyTbg2mH4gya_LkleuvjWurCdSDv _2ANQA513rTNuYoanUnN6MApp.cxjHlMvO6rtQZB8658EmDC8uyUxBtnLkeVo_R.HitjbzCL3Mwp judB0_9EX.zTFb7j6MRGaQIXG1EmGCpdb1GEkGijbKDD2tpA8dZj_cmZvFA8UH8fS1bk.WuepUN6 sCgC237MppfVhInNkHxqeu3IeMBLNkd9_daSGQy1tBlGocCLhLZUCmUNYUpfY3QZUw9uFU_CG51m 9wLSs5EG7tVShGB.B8Ol4sfngqm6hoMtoDZ5gusooUcUDze.3_pofrKHfD2y7KylZvVYjxqTHk3e xjZLJzympYhymLtaBkgNPQQ17rNi8onCmzlO4HbwosrvTnBQxiUfUHDE3DAlMz9aVWOzscwsGQi9 6Y9cItTLqYawxnEVduXU.KXFA3xo59wAciox0dpOhDmrGz7uXqSr2pMzJFzcGe0lyBz6o2rXdTt6 p2vml.0qUs.c8EYYp.FeOKv408GM0ZcYfxZw6fsOxSFsG1onXBywESXTR49TDdSOf42UDD6AZ9zc 8GidDadk5OyI0ttIVZsySEl_UzFZ8NfquYlqKZbZqVlLFvjqAvz5DrpsE
Received: by 76.13.26.109; Tue, 20 Jan 2015 21:50:00 +0000 
Date: Tue, 20 Jan 2015 21:50:00 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Bill Mills <wmills_92105@yahoo.com>,  Alexey Melnikov <alexey.melnikov@isode.com>,  Benjamin Kaduk <kaduk@MIT.EDU>
Message-ID: <396296285.4111283.1421790600398.JavaMail.yahoo@jws10697.mail.bf1.yahoo.com>
In-Reply-To: <1248550839.2367152.1421437735766.JavaMail.yahoo@jws106120.mail.bf1.yahoo.com>
References: <1248550839.2367152.1421437735766.JavaMail.yahoo@jws106120.mail.bf1.yahoo.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_4111282_886378266.1421790600394"
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/WsmlsAt0g0QyN1sgSqXyYOEikO8>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Cancel message Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Jan 2015 21:50:09 -0000

------=_Part_4111282_886378266.1421790600394
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

So is this one ready now for -19 to be published? =C2=A0WGLC done?=20

     On Friday, January 16, 2015 5:19 PM, Bill Mills <wmills_92105@yahoo.co=
m> wrote:
  =20

 Thanks for the good feedback Alexey. =C2=A0I'm much happier with it now.=
=20

     On Friday, January 16, 2015 11:21 AM, Alexey Melnikov <alexey.melnikov=
@isode.com> wrote:
  =20

 Hi Ben,

On 14/01/2015 22:07, Benjamin Kaduk wrote:
> On Fri, 9 Jan 2015, Bill Mills wrote:
>
>> OK, understanding this better.=C2=A0 See the current changes in 3.2.3 an=
d 4.3
>> with an example for IMAP
>> in http://htmlpreview.github.io/?https://github.com/sweetums/idrafts/blo=
b/master/draft-ietf-kitten-sasl-oauth-19.html
> Hmm, I think the text "or send a SASL cancellation token as generally
> defined in section 6.3.1" in section 3.2.3 of the linked document needs t=
o
> specify what document's section 6.3.1 it is referring to.=C2=A0 (This doc=
ument
> has no such section, and neither does RFC 4422; RFC 3501 has such a
> section but it doesn't seem like what was intended.)
>
> Alexey, are you satisfied by text that gives these two options?=C2=A0 Do =
you
> think any of your comments remain unaddressed?
I am happy with the latest version that Bill produced (see his other email)=
.



   =20
_______________________________________________
Kitten mailing list
Kitten@ietf.org
https://www.ietf.org/mailman/listinfo/kitten


   
------=_Part_4111282_886378266.1421790600394
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div id=3D"yui_3_16_0_1_1421282644741_857564" dir=3D"ltr"><sp=
an>So is this one ready now for -19 to be published? &nbsp;WGLC done?</span=
></div> <div class=3D"qtdSeparateBR"><br><br></div><div class=3D"yahoo_quot=
ed" style=3D"display: block;"> <div style=3D"font-family: HelveticaNeue, He=
lvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 12px;=
"> <div style=3D"font-family: HelveticaNeue, Helvetica Neue, Helvetica, Ari=
al, Lucida Grande, sans-serif; font-size: 16px;"> <div dir=3D"ltr"> <font s=
ize=3D"2" face=3D"Arial"> On Friday, January 16, 2015 5:19 PM, Bill Mills &=
lt;wmills_92105@yahoo.com&gt; wrote:<br> </font> </div>  <br><br> <div clas=
s=3D"y_msg_container"><div id=3D"yiv8293110213"><div><div style=3D"color:#0=
00;background-color:#fff;font-family:HelveticaNeue, Helvetica Neue, Helveti=
ca, Arial, Lucida Grande, sans-serif;font-size:12px;"><div dir=3D"ltr" id=
=3D"yiv8293110213yui_3_16_0_1_1421282644741_294018"><span>Thanks for the go=
od feedback Alexey. &nbsp;I'm much happier with it now.</span></div> <div c=
lass=3D"yiv8293110213qtdSeparateBR"><br clear=3D"none"><br clear=3D"none"><=
/div><div class=3D"yiv8293110213yqt4600042201" id=3D"yiv8293110213yqt17788"=
><div class=3D"yiv8293110213yahoo_quoted" style=3D"display: block;"> <div s=
tyle=3D"font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida=
 Grande, sans-serif;font-size:12px;"> <div style=3D"font-family:HelveticaNe=
ue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:1=
6px;"> <div dir=3D"ltr"> <font size=3D"2" face=3D"Arial"> On Friday, Januar=
y 16, 2015 11:21 AM, Alexey Melnikov &lt;alexey.melnikov@isode.com&gt; wrot=
e:<br clear=3D"none"> </font> </div>  <br clear=3D"none"><br clear=3D"none"=
> <div class=3D"yiv8293110213y_msg_container">Hi Ben,<br clear=3D"none"><di=
v class=3D"yiv8293110213yqt2963462766" id=3D"yiv8293110213yqtfd12206"><br c=
lear=3D"none">On 14/01/2015 22:07, Benjamin Kaduk wrote:<br clear=3D"none">=
&gt; On Fri, 9 Jan 2015, Bill Mills wrote:<br clear=3D"none">&gt;<br clear=
=3D"none">&gt;&gt; OK, understanding this better.&nbsp; See the current cha=
nges in 3.2.3 and 4.3<br clear=3D"none">&gt;&gt; with an example for IMAP<b=
r clear=3D"none">&gt;&gt; in <a rel=3D"nofollow" shape=3D"rect" target=3D"_=
blank" href=3D"http://htmlpreview.github.io/?https://github.com/sweetums/id=
rafts/blob/master/draft-ietf-kitten-sasl-oauth-19.html">http://htmlpreview.=
github.io/?https://github.com/sweetums/idrafts/blob/master/draft-ietf-kitte=
n-sasl-oauth-19.html</a><br clear=3D"none">&gt; Hmm, I think the text "or s=
end a SASL cancellation token as generally<br clear=3D"none">&gt; defined i=
n section 6.3.1" in section 3.2.3 of the linked document needs to<br clear=
=3D"none">&gt; specify what document's section 6.3.1 it is referring to.&nb=
sp; (This document<br clear=3D"none">&gt; has no such section, and neither =
does RFC 4422; RFC 3501 has such a<br clear=3D"none">&gt; section but it do=
esn't seem like what was intended.)<br clear=3D"none">&gt;<br clear=3D"none=
">&gt; Alexey, are you satisfied by text that gives these two options?&nbsp=
; Do you<br clear=3D"none">&gt; think any of your comments remain unaddress=
ed?</div><br clear=3D"none">I am happy with the latest version that Bill pr=
oduced (see his other email).<div class=3D"yiv8293110213yqt2963462766" id=
=3D"yiv8293110213yqtfd66998"><br clear=3D"none"><br clear=3D"none"></div><b=
r clear=3D"none"><br clear=3D"none"></div>  </div> </div>  </div></div> </d=
iv></div></div><br><div class=3D"yqt4600042201" id=3D"yqt33587">___________=
____________________________________<br clear=3D"none">Kitten mailing list<=
br clear=3D"none"><a shape=3D"rect" ymailto=3D"mailto:Kitten@ietf.org" href=
=3D"mailto:Kitten@ietf.org">Kitten@ietf.org</a><br clear=3D"none"><a shape=
=3D"rect" href=3D"https://www.ietf.org/mailman/listinfo/kitten" target=3D"_=
blank">https://www.ietf.org/mailman/listinfo/kitten</a><br clear=3D"none"><=
/div><br><br></div>  </div> </div>  </div> </div></body></html>
------=_Part_4111282_886378266.1421790600394--


From nobody Tue Jan 20 13:55:13 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A015B1A0047 for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 13:55:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7U8jyGcsFh1i for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 13:54:58 -0800 (PST)
Received: from dmz-mailsec-scanner-6.mit.edu (dmz-mailsec-scanner-6.mit.edu [18.7.68.35]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7013F1A0027 for <kitten@ietf.org>; Tue, 20 Jan 2015 13:54:58 -0800 (PST)
X-AuditID: 12074423-f797b6d000000cfe-e1-54beceb1ff56
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-6.mit.edu (Symantec Messaging Gateway) with SMTP id 42.D8.03326.1BECEB45; Tue, 20 Jan 2015 16:54:57 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id t0KLsusI001226; Tue, 20 Jan 2015 16:54:56 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t0KLssel006386 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Tue, 20 Jan 2015 16:54:56 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t0KLss4E005613; Tue, 20 Jan 2015 16:54:54 -0500 (EST)
Date: Tue, 20 Jan 2015 16:54:54 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Alexey Melnikov <alexey.melnikov@isode.com>
In-Reply-To: <54B9640F.7090601@isode.com>
Message-ID: <alpine.GSO.1.10.1501201654240.23489@multics.mit.edu>
References: <98CD0AB3-E3B3-42D1-AB3F-3E581FCAD571@isode.com> <867904166.498701.1420844969279.JavaMail.yahoo@jws10697.mail.bf1.yahoo.com> <alpine.GSO.1.10.1501141703440.23489@multics.mit.edu> <54B9640F.7090601@isode.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFmpgleLIzCtJLcpLzFFi42IRYrdT1914bl+IwfV7IhYzVhdZHN28isXi W9d1ZgdmjyVLfjJ5nGo29Jg16zBTAHMUl01Kak5mWWqRvl0CV8bMHQEFP5gqHqzezdTAuISp i5GTQ0LARGLSon9QtpjEhXvr2boYuTiEBBYzSRyZfJgZwtnIKLFxbTsLhHOISeLh2Z1sIC1C Ag2MEh3TRUBsFgFtiQWLvrGC2GwCKhIz32wEqxER0JdY/WoWC4jNLOAj8eziSzBbWKBAYt2l z2A2p4CmxP5lq4FsDg5eAUeJObtEIHZ9ZJTY9vYGM0iNqICOxOr9U8DqeQUEJU7OfAI1U0ti +fRtLBMYBWchSc1CklrAyLSKUTYlt0o3NzEzpzg1Wbc4OTEvL7VI10wvN7NELzWldBMjOHBd lHcw/jmodIhRgINRiYf35aq9IUKsiWXFlbmHGCU5mJREeYvO7gsR4kvKT6nMSCzOiC8qzUkt PsQowcGsJMKrexgox5uSWFmVWpQPk5LmYFES5930gy9ESCA9sSQ1OzW1ILUIJivDwaEkwZsJ MlSwKDU9tSItM6cEIc3EwQkynAdoeDNIDW9xQWJucWY6RP4Uoy7Hgvb9M5mEWPLy81KlxHlV QYoEQIoySvPg5sASzitGcaC3hHmrQKp4gMkKbtIroCVMQEvEdu0BWVKSiJCSamAMtj+r9CJK +sjyhmje1K3Fy2O9t95+7jkttW3P4xsKCl0iNTxXb0k+tH1yaXdY47sos8yrYW4p23PvrUxv cy9yrVWw0p7wc+b3brdpE1neP7fu/32ZK6NY4tKTMLbp3NP5m+5difivULphoep63SWskr3M Rc9ijFzzLc6snXHio+nZB26VlzcqsRRnJBpqMRcVJwIAhQmyOBMDAAA=
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/Eeuqe54FNNPsu0TAXbJZse_Q2XQ>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Cancel message Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Jan 2015 21:55:10 -0000

On Fri, 16 Jan 2015, Alexey Melnikov wrote:

> > Alexey, are you satisfied by text that gives these two options?  Do you
> > think any of your comments remain unaddressed?
>
> I am happy with the latest version that Bill produced (see his other email).

