
From nobody Tue Aug  2 09:25:27 2016
Return-Path: <ghudson@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE36212D0E8 for <kitten@ietfa.amsl.com>; Tue,  2 Aug 2016 09:25:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.508
X-Spam-Level: 
X-Spam-Status: No, score=-5.508 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-1.287, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yuvTxKnLrk5J for <kitten@ietfa.amsl.com>; Tue,  2 Aug 2016 09:25:23 -0700 (PDT)
Received: from dmz-mailsec-scanner-5.mit.edu (dmz-mailsec-scanner-5.mit.edu [18.7.68.34]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1BB6512D0C7 for <kitten@ietf.org>; Tue,  2 Aug 2016 09:25:23 -0700 (PDT)
X-AuditID: 12074422-adfff70000001f37-4b-57a0c971e9c6
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id 47.72.07991.179C0A75; Tue,  2 Aug 2016 12:25:22 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id u72GPLlZ008654 for <kitten@ietf.org>; Tue, 2 Aug 2016 12:25:21 -0400
Received: from [18.101.8.153] (vpn-18-101-8-153.mit.edu [18.101.8.153]) (authenticated bits=0) (User authenticated as ghudson@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id u72GPKGl005703 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT) for <kitten@ietf.org>; Tue, 2 Aug 2016 12:25:21 -0400
References: <20160726193833.30872.31544.idtracker@ietfa.amsl.com>
To: kitten@ietf.org
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <57A0C96F.3010606@mit.edu>
Date: Tue, 2 Aug 2016 12:25:19 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.8.0
MIME-Version: 1.0
In-Reply-To: <20160726193833.30872.31544.idtracker@ietfa.amsl.com>
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrGIsWRmVeSWpSXmKPExsUixCmqrVt0ckG4way/bBZHN69icWD0WLLk J1MAYxSXTUpqTmZZapG+XQJXxvnrNxkLTglWrDx/h7GB8RpvFyMHh4SAiUTDw+QuRi4OIYE2 JokLv88xQjjHGCUmnfnIBuHcZJKY1TWJvYuRk0NYwFXi0/V+MFtIwFFi0tOHzCC2iICwxO6t 78BsNgFlifX7t7KA2LwCahLXVv9kBbFZBFQkpn1uBasRFYiQmLX9BxNEjaDEyZlPwOo5BZwk pi3pYgOxmQX0JHZc/8UKYctLbH87h3kCI/8sJC2zkJTNQlK2gJF5FaNsSm6Vbm5iZk5xarJu cXJiXl5qka6pXm5miV5qSukmRlDwsbso7WCc+M/rEKMAB6MSD29g7vxwIdbEsuLK3EOMkhxM SqK8dYcWhAvxJeWnVGYkFmfEF5XmpBYfYpTgYFYS4Y3aC5TjTUmsrEotyodJSXOwKInzbv/W Hi4kkJ5YkpqdmlqQWgSTleHgUJLgdToB1ChYlJqeWpGWmVOCkGbi4AQZzgM0vBSkhre4IDG3 ODMdIn+KUVFKnFcHJCEAksgozYPrBSeHVI6ZrxjFgV4R5l0JUsUDTCxw3a+ABjMBDT5hADa4 JBEhJdXA2Nxy8aZCwKHK7Iucia07/xUWqG6cwuWwwlPVpvgHS8IysS67w//UjRcIfrcqe3Vw 1wMpxc3rmb3+eGVs9MqafCpjTvDsmi2zmi746orLOdudWflvabahuRtj1KXkyG5vyec96vGa xxvKymbvv828y0EkReebeUhmOadO+g61tX9llzj8jdVUYinOSDTUYi4qTgQA5Q9T2ekCAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/K8pJjlq-n4CI0ISLSXVni21vqJs>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-rfc6112bis-01.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Aug 2016 16:25:25 -0000

On 07/26/2016 03:38 PM, internet-drafts@ietf.org wrote:
> 	Filename        : draft-ietf-kitten-rfc6112bis-01.txt

This revision appears to be editorial, and would be unlikely to affect
an implementation.  I do not have any substantive protocol concerns, but
I do have some minor issues with some of the new wording.

In section 7, "To ensure that an attacker cannot create a channel with a
given name" was changed to "To ensure that an attacker cannot create a
channel by observing exchanges."  The original wording may have used
"name" in a non-intuitive way, but I think the new wording is more
wrong.  The threat is that a MITM attacker might create two channels
with the same ticket session key (known to the attacker); the new
wording suggests that the threat comes from a passive attacker.

In this text:

    Such authorization data, if included in the anonymous ticket, would
    disclose the that the client is a member of the group observed.	

After the changes, there is an extra "the" before "that".

In this new block of text:

    This protocol provides a binding between the party which
    generated the session key and the DH exchange used to generate
    they reply key.  Hypothetically, if the KDC did not use
    PA-PKINIT-KX, the client and KDC would perfrom a DH key
    exchange to determine a shared key, and that key would be used
    as a reply key.  The KDC would then generate a ticket with a
    session key encrypting the reply with the DH agreement.  A MITM
    attacker would just decrypt the session key + ticket using the
    DH key from the attacker and KDC DH exchange, and re-encrypt it
    using the key from the attacker and client DH exchange, while
    keeping a copy of the session key and ticket.  By requiring the
    session key in a way that can be verified by the client, this
    protocol binds the ticket to the DH exchange and prevents the
    MITM attack.

"perfrom" should be "perform".  "session key + ticket" should be
"session key and ticket".  It might be clearer to say "attacker-KDC DH
exchange" than "attacker and KDC DH exchange", and similarly
"attacker-client DH exchange".

"By requiring the session key in a way that..." is not grammatical.


From nobody Tue Aug  9 08:47:07 2016
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5B63812B04F for <kitten@ietfa.amsl.com>; Tue,  9 Aug 2016 08:47:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.448
X-Spam-Level: 
X-Spam-Status: No, score=-5.448 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-1.247, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2OBl9CJwDQkJ for <kitten@ietfa.amsl.com>; Tue,  9 Aug 2016 08:47:05 -0700 (PDT)
Received: from dmz-mailsec-scanner-6.mit.edu (dmz-mailsec-scanner-6.mit.edu [18.7.68.35]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1298212D13A for <kitten@ietf.org>; Tue,  9 Aug 2016 08:47:03 -0700 (PDT)
X-AuditID: 12074423-793ff700000019a7-0f-57a9faf6a8dc
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id AF.3B.06567.6FAF9A75; Tue,  9 Aug 2016 11:47:02 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id u79Fl1Jn023948 for <kitten@ietf.org>; Tue, 9 Aug 2016 11:47:02 -0400
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id u79FkwjH007745 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Tue, 9 Aug 2016 11:47:01 -0400
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id u79Fkw9L018340; Tue, 9 Aug 2016 11:46:58 -0400 (EDT)
Date: Tue, 9 Aug 2016 11:46:58 -0400 (EDT)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
Message-ID: <alpine.GSO.1.10.1608091142540.5272@multics.mit.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrHIsWRmVeSWpSXmKPExsUixCmqrfvt18pwg49n9CyObl7F4sDosWTJ T6YAxigum5TUnMyy1CJ9uwSujLX/NjMXXGauWPFhJUsD4wemLkZODgkBE4nnJ28xdzFycQgJ tDFJrLs6nw3COcYo8WbtZCjnOpPE64f7mEFahATqJX70nmMHsVkEtCTeNG9iBLHZBFQkZr7Z yAZiiwgIS+ze+g6sXljAUWLy/i1A6zg4eAUcJCZ1coCERQV0JFbvn8ICYvMKCEqcnPkEzGYG Grl8+jaWCYy8s5CkZiFJLWBkWsUom5JbpZubmJlTnJqsW5ycmJeXWqRrppebWaKXmlK6iREU NOwuyjsYX/Z5H2IU4GBU4uG9sHxFuBBrYllxZe4hRkkOJiVR3n8HVoYL8SXlp1RmJBZnxBeV 5qQWH2KU4GBWEuG9+h0ox5uSWFmVWpQPk5LmYFES593+rT1cSCA9sSQ1OzW1ILUIJivDwaEk wbvtJ1CjYFFqempFWmZOCUKaiYMTZDgP0PALIDW8xQWJucWZ6RD5U4y6HAt+3F7LJMSSl5+X KiXO+wOkSACkKKM0D24OONp3M6m+YhQHekuYlwcY+0I8wEQBN+kV0BImoCVJqitAlpQkIqSk Ghg7D6+rnlNSWxPeosSwd2rkc0dHB/E2YbOzfmb/dsnkGay40Fk+b8flu58qXs6t2algNHfj ucWFTxPWzP+avcrL0J0j4YXV/LtXvSwUf/NFpaT8qY6b8+Jq/MvMLkGFlVcXxcts9Ktu/17Z rFm26Acj1+bvf574Vf8vWFnKLe550ETuTvHld5+UWIozEg21mIuKEwHABXan0QIAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/SYwm_FVaInzYcuVpt4u7YJstsgg>
Subject: [kitten] call for reviews of draft-ietf-kitten-krb-auth-indicator
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Aug 2016 15:47:06 -0000

This document is being implemented and is likely ready to advance to the
IESG, but as Nathaniel noted at the end of June, it's only had Greg's
review of the -02, my review of the precursor draft, and whatever review
Tom did when the authdata number was assigned.  It would be good to get a
couple more reviews before we send this document over to the IESG, even if
we are going to try out the new scheme that skips a formal WGLC.

-Ben
for the kitten chairs


From nobody Tue Aug  9 16:26:13 2016
Return-Path: <rfeezel@gmail.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 500BA12D892 for <kitten@ietfa.amsl.com>; Tue,  9 Aug 2016 16:26:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.699
X-Spam-Level: 
X-Spam-Status: No, score=-2.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WDrDKeYRmi6P for <kitten@ietfa.amsl.com>; Tue,  9 Aug 2016 16:26:08 -0700 (PDT)
Received: from mail-oi0-x22b.google.com (mail-oi0-x22b.google.com [IPv6:2607:f8b0:4003:c06::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6382912D8E1 for <kitten@ietf.org>; Tue,  9 Aug 2016 16:26:08 -0700 (PDT)
Received: by mail-oi0-x22b.google.com with SMTP id c15so38516359oig.0 for <kitten@ietf.org>; Tue, 09 Aug 2016 16:26:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=Pwx4qnGxEI1jOD0O4ag3fUHtsA29HFM3ok/mDOkKIdQ=; b=WSYnxupbNW02PhJEMhSCGE0BYMwB4Ir7HRmaW6Yopfqom6NkWlITNR345k4t8jQ/7i 9wENwjHI9Anz4n7gG71GzxSMZljcakKBEDvEaveit/708gpYYBxasMHwlY5YfhY3pNXa jpfA7tC0HxpMy1jAUUnbCGT0ipanM1OGIYzTrmSNvEC8lgjQHaQoj+Qg5NOkvAjbkPWQ 1JU8tnTHO8w6lG7QjKPZyr8K3mI8naPEpFPeF3+jmUaNRgSAR1uZ85Pe7oYw28hzBs0W WF7Fwl1V3nzQED2WJTMjw2Upf2UeVaQWvky9Jj4JKFaK4XT2bAp+Vv0ODuNf1XeQ40TE sL/g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=Pwx4qnGxEI1jOD0O4ag3fUHtsA29HFM3ok/mDOkKIdQ=; b=lCAmlzWfN2r8EMLgByl9bRI0+6m/L9culbE9MeHokkWwtTkZc4iq7gnCQxdF7rt+7J J9cuZImtukbnQQNOWq2jq5OXU8Bt6fOJJ5nBVRcU+dAawKlsFdtSqwKCZ7UyAH/488Ob aTYJWNAdVSoUppZlamVnVHzH3VeGnEfnfc5GC3w/TMxUceDpJv1ME/vrErwKaCt72NRS OB0gQmyRfYKmgpCzhJmjuE+vKF+46dzAgX7yhbViH2Ge78CQmNFLCP7BfQhtx4H1R01m dAfjRRfTxTX1HqqEzEUjg+8IUAIV/sEXn2XcSHPUoDsn2b1TIbBil09Foz534RHzzcbT 8GOQ==
X-Gm-Message-State: AEkoouvRB2BkPQLCmgamFMgqe4Us6mxqR/D/7gUSRtOQKNoX7eajc0KHYhXBlZN4EGRtR/sbe3VTtx9AgsasIg==
X-Received: by 10.202.245.88 with SMTP id t85mr417306oih.202.1470785167814; Tue, 09 Aug 2016 16:26:07 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.202.219.9 with HTTP; Tue, 9 Aug 2016 16:26:07 -0700 (PDT)
In-Reply-To: <alpine.GSO.1.10.1608091142540.5272@multics.mit.edu>
References: <alpine.GSO.1.10.1608091142540.5272@multics.mit.edu>
From: Richard Feezel <rfeezel@gmail.com>
Date: Tue, 9 Aug 2016 19:26:07 -0400
Message-ID: <CAGCzPPAPRMeJyugOxrCG73qBRZ3FkJ9dL_RCiwM=UwWXCH6GTA@mail.gmail.com>
To: Benjamin Kaduk <kaduk@mit.edu>
Content-Type: multipart/alternative; boundary=001a113d2d6877f7630539abdb51
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/epOMEvV-ELnSWMLRmjJoT09AJ-c>
Cc: kitten@ietf.org
Subject: Re: [kitten] call for reviews of draft-ietf-kitten-krb-auth-indicator
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Aug 2016 23:26:10 -0000

--001a113d2d6877f7630539abdb51
Content-Type: text/plain; charset=UTF-8

I am keenly interested in seeing this approved as I have immediate need of
this capability.

I have carefully read the -02 draft and I find no problems with it moving
forward as written.

Thanks,
Richard

On Tue, Aug 9, 2016 at 11:46 AM, Benjamin Kaduk <kaduk@mit.edu> wrote:

> This document is being implemented and is likely ready to advance to the
> IESG, but as Nathaniel noted at the end of June, it's only had Greg's
> review of the -02, my review of the precursor draft, and whatever review
> Tom did when the authdata number was assigned.  It would be good to get a
> couple more reviews before we send this document over to the IESG, even if
> we are going to try out the new scheme that skips a formal WGLC.
>
> -Ben
> for the kitten chairs
>
> _______________________________________________
> Kitten mailing list
> Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten
>



-- 
Richard M Feezel
rfeezel@gmail.com

--001a113d2d6877f7630539abdb51
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">I am keenly interested in seeing this approved as I have i=
mmediate need of this capability.<div><br></div><div>I have carefully read =
the -02 draft and I find no problems with it moving forward as written.</di=
v><div><br></div><div>Thanks,</div><div>Richard</div></div><div class=3D"gm=
ail_extra"><br><div class=3D"gmail_quote">On Tue, Aug 9, 2016 at 11:46 AM, =
Benjamin Kaduk <span dir=3D"ltr">&lt;<a href=3D"mailto:kaduk@mit.edu" targe=
t=3D"_blank">kaduk@mit.edu</a>&gt;</span> wrote:<br><blockquote class=3D"gm=
ail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-le=
ft:1ex">This document is being implemented and is likely ready to advance t=
o the<br>
IESG, but as Nathaniel noted at the end of June, it&#39;s only had Greg&#39=
;s<br>
review of the -02, my review of the precursor draft, and whatever review<br=
>
Tom did when the authdata number was assigned.=C2=A0 It would be good to ge=
t a<br>
couple more reviews before we send this document over to the IESG, even if<=
br>
we are going to try out the new scheme that skips a formal WGLC.<br>
<br>
-Ben<br>
for the kitten chairs<br>
<br>
______________________________<wbr>_________________<br>
Kitten mailing list<br>
<a href=3D"mailto:Kitten@ietf.org">Kitten@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/kitten" rel=3D"noreferrer"=
 target=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/kitten</a><br=
>
</blockquote></div><br><br clear=3D"all"><div><br></div>-- <br><div class=
=3D"gmail_signature" data-smartmail=3D"gmail_signature">Richard M Feezel<br=
><a href=3D"mailto:rfeezel@gmail.com" target=3D"_blank">rfeezel@gmail.com</=
a></div>
</div>