Thanks for the confirmation.  I will go ahead and start on the shepherd
writeup to send this to Stephen.

-Ben


From nobody Tue Jan 20 13:59:18 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AB5AE1A004D for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 13:59:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id F6raE9VkEzgg for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 13:59:17 -0800 (PST)
Received: from nm23-vm1.bullet.mail.bf1.yahoo.com (nm23-vm1.bullet.mail.bf1.yahoo.com [98.139.213.141]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B2DEE1A0041 for <kitten@ietf.org>; Tue, 20 Jan 2015 13:59:16 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1421791155; bh=gqCMU31fnTCYyKD2HkEShcmQNKTBgb8JbVRKoDzbb3Y=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=tIm191tcKTjJ4JTzUiS4uAvukLiSs80UiH2hOGIMaJC73aZipsxG0mF7gCgiMjbyjPcwri2SSlw6DDBVge6snhMY2Qo9p5atC7vB3FepabkuVlyV8k3hjiK1XUbJr3ZLGTUVBXV4bMWuySZAf521aYHX7Bj6E3Z6afMO+0rN8aOl29wlaw/5F4+5bcIn4syS7bcx+LR8+YNtS4/er+pzggwp+EOv3QNOTrbkVt1WjhSTkL6ITzTR9jcCmmduXn5uTQ2SDgSefQERAF6TlR1grwIQ70LjGoP7P+Clc/G/7CAknxOQAQzHhlKaSXNWJontgNr22QvoxLbgu4DjaF5O0Q==
Received: from [98.139.215.143] by nm23.bullet.mail.bf1.yahoo.com with NNFMP;  20 Jan 2015 21:59:15 -0000
Received: from [98.139.212.242] by tm14.bullet.mail.bf1.yahoo.com with NNFMP;  20 Jan 2015 21:59:15 -0000
Received: from [127.0.0.1] by omp1051.mail.bf1.yahoo.com with NNFMP; 20 Jan 2015 21:59:15 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 549655.58354.bm@omp1051.mail.bf1.yahoo.com
X-YMail-OSG: OpnWDEEVM1lQgOucfsFOPTVkssO0YdsNCzL326HqXa35kedNcxTkwxkA6yZAQAe l_g345hEkaSk3bY.s6HJIOX5dENjiwM9Cg_GoV7AKAkpUgZxcwsmWt0v44aytLuh3drMA203ilZd D86ib4pDN256KiD0zkPpoTol3qcqRB5n0hnIu4w8Z7ll8t68U.RXYbGpsXZL6AGN5ucBulxPE6OJ U9NEEAB7u4EF1iPVBK3FYSH3QzsTZRApX8Gvc5c25pGOMN0KxxoDBTOFR2zUGtIH_CDqD.s2IXi1 J.qtf9oEFOdYacdrGYgBS3gEBXqfUtehRYsz9LeCnDT0MIQUQgVTCvTDb20Va8Qp0DACiIwoNLmg QlTLJvT5RfOEiStxL2YuEwJY3kqmQotBB.qRlABfxevPmohkUgZFFxZblaqVYsQhwm6J27YXL_dT aMEPkDM.Ip2p_tQ70KJf4VUGnwD30gzRR7kw__wQ8kHHCnUfxQ41LgBCbHH2pKcmkbc2OkeRRVy6 taYPSrHsOLRM-
Received: by 76.13.27.55; Tue, 20 Jan 2015 21:59:15 +0000 
Date: Tue, 20 Jan 2015 21:59:14 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Benjamin Kaduk <kaduk@MIT.EDU>,  Alexey Melnikov <alexey.melnikov@isode.com>
Message-ID: <469812825.4123480.1421791154838.JavaMail.yahoo@jws10674.mail.bf1.yahoo.com>
In-Reply-To: <alpine.GSO.1.10.1501201654240.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1501201654240.23489@multics.mit.edu>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_4123479_472284499.1421791154836"
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/bIbbCxWiQAY4y4TK67Y_HDMB5RM>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Cancel message Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Jan 2015 21:59:17 -0000

------=_Part_4123479_472284499.1421791154836
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

SO you need a -19 now correct?=20

     On Tuesday, January 20, 2015 1:54 PM, Benjamin Kaduk <kaduk@MIT.EDU> w=
rote:
  =20

 On Fri, 16 Jan 2015, Alexey Melnikov wrote:

> > Alexey, are you satisfied by text that gives these two options?=C2=A0 D=
o you
> > think any of your comments remain unaddressed?
>
> I am happy with the latest version that Bill produced (see his other emai=
l).

Thanks for the confirmation.=C2=A0 I will go ahead and start on the shepher=
d
writeup to send this to Stephen.

-Ben


   
------=_Part_4123479_472284499.1421791154836
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div dir=3D"ltr" id=3D"yui_3_16_0_1_1421282644741_870132"><sp=
an id=3D"yui_3_16_0_1_1421282644741_870131">SO you need a -19 now correct?<=
/span></div> <div class=3D"qtdSeparateBR"><br><br></div><div class=3D"yahoo=
_quoted" style=3D"display: block;"> <div style=3D"font-family: HelveticaNeu=
e, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: =
12px;"> <div style=3D"font-family: HelveticaNeue, Helvetica Neue, Helvetica=
, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div dir=3D"ltr"> <f=
ont size=3D"2" face=3D"Arial"> On Tuesday, January 20, 2015 1:54 PM, Benjam=
in Kaduk &lt;kaduk@MIT.EDU&gt; wrote:<br> </font> </div>  <br><br> <div cla=
ss=3D"y_msg_container">On Fri, 16 Jan 2015, Alexey Melnikov wrote:<br clear=
=3D"none"><br clear=3D"none">&gt; &gt; Alexey, are you satisfied by text th=
at gives these two options?&nbsp; Do you<br clear=3D"none">&gt; &gt; think =
any of your comments remain unaddressed?<br clear=3D"none">&gt;<br clear=3D=
"none">&gt; I am happy with the latest version that Bill produced (see his =
other email).<br clear=3D"none"><br clear=3D"none">Thanks for the confirmat=
ion.&nbsp; I will go ahead and start on the shepherd<br clear=3D"none">writ=
eup to send this to Stephen.<div class=3D"yqt8442563747" id=3D"yqtfd56380">=
<br clear=3D"none"><br clear=3D"none">-Ben<br clear=3D"none"></div><br><br>=
</div>  </div> </div>  </div> </div></body></html>
------=_Part_4123479_472284499.1421791154836--


From nobody Tue Jan 20 14:00:05 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A0F681A003B for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 14:00:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id o2mqlX7C7YQt for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 13:59:59 -0800 (PST)
Received: from dmz-mailsec-scanner-5.mit.edu (dmz-mailsec-scanner-5.mit.edu [18.7.68.34]) by ietfa.amsl.com (Postfix) with ESMTP id DFFAF1A0041 for <kitten@ietf.org>; Tue, 20 Jan 2015 13:59:55 -0800 (PST)
X-AuditID: 12074422-f79476d000000d9e-72-54becfdaa84a
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-5.mit.edu (Symantec Messaging Gateway) with SMTP id 04.66.03486.ADFCEB45; Tue, 20 Jan 2015 16:59:54 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id t0KLxrN8027097; Tue, 20 Jan 2015 16:59:54 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t0KLxpI1008184 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Tue, 20 Jan 2015 16:59:53 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t0KLxpqR006294; Tue, 20 Jan 2015 16:59:51 -0500 (EST)
Date: Tue, 20 Jan 2015 16:59:51 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Bill Mills <wmills_92105@yahoo.com>
In-Reply-To: <469812825.4123480.1421791154838.JavaMail.yahoo@jws10674.mail.bf1.yahoo.com>
Message-ID: <alpine.GSO.1.10.1501201659360.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1501201654240.23489@multics.mit.edu> <469812825.4123480.1421791154838.JavaMail.yahoo@jws10674.mail.bf1.yahoo.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: MULTIPART/MIXED; BOUNDARY="-559023410-59578181-1421791191=:23489"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFprJKsWRmVeSWpSXmKPExsUixCmqrHvr/L4QgyM9ahYzVhdZHN28isXi W9d1ZgdmjyVLfjJ5nGo29Jg16zBTAHMUl01Kak5mWWqRvl0CV8b09mbWgmvsFY+2bmZrYGxl 62Lk5JAQMJF4tug5C4QtJnHh3nqgOBeHkMBiJomW+9tZIJyNjBJXGn6wQjiHmCRezXvKBOE0 MEosn/sTrJ9FQFviyqTLjCA2m4CKxMw3G4FmcXCICKhLNH/3BjGZBWIllhxKAqkQFiiQWHfp M1gnp0CkxM8vl8A6eQUcJW71tTNCjO9jlHjVdZwVJCEqoCOxev8UFogiQYmTM5+A2cwC/hJ3 X75gnsAoOAtJahaSFIStLnHg00VGCFtb4v7NNrYFjCyrGGVTcqt0cxMzc4pTk3WLkxPz8lKL dE31cjNL9FJTSjcxgkKd3UVpB+PPg0qHGAU4GJV4eB3W7g0RYk0sK67MPcQoycGkJMpbdHZf iBBfUn5KZUZicUZ8UWlOavEhRgkOZiURXt3DQDnelMTKqtSifJiUNAeLkjjvph98IUIC6Ykl qdmpqQWpRTBZGQ4OJQnegHNAjYJFqempFWmZOSUIaSYOTpDhPEDDi0BqeIsLEnOLM9Mh8qcY dTkWtO+fySTEkpeflyolzusPUiQAUpRRmgc3B5aiXjGKA70lzLsQpIoHmN7gJr0CWsIEtERs 1x6QJSWJCCmpBkaWdQcvm0rvUjn54YrZ6Q1Zpya8F/wn4qH2Q+miluey6gN3N/FH78zftHuD UvX85D4bxfM2Xz2YPnuUae92kJ9Z7crruTRPXm3nTCXWEzksrEfNE8+Gv8qa8+TJTeY8nktZ ht3zd97lWLu6J+2ixVale0bBFvF7njVnlGksnPKJXThcsvX2pElKLMUZiYZazEXFiQC2KzGf LAMAAA==
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/z3fULx1TZV6w85k4LBKrbtOFpVU>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Cancel message Re: Alexey's comments Re: WGLC of draft-ietf-kitten-sasl-oauth-18
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Jan 2015 22:00:03 -0000

  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

---559023410-59578181-1421791191=:23489
Content-Type: TEXT/PLAIN; charset=UTF-8
Content-Transfer-Encoding: QUOTED-PRINTABLE

Yes, please submit the -19 to the datatracker.

-Ben

On Tue, 20 Jan 2015, Bill Mills wrote:

> SO you need a -19 now correct?
>
>      On Tuesday, January 20, 2015 1:54 PM, Benjamin Kaduk <kaduk@MIT.EDU>=
 wrote:
>
>
>  On Fri, 16 Jan 2015, Alexey Melnikov wrote:
>
> > > Alexey, are you satisfied by text that gives these two options?=C2=A0=
 Do you
> > > think any of your comments remain unaddressed?
> >
> > I am happy with the latest version that Bill produced (see his other em=
ail).
>
> Thanks for the confirmation.=C2=A0 I will go ahead and start on the sheph=
erd
> writeup to send this to Stephen.
>
> -Ben
>
>
>
>
---559023410-59578181-1421791191=:23489--


From nobody Tue Jan 20 14:23:13 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AFCEE1A0053; Tue, 20 Jan 2015 14:23:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lgsROEl2YsIR; Tue, 20 Jan 2015 14:23:08 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id DB9D31A004B; Tue, 20 Jan 2015 14:23:08 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.0.p8
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150120222308.20899.87226.idtracker@ietfa.amsl.com>
Date: Tue, 20 Jan 2015 14:23:08 -0800
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/igLDh8L_RRQU_mt_xP4VOVCmexY>
Cc: kitten@ietf.org
Subject: [kitten] I-D Action: draft-ietf-kitten-sasl-oauth-19.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Jan 2015 22:23:10 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Common Authentication Technology Next Generation Working Group of the IETF.