--001a113d2d6877f7630539abdb51--


From nobody Mon Aug 15 21:10:45 2016
Return-Path: <shawn.emery@oracle.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 911C0126579 for <kitten@ietfa.amsl.com>; Mon, 15 Aug 2016 21:10:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.467
X-Spam-Level: 
X-Spam-Status: No, score=-5.467 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-1.247, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id J3SH94slV-c9 for <kitten@ietfa.amsl.com>; Mon, 15 Aug 2016 21:10:42 -0700 (PDT)
Received: from userp1040.oracle.com (userp1040.oracle.com [156.151.31.81]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 121EA124281 for <kitten@ietf.org>; Mon, 15 Aug 2016 21:10:42 -0700 (PDT)
Received: from aserv0021.oracle.com (aserv0021.oracle.com [141.146.126.233]) by userp1040.oracle.com (Sentrion-MTA-4.3.2/Sentrion-MTA-4.3.2) with ESMTP id u7G4AfD6008461 (version=TLSv1 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK) for <kitten@ietf.org>; Tue, 16 Aug 2016 04:10:41 GMT
Received: from userv0121.oracle.com (userv0121.oracle.com [156.151.31.72]) by aserv0021.oracle.com (8.13.8/8.13.8) with ESMTP id u7G4AeIv020742 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK) for <kitten@ietf.org>; Tue, 16 Aug 2016 04:10:40 GMT
Received: from abhmp0002.oracle.com (abhmp0002.oracle.com [141.146.116.8]) by userv0121.oracle.com (8.13.8/8.13.8) with ESMTP id u7G4AcTU012084 for <kitten@ietf.org>; Tue, 16 Aug 2016 04:10:40 GMT
Received: from [10.159.97.80] (/10.159.97.80) by default (Oracle Beehive Gateway v4.0) with ESMTP ; Mon, 15 Aug 2016 21:10:38 -0700
From: Shawn M Emery <shawn.emery@oracle.com>
To: kitten@ietf.org
References: <20160726193833.30872.31544.idtracker@ietfa.amsl.com> <57A0C96F.3010606@mit.edu>
Message-ID: <cea4402d-728c-f6e2-6685-b8874cf8ea00@oracle.com>
Date: Mon, 15 Aug 2016 22:12:47 -0600
User-Agent: Mozilla/5.0 (X11; SunOS i86pc; rv:45.0) Gecko/20100101 Thunderbird/45.1.0
MIME-Version: 1.0
In-Reply-To: <57A0C96F.3010606@mit.edu>
Content-Type: multipart/alternative; boundary="------------CD98438D3BA44AD43B597C40"
X-Source-IP: aserv0021.oracle.com [141.146.126.233]
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/xXXOog3yLb8lMqDeI_PkacdNjOQ>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-rfc6112bis-01.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Aug 2016 04:10:43 -0000

This is a multi-part message in MIME format.
--------------CD98438D3BA44AD43B597C40
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 7bit


Thanks for your review.  Comments in-line.

On 08/ 2/16 10:25 AM, Greg Hudson wrote:
> On 07/26/2016 03:38 PM,internet-drafts@ietf.org  wrote:
>> 	Filename        : draft-ietf-kitten-rfc6112bis-01.txt
> This revision appears to be editorial, and would be unlikely to affect
> an implementation.  I do not have any substantive protocol concerns, but
> I do have some minor issues with some of the new wording.
>
> In section 7, "To ensure that an attacker cannot create a channel with a
> given name" was changed to "To ensure that an attacker cannot create a
> channel by observing exchanges."  The original wording may have used
> "name" in a non-intuitive way, but I think the new wording is more
> wrong.  The threat is that a MITM attacker might create two channels
> with the same ticket session key (known to the attacker); the new
> wording suggests that the threat comes from a passive attacker.

Yes, the key word "observing" indicates a passive state.  How about?:

To ensure that an attacker cannot create a channel by obtaining key 
exchanges between the client and KDC, it is desirable that neither the 
KDC nor the client unilaterally determine the ticket session key.

> In this text:
>
>      Such authorization data, if included in the anonymous ticket, would
>      disclose the that the client is a member of the group observed.	
>
> After the changes, there is an extra "the" before "that".

Done.

> In this new block of text:
>
>      This protocol provides a binding between the party which
>      generated the session key and the DH exchange used to generate
>      they reply key.  Hypothetically, if the KDC did not use
>      PA-PKINIT-KX, the client and KDC would perfrom a DH key
>      exchange to determine a shared key, and that key would be used
>      as a reply key.  The KDC would then generate a ticket with a
>      session key encrypting the reply with the DH agreement.  A MITM
>      attacker would just decrypt the session key + ticket using the
>      DH key from the attacker and KDC DH exchange, and re-encrypt it
>      using the key from the attacker and client DH exchange, while
>      keeping a copy of the session key and ticket.  By requiring the
>      session key in a way that can be verified by the client, this
>      protocol binds the ticket to the DH exchange and prevents the
>      MITM attack.
>
> "perfrom" should be "perform".  "session key + ticket" should be
> "session key and ticket".

Done.

> It might be clearer to say "attacker-KDC DH
> exchange" than "attacker and KDC DH exchange", and similarly
> "attacker-client DH exchange".

Agreed.

> "By requiring the session key in a way that..." is not grammatical.
>

How about?:

This protocol binds the ticket to the DH exchange and prevents the MITM 
attack by requiring the session key in a way that can be verified by the 
client.

Thanks again for your review.

Shawn.
--

--------------CD98438D3BA44AD43B597C40
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix"><br>
      Thanks for your review.  Comments in-line.<br>
      <br>
      On 08/ 2/16 10:25 AM, Greg Hudson wrote:<br>
    </div>
    <blockquote cite="mid:57A0C96F.3010606@mit.edu" type="cite">
      <pre wrap="">On 07/26/2016 03:38 PM, <a class="moz-txt-link-abbreviated" href="mailto:internet-drafts@ietf.org">internet-drafts@ietf.org</a> wrote:
</pre>
      <blockquote type="cite">
        <pre wrap="">	Filename        : draft-ietf-kitten-rfc6112bis-01.txt
</pre>
      </blockquote>
      <pre wrap="">This revision appears to be editorial, and would be unlikely to affect
an implementation.  I do not have any substantive protocol concerns, but
I do have some minor issues with some of the new wording.

In section 7, "To ensure that an attacker cannot create a channel with a
given name" was changed to "To ensure that an attacker cannot create a
channel by observing exchanges."  The original wording may have used
"name" in a non-intuitive way, but I think the new wording is more
wrong.  The threat is that a MITM attacker might create two channels
with the same ticket session key (known to the attacker); the new
wording suggests that the threat comes from a passive attacker.</pre>
    </blockquote>
    <br>
    Yes, the key word "observing" indicates a passive state.  How
    about?:<br>
    <br>
    To ensure that an attacker cannot create a channel by obtaining key
    exchanges between the client and KDC, it is desirable that neither
    the KDC nor the client unilaterally determine the ticket session
    key.<br>
    <br>
    <blockquote cite="mid:57A0C96F.3010606@mit.edu" type="cite">
      <pre wrap="">
In this text:

    Such authorization data, if included in the anonymous ticket, would
    disclose the that the client is a member of the group observed.	

After the changes, there is an extra "the" before "that".</pre>
    </blockquote>
    <br>
    Done.<br>
    <br>
    <blockquote cite="mid:57A0C96F.3010606@mit.edu" type="cite">
      <pre wrap="">
In this new block of text:

    This protocol provides a binding between the party which
    generated the session key and the DH exchange used to generate
    they reply key.  Hypothetically, if the KDC did not use
    PA-PKINIT-KX, the client and KDC would perfrom a DH key
    exchange to determine a shared key, and that key would be used
    as a reply key.  The KDC would then generate a ticket with a
    session key encrypting the reply with the DH agreement.  A MITM
    attacker would just decrypt the session key + ticket using the
    DH key from the attacker and KDC DH exchange, and re-encrypt it
    using the key from the attacker and client DH exchange, while
    keeping a copy of the session key and ticket.  By requiring the
    session key in a way that can be verified by the client, this
    protocol binds the ticket to the DH exchange and prevents the
    MITM attack.

"perfrom" should be "perform".  "session key + ticket" should be
"session key and ticket".</pre>
    </blockquote>
    <br>
    Done.<br>
    <br>
    <blockquote cite="mid:57A0C96F.3010606@mit.edu" type="cite">
      <pre wrap="">It might be clearer to say "attacker-KDC DH
exchange" than "attacker and KDC DH exchange", and similarly
"attacker-client DH exchange".</pre>
    </blockquote>
    <br>
    Agreed.<br>
    <br>
    <blockquote cite="mid:57A0C96F.3010606@mit.edu" type="cite">
      <pre wrap="">
"By requiring the session key in a way that..." is not grammatical.

</pre>
    </blockquote>
    <br>
    How about?:<br>
    <br>
    This protocol binds the ticket to the DH exchange and prevents the
    MITM attack by requiring the session key in a way that can be
    verified by the client.<br>
    <br>
    Thanks again for your review.<br>
    <br>
    Shawn.<br>
    --<br>
  </body>
</html>

--------------CD98438D3BA44AD43B597C40--


From nobody Tue Aug 16 07:47:16 2016
Return-Path: <aamelnikov@fastmail.fm>
X-Original-To: kitten@ietf.org
Delivered-To: kitten@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 3038912B008; Tue, 16 Aug 2016 07:47:11 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: "Alexey Melnikov" <aamelnikov@fastmail.fm>
To: "The IESG" <iesg@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.29.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <147135883119.22847.4813217180392130756.idtracker@ietfa.amsl.com>
Date: Tue, 16 Aug 2016 07:47:11 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/KYLu4J2M5vdRX4gPgm307fNVV84>
Cc: kitten@ietf.org, draft-ietf-kitten-aes-cts-hmac-sha2@ietf.org, kitten-chairs@ietf.org
Subject: [kitten] Alexey Melnikov's No Objection on draft-ietf-kitten-aes-cts-hmac-sha2-10: (with COMMENT)
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Aug 2016 14:47:11 -0000

Alexey Melnikov has entered the following ballot position for
draft-ietf-kitten-aes-cts-hmac-sha2-10: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-kitten-aes-cts-hmac-sha2/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

First mention of UTF-8 needs a reference to RFC 3629.



From nobody Wed Aug 17 08:58:25 2016
Return-Path: <ghudson@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 92CC212D7AF for <kitten@ietfa.amsl.com>; Wed, 17 Aug 2016 08:58:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.448
X-Spam-Level: 
X-Spam-Status: No, score=-5.448 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-1.247, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SndI8VTSuqOq for <kitten@ietfa.amsl.com>; Wed, 17 Aug 2016 08:58:23 -0700 (PDT)
Received: from dmz-mailsec-scanner-6.mit.edu (dmz-mailsec-scanner-6.mit.edu [18.7.68.35]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9053912DE0D for <kitten@ietf.org>; Wed, 17 Aug 2016 08:58:20 -0700 (PDT)
X-AuditID: 12074423-eafff70000005fe1-bd-57b4899b241a
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id AF.42.24545.B9984B75; Wed, 17 Aug 2016 11:58:19 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id u7HFwIPf032062; Wed, 17 Aug 2016 11:58:19 -0400
Received: from [18.101.8.186] (vpn-18-101-8-186.mit.edu [18.101.8.186]) (authenticated bits=0) (User authenticated as ghudson@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id u7HFwGK0026364 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Wed, 17 Aug 2016 11:58:18 -0400
To: Shawn M Emery <shawn.emery@oracle.com>, kitten@ietf.org
References: <20160726193833.30872.31544.idtracker@ietfa.amsl.com> <57A0C96F.3010606@mit.edu> <cea4402d-728c-f6e2-6685-b8874cf8ea00@oracle.com>
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <57B48997.7080207@mit.edu>
Date: Wed, 17 Aug 2016 11:58:15 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.8.0
MIME-Version: 1.0
In-Reply-To: <cea4402d-728c-f6e2-6685-b8874cf8ea00@oracle.com>
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrAIsWRmVeSWpSXmKPExsUixG6nrju7c0u4wYrNkhZHN69iseh7fYjd gcljyZKfTB4fn95iCWCK4rJJSc3JLEst0rdL4MpY3ClRsIqnouXXZ+YGxmecXYycHBICJhKN pyYxdjFycQgJtDFJXD67mAXC2cgosavjOStIlZDAESaJY3szQGxhAVeJT9f72UFsEQFriZl7 zkI1TGCUuHe6F6yBTUBZYv3+rSwgNq+AmsSHZY8YQWwWAVWJRe+ngsVFBSIkZm3/wQRRIyhx cuYTsDingJ1E4883YHOYBfQkdlz/BWXLS2x/O4d5AiP/LCQts5CUzUJStoCReRWjbEpulW5u YmZOcWqybnFyYl5eapGumV5uZoleakrpJkZwQLoo72B82ed9iFGAg1GJh/eG1eZwIdbEsuLK 3EOMkhxMSqK8d6q3hAvxJeWnVGYkFmfEF5XmpBYfYpTgYFYS4W1rAcrxpiRWVqUW5cOkpDlY lMR5t39rDxcSSE8sSc1OTS1ILYLJynBwKEnw5nQANQoWpaanVqRl5pQgpJk4OEGG8wAN3wBS w1tckJhbnJkOkT/FqCglzqsJkhAASWSU5sH1ghNGKseuV4ziQK8I8z4GqeIBJhu47ldAg5mA BvPygw0uSURISTUwGn6/lZl8I2Xex6TZZ41+bQuZcH6S3J/F+x0con7mBn94t+XLnXKjP+4m 9zRDUqzbGP9k1BQaPZ/W1r/mt0vSnScrJ8YISjJYx2slHGrom+25Qcr46zefrSVPxIym2l+9 UHd3CpvA7PNHnlelZLCfOsHQz/fNyOr3/gkGax59WHh6u0LkoSuJdUosxRmJhlrMRcWJAHO/ uNHzAgAA
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/mOjp3eWKN6NY2tHIrEHOINs3gmQ>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-rfc6112bis-01.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 17 Aug 2016 15:58:24 -0000

On 08/16/2016 12:12 AM, Shawn M Emery wrote:
>> In section 7, "To ensure that an attacker cannot create a channel with a
>> given name" was changed to "To ensure that an attacker cannot create a
>> channel by observing exchanges."  The original wording may have used
>> "name" in a non-intuitive way, but I think the new wording is more
>> wrong.  The threat is that a MITM attacker might create two channels
>> with the same ticket session key (known to the attacker); the new
>> wording suggests that the threat comes from a passive attacker.
> 
> Yes, the key word "observing" indicates a passive state.  How about?:
> 
> To ensure that an attacker cannot create a channel by obtaining key
> exchanges between the client and KDC, it is desirable that neither the
> KDC nor the client unilaterally determine the ticket session key.

That still suggests a passive attacker to me.  I suggest:

"To ensure that an active attacker cannot create separate channels to
the client and KDC with the same known key, it is desirable that neither
the KDC nor the client unilaterally determine the ticket session key."

>> "By requiring the session key in a way that..." is not grammatical.
>>
> 
> How about?:
> 
> This protocol binds the ticket to the DH exchange and prevents the MITM
> attack by requiring the session key in a way that can be verified by the
> client.

I believe that change just reverses the two main clauses of the sentence
without eliminating the grammar error.  You could say "requiring the
session key to be created in a way...".