        Title           : A set of SASL Mechanisms for OAuth
        Authors         : William Mills
                          Tim Showalter
                          Hannes Tschofenig
	Filename        : draft-ietf-kitten-sasl-oauth-19.txt
	Pages           : 23
	Date            : 2015-01-20

Abstract:
   OAuth enables a third-party application to obtain limited access to a
   protected resource, either on behalf of a resource owner by
   orchestrating an approval interaction, or by allowing the third-party
   application to obtain access on its own behalf.

   This document defines how an application client uses credentials
   obtained via OAuth over the Simple Authentication and Security Layer
   (SASL) to access a protected resource at a resource serve.  Thereby,
   it enables schemes defined within the OAuth framework for non-HTTP-
   based application protocols.

   Clients typically store the user's long-term credential.  This does,
   however, lead to significant security vulnerabilities, for example,
   when such a credential leaks.  A significant benefit of OAuth for
   usage in those clients is that the password is replaced by a shared
   secret with higher entropy, i.e., the token.  Tokens typically
   provide limited access rights and can be managed and revoked
   separately from the user's long-term password.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-kitten-sasl-oauth/

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-kitten-sasl-oauth-19

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=draft-ietf-kitten-sasl-oauth-19


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Tue Jan 20 15:02:31 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CB2161A0084 for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 15:02:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VS9i7m5J2VJK for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 15:02:28 -0800 (PST)
Received: from dmz-mailsec-scanner-6.mit.edu (dmz-mailsec-scanner-6.mit.edu [18.7.68.35]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7BF181A0079 for <kitten@ietf.org>; Tue, 20 Jan 2015 15:02:28 -0800 (PST)
X-AuditID: 12074423-f797b6d000000cfe-cc-54bede83ca06
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-6.mit.edu (Symantec Messaging Gateway) with SMTP id 5E.5C.03326.38EDEB45; Tue, 20 Jan 2015 18:02:27 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id t0KN2QDW029595 for <kitten@ietf.org>; Tue, 20 Jan 2015 18:02:26 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t0KN2O64028875 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Tue, 20 Jan 2015 18:02:26 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t0KN2OmM014184; Tue, 20 Jan 2015 18:02:24 -0500 (EST)
Date: Tue, 20 Jan 2015 18:02:24 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
Message-ID: <alpine.GSO.1.10.1501201753140.23489@multics.mit.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFjrAIsWRmVeSWpSXmKPExsUixCmqrdt8b1+IwcrVghZHN69icWD0WLLk J1MAYxSXTUpqTmZZapG+XQJXxt9fy5gLJvNUPJg7h6mBcQlXFyMnh4SAicTrdQfYIGwxiQv3 1gPZXBxCAouZJJo+b2WBcI4zSjz+exsqc4NJonXuDCYIp4FRYsvhO0AOBweLgLbExvYEkFFs AioSM99sBBsrIiAssXvrO2aQemGBHkaJN3NuMIEkeAUcJZ5OPcoCYosK6Eis3j+FBSIuKHFy 5hMwm1lAS2L59G0sExj5ZiFJzUKSWsDItIpRNiW3Sjc3MTOnODVZtzg5MS8vtUjXTC83s0Qv NaV0EyMooNhdlHcw/jmodIhRgINRiYf35aq9IUKsiWXFlbmHGCU5mJREeYvu7gsR4kvKT6nM SCzOiC8qzUktPsQowcGsJMKrexgox5uSWFmVWpQPk5LmYFES5930gy9ESCA9sSQ1OzW1ILUI JivDwaEkwasLMlSwKDU9tSItM6cEIc3EwQkynAdoeCVIDW9xQWJucWY6RP4Uo6KUOG82SEIA JJFRmgfXC4v4V4ziQK8I8z4HqeIBJgu47ldAg5mABovt2gMyuCQRISXVwDjVyuTNreD1m48w yzEkyd6uyuk5pVE+wSLwzHr56HKlaRt1XvOc+lWd/Nvzg9mCV25hctMuvgsRnXFkzkZBhoeb 3RR4jEpjPmy8fmPd24+R8ubZ/7ns1sQsfK6lYpBzz97n0pn/3yOlJqm8iHu8dZKNMq/usvuC hew3rBPeXf1XwbfF8secvRFKLMUZiYZazEXFiQCHeJJS0wIAAA==
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/4wxLwm9s56VvlDniKPsuwavpMxA>
Subject: [kitten] WGLC for three "bis" documents: draft-ietf-kitten-rfc4402bis-00, draft-ietf-kitten-rfc5653bis-01, draft-ietf-kitten-rfc6112bis-00
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Jan 2015 23:02:31 -0000

This message begins the Working Group Last Call (WGLC) for the following
three documents: "A Pseudo-Random Function (PRF) for the Kerberos V
Generic Security Service Application Program Interface (GSS-API)
Mechanism" <draft-ietf-kitten-rfc4402bis-00>, "Generic Security Service
API Version 2: Java Bindings Update" <draft-ietf-kitten-rfc5653bis-01>,
and "Anonymity Support for Kerberos" <draft-ietf-kitten-rfc6112bis-00>.
Because there are three documents under review, and the whole body of the
documents are up for re-review (not just the updates), the WGLC is
extended to four weeks, so the WGLC will end on Tuesday February 17th,
2015.  The drafts are available at:

http://tools.ietf.org/html/draft-ietf-kitten-rfc4402bis-00
http://tools.ietf.org/html/draft-ietf-kitten-rfc5653bis-01
http://tools.ietf.org/html/draft-ietf-kitten-rfc6112bis-00

Please review these documents and send comments to the Working Group
mailing list kitten@ietf.org or the co-chairs
<kitten-chairs@tools.ietf.org> before the end of the WGLC.  Any and all
comments on the document(s) are sought in order to assess the strength of
consensus.  Even if you have read and commented on this or earlier
versions of the draft, please feel free to comment again.  This is
particularly important if you found issues with the previous version.

As a reminder, comments can be anything from "this looks fine" to "this is
a horrible idea"; they can include suggestions for minor editorial
corrections to significant editorial changes.


- Your Kitten Chairs


From nobody Tue Jan 20 17:20:48 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0935A1A00FB for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 17:20:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id y0VNmw37W8Qs for <kitten@ietfa.amsl.com>; Tue, 20 Jan 2015 17:20:43 -0800 (PST)
Received: from dmz-mailsec-scanner-2.mit.edu (dmz-mailsec-scanner-2.mit.edu [18.9.25.13]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CBD911A00FA for <kitten@ietf.org>; Tue, 20 Jan 2015 17:20:40 -0800 (PST)
X-AuditID: 1209190d-f79006d000000cfe-80-54befee7ecb1
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-2.mit.edu (Symantec Messaging Gateway) with SMTP id 82.1E.03326.7EEFEB45; Tue, 20 Jan 2015 20:20:39 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id t0L1Kdj7020613 for <kitten@ietf.org>; Tue, 20 Jan 2015 20:20:39 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t0L1KbLE001778 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Tue, 20 Jan 2015 20:20:38 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t0L1Kadt003922; Tue, 20 Jan 2015 20:20:36 -0500 (EST)
Date: Tue, 20 Jan 2015 20:20:36 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
In-Reply-To: <alpine.GSO.1.10.1501201620290.23489@multics.mit.edu>
Message-ID: <alpine.GSO.1.10.1501201908540.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1411241330400.19231@multics.mit.edu> <20141124185114.GM3200@localhost> <alpine.GSO.1.10.1412091618550.23489@multics.mit.edu> <20141209215519.GI12979@localhost> <alpine.GSO.1.10.1412091856160.23489@multics.mit.edu> <20141210002441.GP12979@localhost> <alpine.GSO.1.10.1412101349030.23489@multics.mit.edu> <548F185E.70701@mit.edu> <5492032F.9050607@mit.edu> <20141217230505.GD9443@localhost> <20141220001633.GD12662@localhost> <1421269970.18482.184.camel@minbar.fac.cs.cmu.edu> <alpine.GSO.1.10.1501201620290.23489@multics.mit.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrBIsWRmVeSWpSXmKPExsUixG6nrvv8374QgxvLNSyObl7F4sDosWTJ T6YAxigum5TUnMyy1CJ9uwSujFkv/zAVbJKqmPJ9KVMD402RLkZODgkBE4me9ldsELaYxIV7 68FsIYHFTBL3F8p3MXIB2ccZJa729jNBODeYJJrOL2eBcBoYJQ4+/8MM0sIioC3xZs0hRhCb TUBFYuabjWCjRASEJXZvfQdWIyygKbHz6y1WEJtTwEni4/29YDavgKPE5vtLmCGGbmSR6Jjz HmyQqICOxOr9U1ggigQlTs58AmYzC2hJLJ++jWUCo8AsJKlZSFILGJlWMcqm5Fbp5iZm5hSn JusWJyfm5aUW6Rrp5WaW6KWmlG5iBAUgpyTvDsZ3B5UOMQpwMCrx8Dqs3RsixJpYVlyZe4hR koNJSZQ36+++ECG+pPyUyozE4oz4otKc1OJDjBIczEoivH0fgHK8KYmVValF+TApaQ4WJXHe TT/4QoQE0hNLUrNTUwtSi2CyMhwcShK810CGChalpqdWpGXmlCCkmTg4QYbzAA3PAanhLS5I zC3OTIfIn2JUlBLnXQySEABJZJTmwfXCEsQrRnGgV4R594FU8QCTC1z3K6DBTECDxXbtARlc koiQkmpgXPBOROrLcl/H9A1WzsILulW3db/y/Bovdu12dbDP3HYGxy1V/BLXDPXi8jQrfS+d bVX/ziQs7PT93YvV94/0x2iFRkQEmzgWCO7h9zjgu2ZmjsOukjou4xUebVpXctc+mcsxoT/v 9CWj5N0M8kEHb58s3Lvh4oXAmVtEVl8O/zaFv3bHpb42JZbijERDLeai4kQAI60WkusCAAA=
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/iw9rhGlIFgjhtW9eSY_1-m5cwD0>
Subject: Re: [kitten] RFC2743 errata 4251
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Jan 2015 01:20:46 -0000

On Tue, 20 Jan 2015, Benjamin Kaduk wrote:

> I think this makes the current proposal under consideration (removing
> entirely the paragraph which attempted to give applications guidance on
> when to call GSS_Delete_sec_context()):
>
> ======================================================
>
>   Section 2.2.4 says:
>
>      o  GSS_S_FAILURE indicates that the context is recognized, but that
>      the GSS_Process_context_token() operation could not be performed
>      for reasons unspecified at the GSS-API level.
>
>   It should say:
>
>      o  GSS_S_FAILURE indicates that the context is recognized, but
>      either the GSS_Process_context_token() operation could not be
>      performed for reasons unspecified at the GSS-API level, or the peer
>      had an error consuming the last context token sent to it.  The latter

"had an error" feels slightly informal; I might prefer "experienced an
error" or something like that.

>      occurs when the local side became fully established and produced one
>      last token which was sent to the peer, but the peer encountered an
>      error while processing that last context token.  In either case the
>      minor status code provides additional information.
>
>      In the case of successful processing of error tokens, the minor
>      status code provides information from the input token.  The display
>      string outputs of GSS_Display_status() as applied to such minor
>      status codes should indicate that the error originated on the remote
>      peer, along with the nature of the error.  Note that there is no
>      way to distinguish failures of GSS_Process_context_token() from
>      error token information other than to read the human-readable status
>      display strings.
>
>      In practice, an unexpected security context token that imediately
>      follows full security context establishment is very likely a
>      context token conveying error information rather than a security
>      context deletion token, especially since the latter are obsoleted.

Given what Jeff pointed out about new statements in errata being taken as
indicating important (new) changes, I wonder if this paragraph should also
be removed.  I believe it to be a true statement, but perhaps including it
in the erratum at all will give it more weight than is appropriate.  It is
also the first mention of deletion tokens in section 2.2.4 (another
mention does occur later on), so it comes in somewhat abruptly without
introduction.

>      Applications using transports that may deliver messages out of
>      order may continue to attempt to process per-message tokens between
>      calling GSS_Process_context_token() and GSS_Delete_sec_context(),
>      though there is no guarantee that processing per-message tokens will
>      then succeed.

This also may be too much information for the erratum.  (Again, I believe
it is basically a correct statement, but that including it in the erratum
may cause it to be given too much weight.)

What do other people think?

-Ben

> ======================================================
>
> I will send my thoughts in a separate message.
>
> -Ben
>
> _______________________________________________
> Kitten mailing list
> Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten
>


From nobody Thu Jan 22 16:35:10 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BB4041A1A4D; Thu, 22 Jan 2015 16:35:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nj5-Fmq7_Nqd; Thu, 22 Jan 2015 16:35:04 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 760FD1A1A36; Thu, 22 Jan 2015 16:35:04 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.0.p8
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150123003504.3896.40306.idtracker@ietfa.amsl.com>
Date: Thu, 22 Jan 2015 16:35:04 -0800
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/0PA9hZLS0JpfQJJY7Q3P2NxWBSU>
Cc: kitten@ietf.org
Subject: [kitten] I-D Action: draft-ietf-kitten-pkinit-freshness-00.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Jan 2015 00:35:06 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Common Authentication Technology Next Generation Working Group of the IETF.

        Title           : Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) Freshness Extension
        Authors         : Michiko Short
                          Seth Moore
                          Paul Miller
	Filename        : draft-ietf-kitten-pkinit-freshness-00.txt
	Pages           : 8
	Date            : 2015-01-22

Abstract:
   This document describes how to further extend the Public Key
   Cryptography for Initial Authentication in Kerberos (PKINIT)
   extension [RFC4556] to exchange an opaque data blob which a KDC can
   validate to ensure that the client is currently in possession of the
   private key during a PKInit AS exchange.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-kitten-pkinit-freshness/

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-kitten-pkinit-freshness-00


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Fri Jan 23 10:15:45 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DAF601A700D for <kitten@ietfa.amsl.com>; Fri, 23 Jan 2015 10:15:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.811
X-Spam-Level: 
X-Spam-Status: No, score=-2.811 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QvF_YMSn-tX3 for <kitten@ietfa.amsl.com>; Fri, 23 Jan 2015 10:15:33 -0800 (PST)
Received: from dmz-mailsec-scanner-1.mit.edu (dmz-mailsec-scanner-1.mit.edu [18.9.25.12]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ED7901A711A for <kitten@ietf.org>; Fri, 23 Jan 2015 10:15:29 -0800 (PST)
X-AuditID: 1209190c-f79e46d000000eb2-7a-54c28fbf5dc0
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-1.mit.edu (Symantec Messaging Gateway) with SMTP id 11.F5.03762.FBF82C45; Fri, 23 Jan 2015 13:15:27 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id t0NIFRb6014069 for <kitten@ietf.org>; Fri, 23 Jan 2015 13:15:27 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t0NIFPnK004040 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Fri, 23 Jan 2015 13:15:27 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t0NIFPTr029345; Fri, 23 Jan 2015 13:15:25 -0500 (EST)
Date: Fri, 23 Jan 2015 13:15:25 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
In-Reply-To: <alpine.GSO.1.10.1501071258380.23489@multics.mit.edu>
Message-ID: <alpine.GSO.1.10.1501231313340.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1501071258380.23489@multics.mit.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrEIsWRmVeSWpSXmKPExsUixG6nrru//1CIwZVNJhZHN69icWD0WLLk J1MAYxSXTUpqTmZZapG+XQJXxqNni5gKXrBUvFg6gb2B8TZzFyMnh4SAicT06dfYIWwxiQv3 1rN1MXJxCAksZpI4Oe89E4RznFHi7b4zrCBVQgI3mCSa3nJAJBoYJZatuAaWYBHQluhsnMEC YrMJqEjMfLORDcQWERCW2L31Hdg6YQEdie3HZjKB2JwCThKXXi0Gi/MKOEosfbwXyOYAGuoo MXGrIkhYFKh89f4pLBAlghInZz4Bs5kFtCSWT9/GMoFRYBaS1CwkqQWMTKsYZVNyq3RzEzNz ilOTdYuTE/PyUot0DfVyM0v0UlNKNzGCgo9TkmcH45uDSocYBTgYlXh4G7YcDBFiTSwrrsw9 xCjJwaQkyqsBDF0hvqT8lMqMxOKM+KLSnNTiQ4wSHMxKIrwZKUA53pTEyqrUonyYlDQHi5I4 76YffCFCAumJJanZqakFqUUwWRkODiUJ3hN9QI2CRanpqRVpmTklCGkmDk6Q4TxAw8VBFvMW FyTmFmemQ+RPMepyLGjfP5NJiCUvPy9VSpz3N8ggAZCijNI8uDmwpPGKURzoLWFec5AqHmDC gZv0CmgJE9CSgu0HQJaUJCKkpBoY7SY/3zKbOXupz56qOxNUmp60/YntvLH6lt+OoHTxxP5j mna2mc9Y5vp6/nl6xmDvHqPpFU3aRn+29NUI/fTx4fL/bc3SGhH/jc34wSeG+g02R86p/NGc LBJ07jwfq/baZ5KriwOOvBTfmVG6fcPVB7deZG6pXLRy4YOjRUEVK6eYf/ir+24qoxJLcUai oRZzUXEiAA4Vbn71AgAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/ZT-jEnkgBixQKsFH5zRHwPtPBJQ>
Subject: Re: [kitten] IETF 92 - Agenda items
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Jan 2015 18:15:35 -0000

On Wed, 7 Jan 2015, Benjamin Kaduk wrote:

> Hi all,
>
> IETF 92 is March 22-27 in Dallas.  Please provide any agenda items for a
> Dallas session, either to the list or to the co-chairs, no later than
> Tuesday, January 20, 2015.

I forgot to send a reminder before the deadline.  Luckily, there is still
some time for submitting agenda items.

We plan to submit the agenda to the datatracker early next week, so please
try to get items in by Monday.  They don't need to be long -- a topic name
or draft title and an estimate for the time needed should be sufficient at
this point.

Thanks,

Ben


From nobody Fri Jan 23 10:34:58 2015
Return-Path: <wmills_92105@yahoo.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EDBBF1ACDD3 for <kitten@ietfa.amsl.com>; Fri, 23 Jan 2015 10:34:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.191
X-Spam-Level: *
X-Spam-Status: No, score=1.191 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, FREEMAIL_REPLYTO_END_DIGIT=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uT6wHdTBdXZG for <kitten@ietfa.amsl.com>; Fri, 23 Jan 2015 10:34:37 -0800 (PST)
Received: from nm46-vm10.bullet.mail.bf1.yahoo.com (nm46-vm10.bullet.mail.bf1.yahoo.com [216.109.114.203]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BF4951ACDD0 for <kitten@ietf.org>; Fri, 23 Jan 2015 10:34:36 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1422038076; bh=3GNK/niTapuiVqIjEUvGKCFcq+Z2st7pbAou/JdmhKE=; h=Date:From:Reply-To:To:In-Reply-To:References:Subject:From:Subject; b=q/jh1cXqiRHmyxzUF3ZvUTaxyTr9GqXqSCpWk+SLp3sWWg/w19WBmKtYnEg3p7QMXSOcdu4IC6hsUIVnrFGRitRES3oy5vH/brPebE3RdO++i4Kkc87qhXHMOjry9IoGsQw1zdf/L6Sdlk4mYTtBd2H2ftp4bCDdr2ExQMZlDbfFe97s1qI3ThgTWQ46MpmztMMt1cHoCu0iVSOHh6YXqGuQqBrw1PxoKh4/WXdbm2RLGWX0Nvof9RHbn+gK/OBPjTbHJfG+tMsCPDPN2piEroQC5V72JN7r0eAHMtULBHKjPTKfmp29NYmtPOjMzrJCdNri6vhQKSbIbC/tc/AUqQ==
Received: from [66.196.81.170] by nm46.bullet.mail.bf1.yahoo.com with NNFMP; 23 Jan 2015 18:34:36 -0000
Received: from [98.139.215.228] by tm16.bullet.mail.bf1.yahoo.com with NNFMP;  23 Jan 2015 18:34:35 -0000
Received: from [127.0.0.1] by omp1068.mail.bf1.yahoo.com with NNFMP; 23 Jan 2015 18:34:35 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 976184.15089.bm@omp1068.mail.bf1.yahoo.com
X-YMail-OSG: 4rUpSowVM1mB17RpL8muP1ogjoRKXmEhpZ.J6wyvabtueeiQ99qzLSm5gVvdZjK NDKUclcVbZPQoXvQXPcoNj6NuK6Y.5IF1Y3jIlWwoJ0iyi2hXxUC_C3o2z0De1ST_sD1apjiIOMD ZoXjhsizKxODO0_iUXG6ad83YNGInoEsyCO_epdpqL7twlnSw.jz9kPqypWKWzQt5dN94HhTAS83 TIGYcjNMbyZdDJX1cCv1z0JN8WIe29AhyQGFzgX7Hb2gnzlzif_8oQU0d8yxEizjnX1Ya7rdPcQc 9VBXfJGlig1UHaZXpfBQogHJAAM6bYUrXPNCw3sRTyjjjeQ9L8LgnK_2VlRT5mPghVnKeVnLaOPD .6.wmIJL4ZwBRLRTvotSYJwDML4Zrzz1BerYZvWCHCutYbitBgGYC66weUcQWGyb.qutbd7fCRzL todcehbW7Tuj7oiJe1ccgIeh7k8c5PunMTmgNIGk_aS4iZF3UxqBSNngoWZlK5iE6rtStRIcvi3x 2uWkifNBl
Received: by 76.13.26.79; Fri, 23 Jan 2015 18:34:35 +0000 
Date: Fri, 23 Jan 2015 18:34:35 +0000 (UTC)
From: Bill Mills <wmills_92105@yahoo.com>
To: Benjamin Kaduk <kaduk@MIT.EDU>, "kitten@ietf.org" <kitten@ietf.org>
Message-ID: <922433422.304688.1422038075116.JavaMail.yahoo@mail.yahoo.com>
In-Reply-To: <alpine.GSO.1.10.1501231313340.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1501231313340.23489@multics.mit.edu>
MIME-Version: 1.0
Content-Type: multipart/alternative;  boundary="----=_Part_304687_418588298.1422038075114"
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/SbmSoJTj-RyOrTKjgtxzaHsbWkc>
Subject: Re: [kitten] IETF 92 - Agenda items
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Bill Mills <wmills_92105@yahoo.com>
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Jan 2015 18:34:38 -0000

------=_Part_304687_418588298.1422038075114
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Nothing to do on OAUTH/SASL right? =C2=A0Waiting for shepherd writeup.=20

     On Friday, January 23, 2015 10:15 AM, Benjamin Kaduk <kaduk@MIT.EDU> w=
rote:
  =20

 On Wed, 7 Jan 2015, Benjamin Kaduk wrote:

> Hi all,
>
> IETF 92 is March 22-27 in Dallas.=C2=A0 Please provide any agenda items f=
or a
> Dallas session, either to the list or to the co-chairs, no later than
> Tuesday, January 20, 2015.

I forgot to send a reminder before the deadline.=C2=A0 Luckily, there is st=
ill
some time for submitting agenda items.

We plan to submit the agenda to the datatracker early next week, so please
try to get items in by Monday.=C2=A0 They don't need to be long -- a topic =
name
or draft title and an estimate for the time needed should be sufficient at
this point.