From nobody Tue Aug 23 22:18:47 2016
Return-Path: <shawn.emery@oracle.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 68FD012B074 for <kitten@ietfa.amsl.com>; Tue, 23 Aug 2016 22:18:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.75
X-Spam-Level: 
X-Spam-Status: No, score=-4.75 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H2=-0.001, RP_MATCHES_RCVD=-0.548, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qsGPt_TAV9_N for <kitten@ietfa.amsl.com>; Tue, 23 Aug 2016 22:18:45 -0700 (PDT)
Received: from userp1040.oracle.com (userp1040.oracle.com [156.151.31.81]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6D015128E19 for <kitten@ietf.org>; Tue, 23 Aug 2016 22:18:45 -0700 (PDT)
Received: from aserv0021.oracle.com (aserv0021.oracle.com [141.146.126.233]) by userp1040.oracle.com (Sentrion-MTA-4.3.2/Sentrion-MTA-4.3.2) with ESMTP id u7O5IiZ0031023 (version=TLSv1 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK); Wed, 24 Aug 2016 05:18:44 GMT
Received: from aserv0122.oracle.com (aserv0122.oracle.com [141.146.126.236]) by aserv0021.oracle.com (8.13.8/8.13.8) with ESMTP id u7O5IhVJ019107 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK); Wed, 24 Aug 2016 05:18:44 GMT
Received: from abhmp0009.oracle.com (abhmp0009.oracle.com [141.146.116.15]) by aserv0122.oracle.com (8.14.4/8.14.4) with ESMTP id u7O5Ihho020152; Wed, 24 Aug 2016 05:18:43 GMT
Received: from [10.159.123.252] (/10.159.123.252) by default (Oracle Beehive Gateway v4.0) with ESMTP ; Tue, 23 Aug 2016 22:18:43 -0700
To: Greg Hudson <ghudson@mit.edu>, kitten@ietf.org
References: <20160726193833.30872.31544.idtracker@ietfa.amsl.com> <57A0C96F.3010606@mit.edu> <cea4402d-728c-f6e2-6685-b8874cf8ea00@oracle.com> <57B48997.7080207@mit.edu>
From: Shawn M Emery <shawn.emery@oracle.com>
Message-ID: <0a3add89-c32a-2451-d229-e29fba32bf28@oracle.com>
Date: Tue, 23 Aug 2016 23:20:56 -0600
User-Agent: Mozilla/5.0 (X11; SunOS i86pc; rv:45.0) Gecko/20100101 Thunderbird/45.1.0
MIME-Version: 1.0
In-Reply-To: <57B48997.7080207@mit.edu>
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 7bit
X-Source-IP: aserv0021.oracle.com [141.146.126.233]
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/v0TiwZJISj3rHZR0sInOt7Rq3ZA>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-rfc6112bis-01.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Aug 2016 05:18:46 -0000

On 08/17/16 09:58 AM, Greg Hudson wrote:
> On 08/16/2016 12:12 AM, Shawn M Emery wrote:
>>> In section 7, "To ensure that an attacker cannot create a channel with a
>>> given name" was changed to "To ensure that an attacker cannot create a
>>> channel by observing exchanges."  The original wording may have used
>>> "name" in a non-intuitive way, but I think the new wording is more
>>> wrong.  The threat is that a MITM attacker might create two channels
>>> with the same ticket session key (known to the attacker); the new
>>> wording suggests that the threat comes from a passive attacker.
>> Yes, the key word "observing" indicates a passive state.  How about?:
>>
>> To ensure that an attacker cannot create a channel by obtaining key
>> exchanges between the client and KDC, it is desirable that neither the
>> KDC nor the client unilaterally determine the ticket session key.
> That still suggests a passive attacker to me.  I suggest:
>
> "To ensure that an active attacker cannot create separate channels to
> the client and KDC with the same known key, it is desirable that neither
> the KDC nor the client unilaterally determine the ticket session key."

I don't think "channels" is the right word in the updated sentence. I 
interpreted the original text to indicate that an active attacker can 
not snoop key exchanges between the client and KDC in order to 
compromise a subsequent secure channel.

>>> "By requiring the session key in a way that..." is not grammatical.
>>>
>> How about?:
>>
>> This protocol binds the ticket to the DH exchange and prevents the MITM
>> attack by requiring the session key in a way that can be verified by the
>> client.
> I believe that change just reverses the two main clauses of the sentence
> without eliminating the grammar error.  You could say "requiring the
> session key to be created in a way...".

Sorry, was focused on the entire sentence.  Done.

Shawn.
--


From nobody Tue Aug 23 23:08:35 2016
Return-Path: <ghudson@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A2F3A12D151 for <kitten@ietfa.amsl.com>; Tue, 23 Aug 2016 23:08:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.749
X-Spam-Level: 
X-Spam-Status: No, score=-4.749 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.548, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BlpCUhMZNszg for <kitten@ietfa.amsl.com>; Tue, 23 Aug 2016 23:08:33 -0700 (PDT)
Received: from dmz-mailsec-scanner-6.mit.edu (dmz-mailsec-scanner-6.mit.edu [18.7.68.35]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 36FAD12D0FD for <kitten@ietf.org>; Tue, 23 Aug 2016 23:08:33 -0700 (PDT)
X-AuditID: 12074423-d2fff70000004044-35-57bd39df3264
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id 94.67.16452.FD93DB75; Wed, 24 Aug 2016 02:08:32 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id u7O68Vic013732; Wed, 24 Aug 2016 02:08:31 -0400
Received: from [18.101.8.219] (vpn-18-101-8-219.mit.edu [18.101.8.219]) (authenticated bits=0) (User authenticated as ghudson@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id u7O68T5D019193 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Wed, 24 Aug 2016 02:08:30 -0400
To: Shawn M Emery <shawn.emery@oracle.com>, kitten@ietf.org
References: <20160726193833.30872.31544.idtracker@ietfa.amsl.com> <57A0C96F.3010606@mit.edu> <cea4402d-728c-f6e2-6685-b8874cf8ea00@oracle.com> <57B48997.7080207@mit.edu> <0a3add89-c32a-2451-d229-e29fba32bf28@oracle.com>
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <57BD39DD.3000702@mit.edu>
Date: Wed, 24 Aug 2016 02:08:29 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.8.0
MIME-Version: 1.0
In-Reply-To: <0a3add89-c32a-2451-d229-e29fba32bf28@oracle.com>
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrIIsWRmVeSWpSXmKPExsUixG6nrvvAcm+4we5vzBZHN69iseh7fYjd gcljyZKfTB4fn95iCWCK4rJJSc3JLEst0rdL4Mr42HmNtWCKSEXLyuOMDYztAl2MnBwSAiYS j3YsZOpi5OIQEmhjkjgzaRIjhLORUeLIsV1sEM4RJol5f16wgrQIC7hKfLrezw5iiwhYS8zc c5YFoug+o8Tvy61MIAk2AWWJ9fu3AiU4OHgF1CSWTI0ACbMIqEr8ed0N1isqECExa/sPsHJe AUGJkzOfsIDYnAJ2ErfuXWMEsZkF9CR2XP/FCmHLS2x/O4d5AiP/LCQts5CUzUJStoCReRWj bEpulW5uYmZOcWqybnFyYl5eapGumV5uZoleakrpJkZwSLoo72B82ed9iFGAg1GJh7cjZE+4 EGtiWXFl7iFGSQ4mJVHem6p7w4X4kvJTKjMSizPii0pzUosPMUpwMCuJ8HaYA+V4UxIrq1KL 8mFS0hwsSuK827+1hwsJpCeWpGanphakFsFkZTg4lCR4WyyAGgWLUtNTK9Iyc0oQ0kwcnCDD eYCGbwap4S0uSMwtzkyHyJ9iVJQS51UBSQiAJDJK8+B6wSkjleP2K0ZxoFeEed+AVPEA0w1c 9yugwUxAg1vu7wYZXJKIkJJqYDSWflbvfImRUXiTVRWD4yflyTW/bKzaF2xY3Gq8/+jqOdc0 3JuEA3paNTvDzN3PlH/+q3eq7vlGTtlH5mq5btZWf0QcA5imzwmpVgqLYZ/Od+9lxbr8qN2N ehO7hE906V93Ol6Ub2R/3Mj2rcjXa00+Zss8woy9Vh99fcfbXv1Z2MFHpf1ySizFGYmGWsxF xYkACHcpEfQCAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/QhBq5PjHOPCptItBa7CelHLgy7U>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-rfc6112bis-01.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Aug 2016 06:08:34 -0000