Thanks,

Ben

_______________________________________________
Kitten mailing list
Kitten@ietf.org
https://www.ietf.org/mailman/listinfo/kitten


   
------=_Part_304687_418588298.1422038075114
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:He=
lveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;fo=
nt-size:12px"><div dir=3D"ltr"><span>Nothing to do on OAUTH/SASL right? &nb=
sp;Waiting for shepherd writeup.</span></div> <div class=3D"qtdSeparateBR">=
<br><br></div><div class=3D"yahoo_quoted" style=3D"display: block;"> <div s=
tyle=3D"font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucid=
a Grande, sans-serif; font-size: 12px;"> <div style=3D"font-family: Helveti=
caNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-s=
ize: 16px;"> <div dir=3D"ltr"> <font size=3D"2" face=3D"Arial"> On Friday, =
January 23, 2015 10:15 AM, Benjamin Kaduk &lt;kaduk@MIT.EDU&gt; wrote:<br> =
</font> </div>  <br><br> <div class=3D"y_msg_container">On Wed, 7 Jan 2015,=
 Benjamin Kaduk wrote:<br clear=3D"none"><br clear=3D"none">&gt; Hi all,<br=
 clear=3D"none">&gt;<br clear=3D"none">&gt; IETF 92 is March 22-27 in Dalla=
s.&nbsp; Please provide any agenda items for a<br clear=3D"none">&gt; Dalla=
s session, either to the list or to the co-chairs, no later than<br clear=
=3D"none">&gt; Tuesday, January 20, 2015.<br clear=3D"none"><br clear=3D"no=
ne">I forgot to send a reminder before the deadline.&nbsp; Luckily, there i=
s still<br clear=3D"none">some time for submitting agenda items.<br clear=
=3D"none"><br clear=3D"none">We plan to submit the agenda to the datatracke=
r early next week, so please<br clear=3D"none">try to get items in by Monda=
y.&nbsp; They don't need to be long -- a topic name<br clear=3D"none">or dr=
aft title and an estimate for the time needed should be sufficient at<br cl=
ear=3D"none">this point.<br clear=3D"none"><br clear=3D"none">Thanks,<div c=
lass=3D"yqt6751057174" id=3D"yqtfd88781"><br clear=3D"none"><br clear=3D"no=
ne">Ben<br clear=3D"none"><br clear=3D"none">______________________________=
_________________<br clear=3D"none">Kitten mailing list<br clear=3D"none"><=
a shape=3D"rect" ymailto=3D"mailto:Kitten@ietf.org" href=3D"mailto:Kitten@i=
etf.org">Kitten@ietf.org</a><br clear=3D"none"><a shape=3D"rect" href=3D"ht=
tps://www.ietf.org/mailman/listinfo/kitten" target=3D"_blank">https://www.i=
etf.org/mailman/listinfo/kitten</a><br clear=3D"none"></div><br><br></div> =
 </div> </div>  </div> </div></body></html>
------=_Part_304687_418588298.1422038075114--


From nobody Fri Jan 23 10:40:10 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 343AC1ACDD9 for <kitten@ietfa.amsl.com>; Fri, 23 Jan 2015 10:39:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LZDq2oOH-JgB for <kitten@ietfa.amsl.com>; Fri, 23 Jan 2015 10:39:50 -0800 (PST)
Received: from dmz-mailsec-scanner-8.mit.edu (dmz-mailsec-scanner-8.mit.edu [18.7.68.37]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 74AB81A8715 for <kitten@ietf.org>; Fri, 23 Jan 2015 10:39:39 -0800 (PST)
X-AuditID: 12074425-f798e6d000000d1a-35-54c2956af712
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-8.mit.edu (Symantec Messaging Gateway) with SMTP id 8C.28.03354.A6592C45; Fri, 23 Jan 2015 13:39:38 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id t0NIdb8C004569; Fri, 23 Jan 2015 13:39:38 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t0NIdafI012965 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Fri, 23 Jan 2015 13:39:37 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t0NIdZPM002358; Fri, 23 Jan 2015 13:39:35 -0500 (EST)
Date: Fri, 23 Jan 2015 13:39:35 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Bill Mills <wmills_92105@yahoo.com>
In-Reply-To: <922433422.304688.1422038075116.JavaMail.yahoo@mail.yahoo.com>
Message-ID: <alpine.GSO.1.10.1501231339050.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1501231313340.23489@multics.mit.edu> <922433422.304688.1422038075116.JavaMail.yahoo@mail.yahoo.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: MULTIPART/MIXED; BOUNDARY="-559023410-684339380-1422038375=:23489"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFprAKsWRmVeSWpSXmKPExsUixCmqrZs19VCIwYvTMhZHN69isfjWdZ3Z gcljyZKfTB6zZh1mCmCK4rJJSc3JLEst0rdL4Mr4ceora8Er5ooXXz4wNjDOYu5i5OSQEDCR WN+yhBXCFpO4cG89WxcjF4eQwGImiXt3zrNAOBsZJZbcPMUI4Rxikji0pgOsXUiggVHi2sMo EJtFQFtiy+Y/LCA2m4CKxMw3G4FGcXCICKhLNH/3BgkzA5nfzrxhBLGFBXQkth+byQRSwing LbH0jT1ImFfAUWLP/QaoI4Cm3/u+mA0kIQpUv3r/FBaIIkGJkzOfsEDMDJA49a6feQKj4Cwk qVlIUrOgVh/4dJERwtaWuH+zjW0BI8sqRtmU3Crd3MTMnOLUZN3i5MS8vNQiXQu93MwSvdSU 0k2MoMBmd1HdwTjhkNIhRgEORiUe3oYtB0OEWBPLiitzDzFKcjApifJq9B8KEeJLyk+pzEgs zogvKs1JLT7EKMHBrCTCm5EClONNSaysSi3Kh0lJc7AoifNu+sEXIiSQnliSmp2aWpBaBJOV 4eBQkuC1nQLUKFiUmp5akZaZU4KQZuLgBBnOAzTcAaSGt7ggMbc4Mx0if4pRl2NB+/6ZTEIs efl5qVLivNsnAxUJgBRllObBzYElpFeM4kBvCfOuAKniASYzuEmvgJYwAS0p2H4AZElJIkJK qoGxrJJNddVT7gI5DbNM1m2PXhm0zHD8czk/gu21sJLxBSbxeflnY/fJruoNqjT7YSB66/GX oKrYasGISWwmXH8T/bqWnFZY38B6IfeDd8r+APOFd0Krf5u27786hfXR63/PeH8dFuZsDHu+ R9dy8kYd6dwret/39OpezzhyyOROSesl/0z+STlKLMUZiYZazEXFiQArZPYdIwMAAA==
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/MqLg7mvfNAOQoLLPnUbhnIot1Wc>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] IETF 92 - Agenda items
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Jan 2015 18:39:53 -0000

  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

---559023410-684339380-1422038375=:23489
Content-Type: TEXT/PLAIN; charset=UTF-8
Content-Transfer-Encoding: QUOTED-PRINTABLE

On Fri, 23 Jan 2015, Bill Mills wrote:

> Nothing to do on OAUTH/SASL right? =C2=A0Waiting for shepherd writeup.

Yes, that one's just waiting on me.

-Ben
---559023410-684339380-1422038375=:23489--


From nobody Fri Jan 23 11:24:52 2015
Return-Path: <cantor.2@osu.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5F4E51ACECB for <kitten@ietfa.amsl.com>; Fri, 23 Jan 2015 11:24:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ECApqfife8mw for <kitten@ietfa.amsl.com>; Fri, 23 Jan 2015 11:24:30 -0800 (PST)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1bon0721.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc10::1:721]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4ACBE1ACEC9 for <kitten@ietf.org>; Fri, 23 Jan 2015 11:24:30 -0800 (PST)
Received: from BN1BFFO11FD010.protection.gbl (10.58.144.31) by BN1BFFO11HUB009.protection.gbl (10.58.144.156) with Microsoft SMTP Server (TLS) id 15.1.75.11; Fri, 23 Jan 2015 19:24:06 +0000
Received: from cio-tnc-pf08.osuad.osu.edu (164.107.81.222) by BN1BFFO11FD010.mail.protection.outlook.com (10.58.144.73) with Microsoft SMTP Server (TLS) id 15.1.75.11 via Frontend Transport; Fri, 23 Jan 2015 19:24:06 +0000
Received: from CIO-TNC-HT08.osuad.osu.edu (cio-tnc-ht08.osuad.osu.edu [164.107.81.177]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by cio-tnc-pf08.osuad.osu.edu (Postfix) with ESMTPS id D807E2E0035; Fri, 23 Jan 2015 14:24:05 -0500 (EST)
Received: from CIO-TNC-D2MBX02.osuad.osu.edu ([fe80::3960:dd86:ba2:ad26]) by CIO-TNC-HT08.osuad.osu.edu ([fe80::8431:784b:bd14:3d8%18]) with mapi id 14.03.0174.001; Fri, 23 Jan 2015 14:24:04 -0500
From: "Cantor, Scott" <cantor.2@osu.edu>
To: Benjamin Kaduk <kaduk@MIT.EDU>, Bill Mills <wmills_92105@yahoo.com>
Thread-Topic: [kitten] IETF 92 - Agenda items
Thread-Index: AQHQKqVibwLOciIAk0uZpWtoed8xM5zOb6SAgAAFW4CAAAFmgP//uJwA
Date: Fri, 23 Jan 2015 19:24:04 +0000
Message-ID: <1BC55B5B-8BFF-45E6-A2AB-49134C728585@osu.edu>
References: <alpine.GSO.1.10.1501231313340.23489@multics.mit.edu> <922433422.304688.1422038075116.JavaMail.yahoo@mail.yahoo.com> <alpine.GSO.1.10.1501231339050.23489@multics.mit.edu>
In-Reply-To: <alpine.GSO.1.10.1501231339050.23489@multics.mit.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [128.146.46.27]
Content-Type: text/plain; charset="utf-8"
Content-ID: <67F156AE6071CB4182C768D26E25CE1D@osu.edu>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-EOPAttributedMessage: 0
Received-SPF: Pass (protection.outlook.com: domain of osu.edu designates 164.107.81.222 as permitted sender) receiver=protection.outlook.com; client-ip=164.107.81.222; helo=cio-tnc-pf08.osuad.osu.edu;
Authentication-Results: spf=pass (sender IP is 164.107.81.222) smtp.mailfrom=cantor.2@osu.edu; ietf.org; dkim=none (message not signed) header.d=none;
X-Forefront-Antispam-Report: CIP:164.107.81.222; CTRY:US; IPV:NLI; EFV:NLI; SFV:NSPM; SFS:(10019020)(6009001)(47776003)(75432002)(86362001)(66066001)(2171001)(2656002)(46102003)(82746002)(6806004)(109096001)(558084003)(90282001)(76176999)(54356999)(50986999)(88552001)(23676002)(87936001)(106466001)(36756003)(106116001)(50466002)(83716003)(89122001)(92566002)(2900100001)(77156002)(2950100001)(62966003)(93346002)(33656002)(102836002)(2521001)(104396002); DIR:OUT; SFP:1102; SCL:1; SRVR:BN1BFFO11HUB009; H:cio-tnc-pf08.osuad.osu.edu;  FPR:; SPF:None; MLV:sfv; LANG:en; 
X-Microsoft-Antispam: UriScan:;
X-Microsoft-Antispam: BCL:0;PCL:0;RULEID:;SRVR:BN1BFFO11HUB009;
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(601004); SRVR:BN1BFFO11HUB009; 
X-Forefront-PRVS: 0465429B7F
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:; SRVR:BN1BFFO11HUB009; 
X-OriginatorOrg: osu.edu
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 23 Jan 2015 19:24:06.3472 (UTC)
X-MS-Exchange-CrossTenant-Id: b4d138ca-1815-4a9b-a3a7-130a33b1e692
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=b4d138ca-1815-4a9b-a3a7-130a33b1e692; Ip=[164.107.81.222]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN1BFFO11HUB009
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/EWmjn2h1rvZESHLbZZzSMLswU44>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] IETF 92 - Agenda items
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Jan 2015 19:24:32 -0000