On 08/24/2016 01:20 AM, Shawn M Emery wrote:
> On 08/17/16 09:58 AM, Greg Hudson wrote:
>> On 08/16/2016 12:12 AM, Shawn M Emery wrote:
>>>> In section 7, "To ensure that an attacker cannot create a channel
>>>> with a
>>>> given name" was changed to "To ensure that an attacker cannot create a
>>>> channel by observing exchanges."  The original wording may have used
>>>> "name" in a non-intuitive way, but I think the new wording is more
>>>> wrong.  The threat is that a MITM attacker might create two channels
>>>> with the same ticket session key (known to the attacker); the new
>>>> wording suggests that the threat comes from a passive attacker.
>>> Yes, the key word "observing" indicates a passive state.  How about?:
>>>
>>> To ensure that an attacker cannot create a channel by obtaining key
>>> exchanges between the client and KDC, it is desirable that neither the
>>> KDC nor the client unilaterally determine the ticket session key.
>> That still suggests a passive attacker to me.  I suggest:
>>
>> "To ensure that an active attacker cannot create separate channels to
>> the client and KDC with the same known key, it is desirable that neither
>> the KDC nor the client unilaterally determine the ticket session key."
> 
> I don't think "channels" is the right word in the updated sentence. I
> interpreted the original text to indicate that an active attacker can
> not snoop key exchanges between the client and KDC in order to
> compromise a subsequent secure channel.

The attack being thwarted is described in the last paragraph of the section:

    A MITM attacker would just decrypt the session key + ticket using the
    DH key from the attacker and KDC DH exchange, and re-encrypt it using
    the key from the attacker and client DH exchange, while keeping a
    copy of the session key and ticket.

To add more detail: the scenario we are trying to protect is that a
client preauthenticates with unverified anonymous PKINIT to obtain a
TGT, then uses that TGT as FAST armor for encrypted challenge (or
another FAST factor with similar properties).  Without the mechanism in
section 7, an attacker in the middle could:

1. Perform its own anonymous PKINIT authentication to the real KDC to
get a ticket with a known session key.

2. Impersonate the KDC to the real client, performing the KDC side of
the anonymous PKINIT.

3. Issue a ticket to the client using the same session key as the one it
got in step 1.

4. Decrypt the subsequent FAST-protected AS exchange using the session
key from step 1.


From nobody Wed Aug 24 17:53:16 2016
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AD8F112D5F7 for <kitten@ietfa.amsl.com>; Wed, 24 Aug 2016 17:53:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.769
X-Spam-Level: 
X-Spam-Status: No, score=-4.769 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.548, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5e0SCx_0W4Oh for <kitten@ietfa.amsl.com>; Wed, 24 Aug 2016 17:53:13 -0700 (PDT)
Received: from dmz-mailsec-scanner-5.mit.edu (dmz-mailsec-scanner-5.mit.edu [18.7.68.34]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7651112D5C7 for <kitten@ietf.org>; Wed, 24 Aug 2016 17:53:12 -0700 (PDT)
X-AuditID: 12074422-f37ff7000000337c-25-57be41771571
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id 25.E5.13180.7714EB75; Wed, 24 Aug 2016 20:53:11 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id u7P0rAk2032474 for <kitten@ietf.org>; Wed, 24 Aug 2016 20:53:11 -0400
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id u7P0r7dQ029378 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Wed, 24 Aug 2016 20:53:10 -0400
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id u7P0r7lH017921; Wed, 24 Aug 2016 20:53:07 -0400 (EDT)
Date: Wed, 24 Aug 2016 20:53:06 -0400 (EDT)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
Message-ID: <alpine.GSO.1.10.1608242050500.5272@multics.mit.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrPIsWRmVeSWpSXmKPExsUixCmqrVvuuC/coOWBpsXRzatYHBg9liz5 yRTAGMVlk5Kak1mWWqRvl8CVceqJXsEJpoqDa/rZGxj/MXYxcnJICJhIHFq2l7WLkYtDSKCN SeL41a/MEM5xRoklp9rZIJwbTBK7Ls6GchoYJdb23GEB6WcR0JZ49OY8mM0moCIx881GNhBb REBYYvfWd8wgtrCAlMSWZ83sIDavgIPE8zkNYLtFBXQkVu+fwgIRF5Q4OfMJmM0soCWxfPo2 lgmMvLOQpGYhSS1gZFrFKJuSW6Wbm5iZU5yarFucnJiXl1qka6qXm1mil5pSuokRFDbsLko7 GCf+8zrEKMDBqMTDu2PV3nAh1sSy4srcQ4ySHExKorzhTUAhvqT8lMqMxOKM+KLSnNTiQ4wS HMxKIry69vvChXhTEiurUovyYVLSHCxK4rzbv7WHCwmkJ5akZqemFqQWwWRlODiUJHhzHYAa BYtS01Mr0jJzShDSTBycIMN5gIYngtTwFhck5hZnpkPkTzHqciz4cXstkxBLXn5eqpQ4bxRI kQBIUUZpHtwccLzvZlJ9xSgO9JYw7w+QO3mAqQJu0iugJUxAS1ru7wZZUpKIkJJqYPTfMmF9 +f0Nrdf/1xycdGJF3TFde5ddz15LTbygZKZ4JyPSM2XbLQYNl8LNjVen65wM3Dc5On5z3gSR v41zL0xn1+3r2b50z1uWbXf4X7DKzSw6LZBT7aX6gmdLLmOZ10O7FVfnXNtZ1Bz7X3dN2Jo3 jxNyW26JMuRfPnEozp35RVzO5A2l87mVWIozEg21mIuKEwE4iJtN0gIAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/ixmW2jTGijlAAvLSLzwuNET34co>
Subject: [kitten] meeting in Seoul?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Aug 2016 00:53:14 -0000

Hi all,

Session requests are now open for IETF 97 in Seoul (November 13-18).  Does
anyone have topic(s) they would like to cover there?  If there are no
responses, I will assume that we will not meet and submit a session
request to that effect.

Please send in any topics by September 7.

-Ben
for the kitten chairs


From nobody Thu Aug 25 13:08:26 2016
Return-Path: <npmccallum@redhat.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ACB2012D0AD for <kitten@ietfa.amsl.com>; Thu, 25 Aug 2016 13:08:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.469
X-Spam-Level: 
X-Spam-Status: No, score=-6.469 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HK_RANDOM_ENVFROM=0.001, HK_RANDOM_FROM=1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.548, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AoUkSTj3tIt7 for <kitten@ietfa.amsl.com>; Thu, 25 Aug 2016 13:08:23 -0700 (PDT)
Received: from mx1.redhat.com (mx1.redhat.com [209.132.183.28]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 465C712B040 for <kitten@ietf.org>; Thu, 25 Aug 2016 13:08:23 -0700 (PDT)
Received: from int-mx09.intmail.prod.int.phx2.redhat.com (int-mx09.intmail.prod.int.phx2.redhat.com [10.5.11.22]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id E06BA7F7A9; Thu, 25 Aug 2016 20:02:39 +0000 (UTC)
Received: from dhcp137-207.rdu.redhat.com (dhcp137-207.rdu.redhat.com [10.13.137.207]) by int-mx09.intmail.prod.int.phx2.redhat.com (8.14.4/8.14.4) with ESMTP id u7PK2c4C012806 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Thu, 25 Aug 2016 16:02:39 -0400
Message-ID: <1472155358.25965.9.camel@redhat.com>
From: Nathaniel McCallum <npmccallum@redhat.com>
To: Benjamin Kaduk <kaduk@MIT.EDU>, kitten@ietf.org
Date: Thu, 25 Aug 2016 16:02:38 -0400
In-Reply-To: <alpine.GSO.1.10.1608242050500.5272@multics.mit.edu>
References: <alpine.GSO.1.10.1608242050500.5272@multics.mit.edu>
Content-Type: text/plain; charset="UTF-8"
Mime-Version: 1.0
Content-Transfer-Encoding: 8bit
X-Scanned-By: MIMEDefang 2.68 on 10.5.11.22
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.28]); Thu, 25 Aug 2016 20:02:40 +0000 (UTC)
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/c0j1CUPX79fmr_pc9WIH8d_2GNU>
Cc: Matt Rogers <mrogers@redhat.com>
Subject: Re: [kitten] meeting in Seoul?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Aug 2016 20:08:24 -0000

On Wed, 2016-08-24 at 20:53 -0400, Benjamin Kaduk wrote:
> Hi all,
> 
> Session requests are now open for IETF 97 in Seoul (November 13-
> 18).  Does
> anyone have topic(s) they would like to cover there?  If there are no
> responses, I will assume that we will not meet and submit a session
> request to that effect.
> 
> Please send in any topics by September 7.