TmV4dCBzdGVwcyBpbiBzYW1sLWVjLCBJIHRoaW5rLCB3aGljaCBJIGFzc3VtZSBpcyBqdXN0IGEg
cmVwZWF0IG9mIHRoZSANCndpZGVyIHJldmlldyBJIGdvdCBlYXJsaWVyIGxhc3QgeWVhciBzbyB3
ZSBjYW4gc3RhcnQgbG9va2luZyBhdCBXR0xDLg0KDQotLSBTY290dA0KDQoNCg0K


From nobody Fri Jan 23 11:27:40 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4928A1ACEDC for <kitten@ietfa.amsl.com>; Fri, 23 Jan 2015 11:27:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6b4kH0tcrhTd for <kitten@ietfa.amsl.com>; Fri, 23 Jan 2015 11:27:13 -0800 (PST)
Received: from dmz-mailsec-scanner-6.mit.edu (dmz-mailsec-scanner-6.mit.edu [18.7.68.35]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 773611ACF03 for <kitten@ietf.org>; Fri, 23 Jan 2015 11:26:57 -0800 (PST)
X-AuditID: 12074423-f797b6d000000cfe-7e-54c2a08070a2
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-6.mit.edu (Symantec Messaging Gateway) with SMTP id FF.F3.03326.080A2C45; Fri, 23 Jan 2015 14:26:56 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id t0NJQtK9010860; Fri, 23 Jan 2015 14:26:55 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t0NJQrhd029602 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Fri, 23 Jan 2015 14:26:55 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t0NJQrmc008386; Fri, 23 Jan 2015 14:26:53 -0500 (EST)
Date: Fri, 23 Jan 2015 14:26:53 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: "Cantor, Scott" <cantor.2@osu.edu>
In-Reply-To: <1BC55B5B-8BFF-45E6-A2AB-49134C728585@osu.edu>
Message-ID: <alpine.GSO.1.10.1501231426060.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1501231313340.23489@multics.mit.edu> <922433422.304688.1422038075116.JavaMail.yahoo@mail.yahoo.com> <alpine.GSO.1.10.1501231339050.23489@multics.mit.edu> <1BC55B5B-8BFF-45E6-A2AB-49134C728585@osu.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrJIsWRmVeSWpSXmKPExsUixCmqrduw4FCIwf7XghYtR8Qtjm5exeLA 5LFkyU8mj+ary9kDmKK4bFJSczLLUov07RK4Mk7Mu81YsJG5ouPtFNYGxtNMXYycHBICJhKt c2+xQNhiEhfurWfrYuTiEBJYzCQxbXEjO4SzkVFiyrwHjBDOISaJnf0fWSCcBkaJ3WuuAPVw cLAIaEucW6gHMopNQEVi5puNbCC2iICaxOoFb5lBbGYBdYlvZ94wgtjCAjoS24/NBDuDU8Ba Yu2KBrAaXgFHiedbH0BtfsoocX3vK3aQhChQw+r9U1ggigQlTs58wgIxVEti+fRtLBMYBWch Sc1CklrAyLSKUTYlt0o3NzEzpzg1Wbc4OTEvL7VI10wvN7NELzWldBMjKFTZXZR3MP45qHSI UYCDUYmHt2HLwRAh1sSy4srcQ4ySHExKorzn5hwKEeJLyk+pzEgszogvKs1JLT7EKMHBrCTC m5EClONNSaysSi3Kh0lJc7AoifNu+sEXIiSQnliSmp2aWpBaBJOV4eBQkuAVmw/UKFiUmp5a kZaZU4KQZuLgBBnOAzScB6SGt7ggMbc4Mx0if4pRl2NB+/6ZTEIsefl5qVLivHvnARUJgBRl lObBzYGlmFeM4kBvCfMag4ziAaYnuEmvgJYwAS0p2H4AZElJIkJKqoGx5v37I35xf/2M1ntM PyYjxb8+iGXJo8ecK1wt92/vTIpJ9GJ3krbykfH7YPhlckqINpd6yK7cMqaW76/v7Ct6f2iS YXvu3hfSxXdy9J5tnpIwv2ZSovXepaELfBoPfpbcVDshVlvYtIt1vpGYfZr8+Q1eL5hyX63p WK3aHJzSHSy3MM5eOkSJpTgj0VCLuag4EQDWHX4yDAMAAA==
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/0GTu033BKVZb-enH-GYFllKorhs>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] IETF 92 - Agenda items
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Jan 2015 19:27:17 -0000

On Fri, 23 Jan 2015, Cantor, Scott wrote:

> Next steps in saml-ec, I think, which I assume is just a repeat of the
> wider review I got earlier last year so we can start looking at WGLC.

Hi Scott,

Do you want a dedicated slot in the agenda to talk about it?  (Will you be
there in person?)

It sounds like this could probably just be covered in the "summary of WG
document status" portion of the chair slides.

-Ben


From nobody Sat Jan 24 09:46:59 2015
Return-Path: <cantor.2@osu.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 612791A034C for <kitten@ietfa.amsl.com>; Sat, 24 Jan 2015 09:46:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XLIWAfOrnVSU for <kitten@ietfa.amsl.com>; Sat, 24 Jan 2015 09:46:55 -0800 (PST)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2on0122.outbound.protection.outlook.com [65.55.169.122]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 96A5D1A0016 for <kitten@ietf.org>; Sat, 24 Jan 2015 09:46:54 -0800 (PST)
Received: from BY2FFO11FD011.protection.gbl (10.1.14.34) by BY2FFO11HUB055.protection.gbl (10.1.14.244) with Microsoft SMTP Server (TLS) id 15.1.75.11; Sat, 24 Jan 2015 17:46:52 +0000
Received: from cio-krc-pf07.osuad.osu.edu (164.107.81.214) by BY2FFO11FD011.mail.protection.outlook.com (10.1.14.129) with Microsoft SMTP Server (TLS) id 15.1.75.11 via Frontend Transport; Sat, 24 Jan 2015 17:46:52 +0000
Received: from CIO-TNC-HT06.osuad.osu.edu (cio-tnc-ht06.osuad.osu.edu [164.107.81.171]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by cio-krc-pf07.osuad.osu.edu (Postfix) with ESMTPS id 67BA2500066; Sat, 24 Jan 2015 12:46:51 -0500 (EST)
Received: from CIO-TNC-D2MBX02.osuad.osu.edu ([fe80::3960:dd86:ba2:ad26]) by CIO-TNC-HT06.osuad.osu.edu ([fe80::3d16:84bd:8d88:7cfd%12]) with mapi id 14.03.0174.001; Sat, 24 Jan 2015 12:46:50 -0500
From: "Cantor, Scott" <cantor.2@osu.edu>
To: Benjamin Kaduk <kaduk@MIT.EDU>
Thread-Topic: [kitten] IETF 92 - Agenda items
Thread-Index: AQHQKqVibwLOciIAk0uZpWtoed8xM5zOb6SAgAAFW4CAAAFmgP//uJwAgABUm4CAASIu4A==
Date: Sat, 24 Jan 2015 17:46:50 +0000
Message-ID: <9846A6064BD102419D06814DD0D78DE106EB90@CIO-TNC-D2MBX02.osuad.osu.edu>
References: <alpine.GSO.1.10.1501231313340.23489@multics.mit.edu> <922433422.304688.1422038075116.JavaMail.yahoo@mail.yahoo.com> <alpine.GSO.1.10.1501231339050.23489@multics.mit.edu> <1BC55B5B-8BFF-45E6-A2AB-49134C728585@osu.edu> <alpine.GSO.1.10.1501231426060.23489@multics.mit.edu>
In-Reply-To: <alpine.GSO.1.10.1501231426060.23489@multics.mit.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [65.31.0.111]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-EOPAttributedMessage: 0
Received-SPF: Pass (protection.outlook.com: domain of osu.edu designates 164.107.81.214 as permitted sender) receiver=protection.outlook.com; client-ip=164.107.81.214; helo=cio-krc-pf07.osuad.osu.edu;
Authentication-Results: spf=pass (sender IP is 164.107.81.214) smtp.mailfrom=cantor.2@osu.edu; ietf.org; dkim=none (message not signed) header.d=none;
X-Forefront-Antispam-Report: CIP:164.107.81.214; CTRY:US; IPV:NLI; EFV:NLI; SFV:NSPM; SFS:(10019020)(6009001)(2920100001)(2900100001)(66066001)(50986999)(46102003)(54356999)(2950100001)(87936001)(2171001)(33656002)(97756001)(86362001)(55846006)(2656002)(6806004)(23726002)(50466002)(93886004)(75432002)(102836002)(92566002)(106466001)(88552001)(93346002)(558084003)(47776003)(46406003)(62966003)(76176999)(106116001)(109096001)(77156002)(89122001); DIR:OUT; SFP:1102; SCL:1; SRVR:BY2FFO11HUB055; H:cio-krc-pf07.osuad.osu.edu; FPR:; SPF:None; MLV:sfv; LANG:en; 
X-Microsoft-Antispam: UriScan:;
X-Microsoft-Antispam: BCL:0;PCL:0;RULEID:;SRVR:BY2FFO11HUB055;
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(601004); SRVR:BY2FFO11HUB055; 
X-Forefront-PRVS: 0466CA5A45
X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:;SRVR:BY2FFO11HUB055;
X-OriginatorOrg: osu.edu
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 24 Jan 2015 17:46:52.2963 (UTC)
X-MS-Exchange-CrossTenant-Id: b4d138ca-1815-4a9b-a3a7-130a33b1e692
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=b4d138ca-1815-4a9b-a3a7-130a33b1e692; Ip=[164.107.81.214]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY2FFO11HUB055
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/JSFte696XIkRxLrC0Xr8FzGb8dM>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] IETF 92 - Agenda items
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 24 Jan 2015 17:46:56 -0000

> Do you want a dedicated slot in the agenda to talk about it?  (Will you b=
e
> there in person?)

I don't expect to be. I don't have anything specific to say, no.

> It sounds like this could probably just be covered in the "summary of WG
> document status" portion of the chair slides.

It can.=20

-- Scott


From nobody Sat Jan 24 16:15:58 2015
Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 750911A1BC8 for <kitten@ietfa.amsl.com>; Sat, 24 Jan 2015 16:15:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level: 
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aX_PGH8l6WTU for <kitten@ietfa.amsl.com>; Sat, 24 Jan 2015 16:15:51 -0800 (PST)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E5DCA1A1BC3 for <kitten@ietf.org>; Sat, 24 Jan 2015 16:15:49 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id 3648EBEE4; Sun, 25 Jan 2015 00:15:47 +0000 (GMT)
X-Virus-Scanned: Debian amavisd-new at scss.tcd.ie
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lSXP3kI8xgZk; Sun, 25 Jan 2015 00:15:45 +0000 (GMT)
Received: from [10.87.48.73] (unknown [86.42.27.85]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id ABFA6BED1; Sun, 25 Jan 2015 00:15:45 +0000 (GMT)
Message-ID: <54C435B0.7020801@cs.tcd.ie>
Date: Sun, 25 Jan 2015 00:15:44 +0000
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.4.0
MIME-Version: 1.0
To: Benjamin Kaduk <kaduk@MIT.EDU>, kitten@ietf.org
References: <20150104223051.25758.7861.idtracker@ietfa.amsl.com> <alpine.GSO.1.10.1501041731160.23489@multics.mit.edu>
In-Reply-To: <alpine.GSO.1.10.1501041731160.23489@multics.mit.edu>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/a6XdR-A_RlVLbAudfkEhAr-l_AI>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-gss-loop-04.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 25 Jan 2015 00:15:54 -0000

Folks,

A bit slowly (sorry) but I've requested IETC LC for this
one. Looks like a useful doc.

Cheers,
S.


On 04/01/15 22:31, Benjamin Kaduk wrote:
> On Sun, 4 Jan 2015, internet-drafts@ietf.org wrote:
> 
>>
>> A New Internet-Draft is available from the on-line Internet-Drafts directories.
>>  This draft is a work item of the Common Authentication Technology Next Generation Working Group of the IETF.
>>
>>         Title           : Structure of the GSS Negotiation Loop
>>         Author          : Benjamin Kaduk
>> 	Filename        : draft-ietf-kitten-gss-loop-04.txt
>> 	Pages           : 20
>> 	Date            : 2015-01-04
>>
>> Abstract:
>>    This document specifies the generic structure of the negotiation loop
>>    to establish a GSS security context between initiator and acceptor.
>>    The control flow of the loop is indicated for both parties, including
>>    error conditions, and indications are given for where application-
>>    specific behavior must be specified.
>>
>>
>> There's also a htmlized version available at:
>> http://tools.ietf.org/html/draft-ietf-kitten-gss-loop-04
>>
>> A diff from the previous version is available at:
>> http://www.ietf.org/rfcdiff?url2=draft-ietf-kitten-gss-loop-04
> 
> This is just a few more nits found during shepherd review, that I missed
> fixing in the -03.
> 
> -Ben
> 
> _______________________________________________
> Kitten mailing list
> Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten
> 


From nobody Mon Jan 26 06:34:05 2015
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 963711A8955; Mon, 26 Jan 2015 06:34:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.9
X-Spam-Level: 
X-Spam-Status: No, score=-101.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, USER_IN_WHITELIST=-100] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mFd3QMSDJ39U; Mon, 26 Jan 2015 06:34:02 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 6169D1A883D; Mon, 26 Jan 2015 06:34:02 -0800 (PST)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 5.10.1
Auto-Submitted: auto-generated
Precedence: bulk
Sender: <iesg-secretary@ietf.org>
Message-ID: <20150126143402.29738.32769.idtracker@ietfa.amsl.com>
Date: Mon, 26 Jan 2015 06:34:02 -0800
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/M5IMA4GBqJXnhpCLHJ94AfLfm0s>
Cc: kitten@ietf.org
Subject: [kitten] Last Call: <draft-ietf-kitten-gss-loop-04.txt> (Structure of the GSS Negotiation Loop) to Informational RFC
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Reply-To: ietf@ietf.org
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 Jan 2015 14:34:03 -0000

The IESG has received a request from the Common Authentication Technology
Next Generation WG (kitten) to consider the following document:
- 'Structure of the GSS Negotiation Loop'
  <draft-ietf-kitten-gss-loop-04.txt> as Informational RFC

The IESG plans to make a decision in the next few weeks, and solicits
final comments on this action. Please send substantive comments to the
ietf@ietf.org mailing lists by 2015-02-09. Exceptionally, comments may be
sent to iesg@ietf.org instead. In either case, please retain the
beginning of the Subject line to allow automated sorting.

Abstract


   This document specifies the generic structure of the negotiation loop
   to establish a GSS security context between initiator and acceptor.
   The control flow of the loop is indicated for both parties, including
   error conditions, and indications are given for where application-
   specific behavior must be specified.




The file can be obtained via
http://datatracker.ietf.org/doc/draft-ietf-kitten-gss-loop/

IESG discussion can be tracked via
http://datatracker.ietf.org/doc/draft-ietf-kitten-gss-loop/ballot/


No IPR declarations have been submitted directly on this I-D.



From nobody Tue Jan 27 08:55:46 2015
Return-Path: <michikos@microsoft.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 10C791A6EF9 for <kitten@ietfa.amsl.com>; Tue, 27 Jan 2015 08:55:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MKaLor152Rwy for <kitten@ietfa.amsl.com>; Tue, 27 Jan 2015 08:55:43 -0800 (PST)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2on0104.outbound.protection.outlook.com [65.55.169.104]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 984771A6EF2 for <kitten@ietf.org>; Tue, 27 Jan 2015 08:55:43 -0800 (PST)
Received: from BL2PR03MB212.namprd03.prod.outlook.com (10.255.230.151) by BL2PR03MB210.namprd03.prod.outlook.com (10.255.230.144) with Microsoft SMTP Server (TLS) id 15.1.65.19; Tue, 27 Jan 2015 16:55:42 +0000
Received: from BL2PR03MB212.namprd03.prod.outlook.com ([169.254.15.45]) by BL2PR03MB212.namprd03.prod.outlook.com ([169.254.15.45]) with mapi id 15.01.0065.013; Tue, 27 Jan 2015 16:55:42 +0000
From: Michiko Short <michikos@microsoft.com>
To: "kitten@ietf.org" <kitten@ietf.org>
Thread-Topic: IETF 92 - Agenda items 
Thread-Index: AdA6UhTTKsgF7dTTQtOXubAW2M1GrA==
Date: Tue, 27 Jan 2015 16:55:42 +0000
Message-ID: <BL2PR03MB2127F1DB2A392B94992734BD0320@BL2PR03MB212.namprd03.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [2001:4898:80e8:ed31::3]
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=microsoft.com;
x-dmarcaction-test: None
x-microsoft-antispam: BCL:0;PCL:0;RULEID:(3005004);SRVR:BL2PR03MB210;
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0;PCL:0;RULEID:;SRVR:BL2PR03MB210;
x-forefront-prvs: 046985391D
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(51704005)(164054003)(53754006)(13464003)(24454002)(46102003)(99286002)(107886001)(2351001)(86362001)(122556002)(74316001)(2501002)(86612001)(19580405001)(87936001)(19580395003)(54206007)(54606007)(54356999)(50986999)(2656002)(33656002)(110136001)(62966003)(77156002)(40100003)(92566002)(450100001)(102836002)(76576001)(2900100001)(3826002); DIR:OUT; SFP:1102; SCL:1; SRVR:BL2PR03MB210; H:BL2PR03MB212.namprd03.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en; 
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.onmicrosoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 27 Jan 2015 16:55:42.0912 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL2PR03MB210
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/eAGWVxuraWMjmoVV02HT-m4owcU>
Subject: Re: [kitten] IETF 92 - Agenda items
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 Jan 2015 16:55:45 -0000

Should we plan to discuss the freshness token draft?

-----Original Message-----
Message: 2
Date: Fri, 23 Jan 2015 13:15:25 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
Subject: Re: [kitten] IETF 92 - Agenda items
Message-ID: <alpine.GSO.1.10.1501231313340.23489@multics.mit.edu>
Content-Type: TEXT/PLAIN; charset=3DUS-ASCII

On Wed, 7 Jan 2015, Benjamin Kaduk wrote:

> Hi all,
>
> IETF 92 is March 22-27 in Dallas.  Please provide any agenda items for=20
> a Dallas session, either to the list or to the co-chairs, no later=20
> than Tuesday, January 20, 2015.

I forgot to send a reminder before the deadline.  Luckily, there is still s=
ome time for submitting agenda items.

We plan to submit the agenda to the datatracker early next week, so please =
try to get items in by Monday.  They don't need to be long -- a topic name =
or draft title and an estimate for the time needed should be sufficient at =
this point.

Thanks,

Ben


From nobody Wed Jan 28 09:05:45 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 592B11A8782 for <kitten@ietfa.amsl.com>; Wed, 28 Jan 2015 09:05:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id S3bCsoZlsZQp for <kitten@ietfa.amsl.com>; Wed, 28 Jan 2015 09:05:36 -0800 (PST)
Received: from dmz-mailsec-scanner-5.mit.edu (dmz-mailsec-scanner-5.mit.edu [18.7.68.34]) by ietfa.amsl.com (Postfix) with ESMTP id B8A551A8798 for <kitten@ietf.org>; Wed, 28 Jan 2015 09:05:34 -0800 (PST)
X-AuditID: 12074422-f79476d000000d9e-41-54c916dd3949
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-5.mit.edu (Symantec Messaging Gateway) with SMTP id D7.B8.03486.DD619C45; Wed, 28 Jan 2015 12:05:33 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id t0SH5XAu022958; Wed, 28 Jan 2015 12:05:33 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t0SH5VMs001827 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 28 Jan 2015 12:05:32 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t0SH5Ttb001604; Wed, 28 Jan 2015 12:05:29 -0500 (EST)
Date: Wed, 28 Jan 2015 12:05:29 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Michiko Short <michikos@microsoft.com>
In-Reply-To: <BL2PR03MB2127F1DB2A392B94992734BD0320@BL2PR03MB212.namprd03.prod.outlook.com>
Message-ID: <alpine.GSO.1.10.1501281204500.23489@multics.mit.edu>
References: <BL2PR03MB2127F1DB2A392B94992734BD0320@BL2PR03MB212.namprd03.prod.outlook.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrJIsWRmVeSWpSXmKPExsUixCmqrXtX7GSIwZFPNhZHN69isfjXzefA 5LFkyU8mj9Ydf9kDmKK4bFJSczLLUov07RK4MpofPmUv6GWqWLnxFUsD40XGLkZODgkBE4nT D3eyQthiEhfurWfrYuTiEBJYzCTxcM9CZghnI6PE03tnWCGcQ0wSa+d/gyprYJR4Nmk3O0g/ i4C2xO3JK5hBbDYBFYmZbzaygdgiAloSHy6cZgGxmQXUJb6deQO2W1hAR2L7sZlMIDanQLTE jS/zwWp4BRwldpzZD2YLCURJNPy/AlYvClS/ev8UqBpBiZMzn0DN1JJYPn0bywRGwVlIUrOQ pBYwMq1ilE3JrdLNTczMKU5N1i1OTszLSy3SNdXLzSzRS00p3cQIClV2F6UdjD8PKh1iFOBg VOLhfWF2IkSINbGsuDL3EKMkB5OSKC+7yMkQIb6k/JTKjMTijPii0pzU4kOMEhzMSiK8/SxA Od6UxMqq1KJ8mJQ0B4uSOO+mH3whQgLpiSWp2ampBalFMFkZDg4lCd4dokCNgkWp6akVaZk5 JQhpJg5OkOE8QMOLQWp4iwsSc4sz0yHypxh1ORa075/JJMSSl5+XKiXO6w9SJABSlFGaBzcH lmJeMYoDvSXMOw+kigeYnuAmvQJawgS0JHDxCZAlJYkIKakGxl41qZp91WvbDmzQbPi/RuGS rcsmh+T/DU8ktrGoWa+VNhHaeN70cthDt41fxLy3Hw7cduywXbyBVntdxCTbG1nKGdVHFA4F bJQ0/isesvDhVfZ03db7QpsNLpmlKQg/MXOb9Vlx/lFjg2kVJh3JvE++PrE9vTdEftVj6Vnf gh4pH+M7HezRqcRSnJFoqMVcVJwIAPCnq9EMAwAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/G-7QTaQ-KO8eedN0tdKQ_q5xgz8>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] IETF 92 - Agenda items
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 Jan 2015 17:05:42 -0000

On Tue, 27 Jan 2015, Michiko Short wrote:

> Should we plan to discuss the freshness token draft?

I think it will be enough to cover it in the chair slides' "document
status" section, unless there are issues brought up on the list between
now and then.

-Ben


From nobody Wed Jan 28 12:27:03 2015
Return-Path: <michikos@microsoft.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 051AC1A0195 for <kitten@ietfa.amsl.com>; Wed, 28 Jan 2015 12:27:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HZ2zDV1Cjkyf for <kitten@ietfa.amsl.com>; Wed, 28 Jan 2015 12:26:58 -0800 (PST)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1on0785.outbound.protection.outlook.com [IPv6:2a01:111:f400:fc10::785]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A5EDD1A0174 for <kitten@ietf.org>; Wed, 28 Jan 2015 12:26:58 -0800 (PST)
Received: from BL2PR03MB212.namprd03.prod.outlook.com (10.255.230.151) by BL2PR03MB212.namprd03.prod.outlook.com (10.255.230.151) with Microsoft SMTP Server (TLS) id 15.1.65.19; Wed, 28 Jan 2015 20:26:35 +0000
Received: from BL2PR03MB212.namprd03.prod.outlook.com ([169.254.15.5]) by BL2PR03MB212.namprd03.prod.outlook.com ([169.254.15.5]) with mapi id 15.01.0065.013; Wed, 28 Jan 2015 20:26:35 +0000
From: Michiko Short <michikos@microsoft.com>
To: Benjamin Kaduk <kaduk@MIT.EDU>
Thread-Topic: [kitten] IETF 92 - Agenda items
Thread-Index: AQHQOxyimLN/BgupokqXMGnhEih/nZzV+xmw
Date: Wed, 28 Jan 2015 20:26:35 +0000
Message-ID: <BL2PR03MB2125644223ABFFE198AE093D0330@BL2PR03MB212.namprd03.prod.outlook.com>
References: <BL2PR03MB2127F1DB2A392B94992734BD0320@BL2PR03MB212.namprd03.prod.outlook.com> <alpine.GSO.1.10.1501281204500.23489@multics.mit.edu>
In-Reply-To: <alpine.GSO.1.10.1501281204500.23489@multics.mit.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [2001:4898:80e8:ed31::2]
authentication-results: MIT.EDU; dkim=none (message not signed) header.d=none;MIT.EDU; dmarc=none action=none header.from=microsoft.com;
x-dmarcaction-test: None
x-microsoft-antispam: BCL:0;PCL:0;RULEID:(3005004);SRVR:BL2PR03MB212;
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0;PCL:0;RULEID:;SRVR:BL2PR03MB212;
x-forefront-prvs: 047001DADA
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(41574002)(377454003)(13464003)(24454002)(2900100001)(19580395003)(40100003)(33656002)(2950100001)(54356999)(76176999)(19580405001)(50986999)(2171001)(2656002)(87936001)(122556002)(92566002)(54606007)(99286002)(54206007)(77156002)(62966003)(86362001)(102836002)(76576001)(106116001)(74316001)(86612001)(46102003); DIR:OUT; SFP:1102; SCL:1; SRVR:BL2PR03MB212; H:BL2PR03MB212.namprd03.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en; 
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.onmicrosoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 Jan 2015 20:26:35.3485 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL2PR03MB212
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/0S90FUmXIHklrJKf1KghOQOdea0>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] IETF 92 - Agenda items
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 Jan 2015 20:27:02 -0000

That works for me. Thanks!