I would definitely like to discuss my three outstanding drafts:
  * Authentication Indicators
  * URI Discovery
  * SPAKE Preauth

This discussion doesn't have to be in Seoul, though I may be there for
other reasons.

In the case of Authentication Indicators, the authors feel this draft
is complete and is ready for WGLC.

Regarding the other two drafts, I am about to issue new revisions
(today or tomorrow). I would very much like them to be adopted by the
working group.

In the case of URI Discovery, we are close to merging a patch
supporting the feature.
    https://github.com/krb5/krb5/pull/481

In the case of SPAKE, we have a basic implementation working and plan
to expand it to support second features in the coming months.
    https://github.com/greghudson/krb5/tree/spake

We would very much like to move these drafts along as quickly as
possible.

Nathaniel


From nobody Fri Aug 26 09:34:52 2016
Return-Path: <internet-drafts@ietf.org>
X-Original-To: kitten@ietf.org
Delivered-To: kitten@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 3369512D142; Fri, 26 Aug 2016 09:34:47 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.31.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <147222928720.28387.15678500124278170272.idtracker@ietfa.amsl.com>
Date: Fri, 26 Aug 2016 09:34:47 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/5rfCjCurY_12zwiLPSK9jANMKgQ>
Cc: kitten@ietf.org
Subject: [kitten] I-D Action: draft-ietf-kitten-aes-cts-hmac-sha2-11.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 26 Aug 2016 16:34:47 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Common Authentication Technology Next Generation of the IETF.

        Title           : AES Encryption with HMAC-SHA2 for Kerberos 5
        Authors         : Michael J. Jenkins
                          Michael A. Peck
                          Kelley W. Burgin
	Filename        : draft-ietf-kitten-aes-cts-hmac-sha2-11.txt
	Pages           : 18
	Date            : 2016-08-26

Abstract:
   This document specifies two encryption types and two corresponding
   checksum types for Kerberos 5.  The new types use AES in CTS mode
   (CBC mode with ciphertext stealing) for confidentiality and HMAC with
   a SHA-2 hash for integrity.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-kitten-aes-cts-hmac-sha2/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-kitten-aes-cts-hmac-sha2-11

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-kitten-aes-cts-hmac-sha2-11


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Fri Aug 26 10:11:30 2016
Return-Path: <m.jenkins.364706@gmail.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8A8A312D0BF for <kitten@ietfa.amsl.com>; Fri, 26 Aug 2016 10:11:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.749
X-Spam-Level: 
X-Spam-Status: No, score=-1.749 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Cl0sZxcEmzzk for <kitten@ietfa.amsl.com>; Fri, 26 Aug 2016 10:11:28 -0700 (PDT)
Received: from mail-ua0-x235.google.com (mail-ua0-x235.google.com [IPv6:2607:f8b0:400c:c08::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D30A812B054 for <kitten@ietf.org>; Fri, 26 Aug 2016 10:11:27 -0700 (PDT)
Received: by mail-ua0-x235.google.com with SMTP id l94so85457984ual.0 for <kitten@ietf.org>; Fri, 26 Aug 2016 10:11:27 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to;  bh=wGGEJzrIaSFwOXsWR2QQftSdnhIe9eyX2/xFOEXmM3U=; b=eCYyGZPTm6h7AotNEsFSlfctciOFsbvO870osvB1FKa0CRFu3TADNgc9ccEKgPd7h6 qx1txkN/F2kqme4XqwBkV1KR8IQQo1g7lCQ7mqpUK5Y7HNj6/Kmy22QnRc8eRSoEBbNh Z8DbYJMKLILcgEovEoUFjAUBA3bN9lOu9+sCCmj2y7xwEt5vW+Gd95dY5G9ePiS6jZ8W HPHoRy2DMbcxTiszH310RKHVVyW1YPVJHpBEzuuXCPYUeJ8DId47VKQF8+0r5FLcFthn UlIyNX1Rr4/FF5UboPQgWDg0k1AKq8G6OT0Kn1LjJrKZQupdxL32OBqepGLG8YpMqTDK oCPA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=wGGEJzrIaSFwOXsWR2QQftSdnhIe9eyX2/xFOEXmM3U=; b=RAcGEg9wlS1HMu5jaD5lAXYcwI5hxFGRwClvwt0UqenEhRJQZ4kemAz5PI7BZAN3cu EP4hNjNyIVG9LYAHQwzNbMml3BgdeETgBAPTEiGZHvK2jMybr8cTl7eUK2nsz+ZEntMM oUF/Ke8jFxqud8/1hu/R3CmmW+Lado/E1yobAG9Ja8L2Z1aobnphJxo3STu1UydwHCIK TUaQ9bLmfpywWnCUyJZLxNjGl6Mg+5/AsXHq7J2yO9go4aLjeRXX0Q1Cg5MvShuTRUbe +EKosuZfW34WXJ5SS7H4IKFbIYi/acIDPXhgoq+QHnqsj1/tL3IR3LQ03+ASBS04Yb9k 793A==
X-Gm-Message-State: AE9vXwP/Gd7Cwr2l+RVwJ4TZ9VBKYZyQFnKyOoQEo6Cm38h4baARBBP1VUefsDFaySWNJeYV0arJtSn+4DSqRw==
X-Received: by 10.31.207.1 with SMTP id f1mr2795688vkg.47.1472231486878; Fri, 26 Aug 2016 10:11:26 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.31.149.199 with HTTP; Fri, 26 Aug 2016 10:11:26 -0700 (PDT)
In-Reply-To: <147222928720.28387.15678500124278170272.idtracker@ietfa.amsl.com>
References: <147222928720.28387.15678500124278170272.idtracker@ietfa.amsl.com>
From: Michael Jenkins <m.jenkins.364706@gmail.com>
Date: Fri, 26 Aug 2016 13:11:26 -0400
Message-ID: <CAC2=hne-s-7r_z6xuafOxgSBsp+zj_f-FPYbgh1J=oMRWm57vw@mail.gmail.com>
To: kitten@ietf.org
Content-Type: multipart/alternative; boundary=001a114e1ff6cd7a50053afc9aef
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/qG98AraUnRK7IW1Hcxd9naoPirw>
Subject: [kitten] Fwd: I-D Action: draft-ietf-kitten-aes-cts-hmac-sha2-11.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 26 Aug 2016 17:11:29 -0000

--001a114e1ff6cd7a50053afc9aef
Content-Type: text/plain; charset=UTF-8

This update is in response to comments made so far during IESG review. It
contains several clarifications but no changes that required test vector
regeneration.

---------- Forwarded message ----------
From: <internet-drafts@ietf.org>
Date: Fri, Aug 26, 2016 at 12:34 PM
Subject: [kitten] I-D Action: draft-ietf-kitten-aes-cts-hmac-sha2-11.txt
To: i-d-announce@ietf.org
Cc: kitten@ietf.org



A New Internet-Draft is available from the on-line Internet-Drafts
directories.
This draft is a work item of the Common Authentication Technology Next
Generation of the IETF.