-Mich

-----Original Message-----
From: Benjamin Kaduk [mailto:kaduk@MIT.EDU]=20
Sent: Wednesday, January 28, 2015 9:05 AM
To: Michiko Short
Cc: kitten@ietf.org
Subject: Re: [kitten] IETF 92 - Agenda items

On Tue, 27 Jan 2015, Michiko Short wrote:

> Should we plan to discuss the freshness token draft?

I think it will be enough to cover it in the chair slides' "document status=
" section, unless there are issues brought up on the list between now and t=
hen.

-Ben


From nobody Thu Jan 29 14:14:06 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 754901A887F for <kitten@ietfa.amsl.com>; Thu, 29 Jan 2015 14:14:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U1RdTAvTpwuS for <kitten@ietfa.amsl.com>; Thu, 29 Jan 2015 14:14:03 -0800 (PST)
Received: from dmz-mailsec-scanner-8.mit.edu (dmz-mailsec-scanner-8.mit.edu [18.7.68.37]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3B4441A039C for <kitten@ietf.org>; Thu, 29 Jan 2015 14:14:03 -0800 (PST)
X-AuditID: 12074425-f798e6d000000d1a-b0-54cab0a95dcb
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-8.mit.edu (Symantec Messaging Gateway) with SMTP id 76.52.03354.AA0BAC45; Thu, 29 Jan 2015 17:14:02 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id t0TME1Mj016746 for <kitten@ietf.org>; Thu, 29 Jan 2015 17:14:01 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t0TMDxVf007627 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Thu, 29 Jan 2015 17:14:01 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t0TMDxZE028263; Thu, 29 Jan 2015 17:13:59 -0500 (EST)
Date: Thu, 29 Jan 2015 17:13:59 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
In-Reply-To: <20150123003504.3896.40306.idtracker@ietfa.amsl.com>
Message-ID: <alpine.GSO.1.10.1501291713230.23489@multics.mit.edu>
References: <20150123003504.3896.40306.idtracker@ietfa.amsl.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrKIsWRmVeSWpSXmKPExsUixCmqrLtqw6kQgzUrmS2Obl7F4sDosWTJ T6YAxigum5TUnMyy1CJ9uwSujEs9O1gLTnBVTG6cwNzA+JK9i5GDQ0LARGJyh3YXIyeQKSZx 4d56ti5GLg4hgcVMEhsvtkA5xxklXtxYxA7h3GCSONF9jBGkRUiggVFiznQmEJtFQFti169L zCA2m4CKxMw3G9lAbBEBYYndW9+BxYUFvCU6D10Hq+cUcJRo/LGZCeQKXiB77iwPiJEOEn8X vAErFxXQkVi9fwoLiM0rIChxcuYTMJtZQEti+fRtLBMYBWYhSc1CklrAyLSKUTYlt0o3NzEz pzg1Wbc4OTEvL7VI10IvN7NELzWldBMjKPTYXVR3ME44pHSIUYCDUYmHN6HxZIgQa2JZcWXu IUZJDiYlUd6Na0+FCPEl5adUZiQWZ8QXleakFh9ilOBgVhLhVV0ElONNSaysSi3Kh0lJc7Ao ifNu+sEXIiSQnliSmp2aWpBaBJOV4eBQkuCdux6oUbAoNT21Ii0zpwQhzcTBCTKcB2j4DpAa 3uKCxNzizHSI/ClGRSlxXieQhABIIqM0D64XlhpeMYoDvSLMywVMFEI8wLQC1/0KaDAT0ODA xSdABpckIqSkGhg5PyooTD3mvyz81PIdN/xuHlk9/+E7ue8FKS01sy4sLBM7c2xVyyzp3smP D9wtYzqRMtVJUizv565iU6NgpTquci01388uqWuO1vcqHCv2q54zwflLe5JW3bNny5q31GSa HMpweiNl7fu5sX+JzK+stfwHzkouKEld9dIs4RxfTeoC+Sv3ZpxRYinOSDTUYi4qTgQAT5dX 1OgCAAA=
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/5HzdzaCzxdoEE64XRY-CcX7sKh8>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-pkinit-freshness-00.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Jan 2015 22:14:05 -0000

On Thu, 22 Jan 2015, internet-drafts@ietf.org wrote:

>
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
>  This draft is a work item of the Common Authentication Technology Next Generation Working Group of the IETF.
>
>         Title           : Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) Freshness Extension
>         Authors         : Michiko Short
>                           Seth Moore
>                           Paul Miller
> 	Filename        : draft-ietf-kitten-pkinit-freshness-00.txt
> 	Pages           : 8
> 	Date            : 2015-01-22
>
> Abstract:
>    This document describes how to further extend the Public Key
>    Cryptography for Initial Authentication in Kerberos (PKINIT)
>    extension [RFC4556] to exchange an opaque data blob which a KDC can
>    validate to ensure that the client is currently in possession of the
>    private key during a PKInit AS exchange.
>
>
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-kitten-pkinit-freshness/
>
> There's also a htmlized version available at:
> http://tools.ietf.org/html/draft-ietf-kitten-pkinit-freshness-00


I think these updates look good.  If no other comments come in, we should
probably add this to the queue for WGLC.

-Ben


From nobody Thu Jan 29 14:15:54 2015
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8F5331A8884 for <kitten@ietfa.amsl.com>; Thu, 29 Jan 2015 14:15:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ENKICvhBt_Mu for <kitten@ietfa.amsl.com>; Thu, 29 Jan 2015 14:15:49 -0800 (PST)
Received: from dmz-mailsec-scanner-1.mit.edu (dmz-mailsec-scanner-1.mit.edu [18.9.25.12]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2FE2A1A8883 for <kitten@ietf.org>; Thu, 29 Jan 2015 14:15:49 -0800 (PST)
X-AuditID: 1209190c-f79e46d000000eb2-c2-54cab114a496
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-1.mit.edu (Symantec Messaging Gateway) with SMTP id B4.04.03762.411BAC45; Thu, 29 Jan 2015 17:15:48 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id t0TMFlh2003514 for <kitten@ietf.org>; Thu, 29 Jan 2015 17:15:47 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t0TMFjgw008179 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Thu, 29 Jan 2015 17:15:47 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t0TMFjGw028489; Thu, 29 Jan 2015 17:15:45 -0500 (EST)
Date: Thu, 29 Jan 2015 17:15:45 -0500 (EST)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
In-Reply-To: <alpine.GSO.1.10.1501201753140.23489@multics.mit.edu>
Message-ID: <alpine.GSO.1.10.1501291715220.23489@multics.mit.edu>
References: <alpine.GSO.1.10.1501201753140.23489@multics.mit.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrOIsWRmVeSWpSXmKPExsUixG6noiuy8VSIwawz3BZHN69icWD0WLLk J1MAYxSXTUpqTmZZapG+XQJXxqr37AXH+SqO7O1gbmCczNPFyMkhIWAiseXUdxYIW0ziwr31 bCC2kMBiJonGlRJdjFxA9nFGiZ4vLUwQzg0miYYfexghnAZGiT877jODtLAIaEvM+/mMCcRm E1CRmPlmI9goEQFhid1b3zGDNAgLzGSU6DzTDFbEKeAk0fesEayIV8BRYlnzVhaI3Y4S0y5t YwexRQV0JFbvn8ICUSMocXLmEzCbWUBLYvn0bSwTGAVmIUnNQpJawMi0ilE2JbdKNzcxM6c4 NVm3ODkxLy+1SNdQLzezRC81pXQTIyj8OCV5djC+Oah0iFGAg1GJhzeh8WSIEGtiWXFl7iFG SQ4mJVHejWtPhQjxJeWnVGYkFmfEF5XmpBYfYpTgYFYS4VVdBJTjTUmsrEotyodJSXOwKInz bvrBFyIkkJ5YkpqdmlqQWgSTleHgUJLgtV4P1ChYlJqeWpGWmVOCkGbi4AQZzgM0vGMdyPDi gsTc4sx0iPwpRkUpcd5/IM0CIImM0jy4Xlh6eMUoDvSKMO8kkCoeYGqB634FNJgJaHDg4hMg g0sSEVJSDYzSy58tlvGcz+nVZPXbMnPNhc1v5HY837D0ZEnIBaPKepEi1nlrlm6VX5QYNeFb o+Gr743nwmsjinpuLpR1ifC88uZT99oplttfhH+dlHNvvWjvXi5RyXqnk8m3sgy8bvOZe0UJ hy6b4743SWj5/ZBlWl9f/BX2nzLxZMHOJdOtq6Z1qx3aaOOrxFKckWioxVxUnAgA95bRNOoC AAA=
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/5Ubpzj-0D2BdtSkqXHDn0fl0jHM>
Subject: Re: [kitten] WGLC for three "bis" documents: draft-ietf-kitten-rfc4402bis-00, draft-ietf-kitten-rfc5653bis-01, draft-ietf-kitten-rfc6112bis-00
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Jan 2015 22:15:51 -0000

Just under three weeks remain in this WGLC period.

-Ben

On Tue, 20 Jan 2015, Benjamin Kaduk wrote:

> This message begins the Working Group Last Call (WGLC) for the following
> three documents: "A Pseudo-Random Function (PRF) for the Kerberos V
> Generic Security Service Application Program Interface (GSS-API)
> Mechanism" <draft-ietf-kitten-rfc4402bis-00>, "Generic Security Service
> API Version 2: Java Bindings Update" <draft-ietf-kitten-rfc5653bis-01>,
> and "Anonymity Support for Kerberos" <draft-ietf-kitten-rfc6112bis-00>.
> Because there are three documents under review, and the whole body of the
> documents are up for re-review (not just the updates), the WGLC is
> extended to four weeks, so the WGLC will end on Tuesday February 17th,
> 2015.  The drafts are available at:
>
> http://tools.ietf.org/html/draft-ietf-kitten-rfc4402bis-00
> http://tools.ietf.org/html/draft-ietf-kitten-rfc5653bis-01
> http://tools.ietf.org/html/draft-ietf-kitten-rfc6112bis-00
>
> Please review these documents and send comments to the Working Group
> mailing list kitten@ietf.org or the co-chairs
> <kitten-chairs@tools.ietf.org> before the end of the WGLC.  Any and all
> comments on the document(s) are sought in order to assess the strength of
> consensus.  Even if you have read and commented on this or earlier
> versions of the draft, please feel free to comment again.  This is
> particularly important if you found issues with the previous version.
>
> As a reminder, comments can be anything from "this looks fine" to "this is
> a horrible idea"; they can include suggestions for minor editorial
> corrections to significant editorial changes.
>
>
> - Your Kitten Chairs
>
> _______________________________________________
> Kitten mailing list
> Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten
>