        Title           : AES Encryption with HMAC-SHA2 for Kerberos 5
        Authors         : Michael J. Jenkins
                          Michael A. Peck
                          Kelley W. Burgin
        Filename        : draft-ietf-kitten-aes-cts-hmac-sha2-11.txt
        Pages           : 18
        Date            : 2016-08-26

Abstract:
   This document specifies two encryption types and two corresponding
   checksum types for Kerberos 5.  The new types use AES in CTS mode
   (CBC mode with ciphertext stealing) for confidentiality and HMAC with
   a SHA-2 hash for integrity.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-kitten-aes-cts-hmac-sha2/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-kitten-aes-cts-hmac-sha2-11

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-kitten-aes-cts-hmac-sha2-11


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

_______________________________________________
Kitten mailing list
Kitten@ietf.org
https://www.ietf.org/mailman/listinfo/kitten



-- 
Mike Jenkins
mjjenki@tycho.ncsc.mil - if you want me to read it only at my desk
m.jenkins.364706@gmail.com - to read everywhere
443-634-3951

--001a114e1ff6cd7a50053afc9aef
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">This update is in response to comments made so far during =
IESG review. It<br>
contains several clarifications but no changes that required test vector<br=
>
regeneration.<br><br>
<div class=3D"gmail_quote">---------- Forwarded message ----------<br>From:=
 <b class=3D"gmail_sendername"></b> <span dir=3D"ltr">&lt;<a href=3D"mailto=
:internet-drafts@ietf.org">internet-drafts@ietf.org</a>&gt;</span><br>Date:=
 Fri, Aug 26, 2016 at 12:34 PM<br>Subject: [kitten] I-D Action: draft-ietf-=
kitten-aes-cts-hmac-sha2-11.txt<br>To: <a href=3D"mailto:i-d-announce@ietf.=
org">i-d-announce@ietf.org</a><br>Cc: <a href=3D"mailto:kitten@ietf.org">ki=
tten@ietf.org</a><br><br><br><br>
A New Internet-Draft is available from the on-line Internet-Drafts director=
ies.<br>
This draft is a work item of the Common Authentication Technology Next Gene=
ration of the IETF.<br>
<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 Title=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0:=
 AES Encryption with HMAC-SHA2 for Kerberos 5<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 Authors=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0: Mich=
ael J. Jenkins<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 Michael A. Peck<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 Kelley W. Burgin<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 Filename=C2=A0 =C2=A0 =C2=A0 =C2=A0 : draft-iet=
f-kitten-aes-cts-<wbr>hmac-sha2-11.txt<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 Pages=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0:=
 18<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 Date=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 :=
 2016-08-26<br>
<br>
Abstract:<br>
=C2=A0 =C2=A0This document specifies two encryption types and two correspon=
ding<br>
=C2=A0 =C2=A0checksum types for Kerberos 5.=C2=A0 The new types use AES in =
CTS mode<br>
=C2=A0 =C2=A0(CBC mode with ciphertext stealing) for confidentiality and HM=
AC with<br>
=C2=A0 =C2=A0a SHA-2 hash for integrity.<br>
<br>
<br>
The IETF datatracker status page for this draft is:<br>
<a href=3D"https://datatracker.ietf.org/doc/draft-ietf-kitten-aes-cts-hmac-=
sha2/" rel=3D"noreferrer" target=3D"_blank">https://datatracker.ietf.org/<w=
br>doc/draft-ietf-kitten-aes-cts-<wbr>hmac-sha2/</a><br>
<br>
There&#39;s also a htmlized version available at:<br>
<a href=3D"https://tools.ietf.org/html/draft-ietf-kitten-aes-cts-hmac-sha2-=
11" rel=3D"noreferrer" target=3D"_blank">https://tools.ietf.org/html/<wbr>d=
raft-ietf-kitten-aes-cts-<wbr>hmac-sha2-11</a><br>
<br>
A diff from the previous version is available at:<br>
<a href=3D"https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-kitten-aes-cts-hm=
ac-sha2-11" rel=3D"noreferrer" target=3D"_blank">https://www.ietf.org/rfcdi=
ff?<wbr>url2=3Ddraft-ietf-kitten-aes-<wbr>cts-hmac-sha2-11</a><br>
<br>
<br>
Please note that it may take a couple of minutes from the time of submissio=
n<br>
until the htmlized version and diff are available at <a href=3D"http://tool=
s.ietf.org" rel=3D"noreferrer" target=3D"_blank">tools.ietf.org</a>.<br>
<br>
Internet-Drafts are also available by anonymous FTP at:<br>
<a href=3D"ftp://ftp.ietf.org/internet-drafts/" rel=3D"noreferrer" target=
=3D"_blank">ftp://ftp.ietf.org/internet-<wbr>drafts/</a><br>
<br>
______________________________<wbr>_________________<br>
Kitten mailing list<br>
<a href=3D"mailto:Kitten@ietf.org">Kitten@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/kitten" rel=3D"noreferrer"=
 target=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/kitten</a><br=
>
</div><br><br clear=3D"all"><br>-- <br><div class=3D"gmail_signature" data-=
smartmail=3D"gmail_signature"><div dir=3D"ltr"><div><div dir=3D"ltr">Mike J=
enkins<br><div><a href=3D"mailto:mjjenki@tycho.ncsc.mil" target=3D"_blank">=
mjjenki@tycho.ncsc.mil</a> - if you want me to read it only at my desk<br><=
/div><a href=3D"mailto:m.jenkins.364706@gmail.com" target=3D"_blank">m.jenk=
ins.364706@gmail.com</a> - to read everywhere<br>443-634-3951</div></div></=
div></div>
</div>

--001a114e1ff6cd7a50053afc9aef--


From nobody Sat Aug 27 23:07:39 2016
Return-Path: <ghudson@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5E60512D10C for <kitten@ietfa.amsl.com>; Sat, 27 Aug 2016 23:07:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.748
X-Spam-Level: 
X-Spam-Status: No, score=-4.748 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.548, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mkIpSBXv2wub for <kitten@ietfa.amsl.com>; Sat, 27 Aug 2016 23:07:37 -0700 (PDT)
Received: from dmz-mailsec-scanner-2.mit.edu (dmz-mailsec-scanner-2.mit.edu [18.9.25.13]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 20D3312D107 for <kitten@ietf.org>; Sat, 27 Aug 2016 23:07:36 -0700 (PDT)
X-AuditID: 1209190d-057ff70000003b22-a9-57c27fa3147e
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id 3A.D6.15138.3AF72C75; Sun, 28 Aug 2016 02:07:33 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id u7S67V4a030548 for <kitten@ietf.org>; Sun, 28 Aug 2016 02:07:31 -0400
Received: from [18.100.8.196] ([18.100.8.196]) (authenticated bits=0) (User authenticated as ghudson@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id u7S67Tb3005684 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT) for <kitten@ietf.org>; Sun, 28 Aug 2016 02:07:31 -0400
References: <147222928720.28387.15678500124278170272.idtracker@ietfa.amsl.com>
To: kitten@ietf.org
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <7f05e299-321a-3f85-c46e-74e39f3268ef@mit.edu>
Date: Sun, 28 Aug 2016 02:07:29 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.2.0
MIME-Version: 1.0
In-Reply-To: <147222928720.28387.15678500124278170272.idtracker@ietfa.amsl.com>
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrAIsWRmVeSWpSXmKPExsUixG6noru0/lC4wdxbahZHN69icWD0WLLk J1MAYxSXTUpqTmZZapG+XQJXxtxVE5kKvjFW/N7J38B4mbGLkZNDQsBE4s6jRUxdjFwcQgJt TBJnfyxmh3COM0psOHmRFcI5xCTRd2MdM0iLsICPxLftU4FsDqCEn8T9dTwgYREBYYndW9+B lbAJKEus37+VBaSEV8BKYu1bVZAwi4CqxP7pU8FKRAUiJG6t+gh2BK+AoMTJmU9YQGxOAX+J OWd6weLMAnoSO67/YoWw5SW2v53DPIGRfxaSlllIymYhKVvAyLyKUTYlt0o3NzEzpzg1Wbc4 OTEvL7VI10gvN7NELzWldBMjKPA4JXl3MP6763WIUYCDUYmH1+PHwXAh1sSy4srcQ4ySHExK orx3RIBCfEn5KZUZicUZ8UWlOanFhxglOJiVRHj31h4KF+JNSaysSi3Kh0lJc7AoifN2zTgQ LiSQnliSmp2aWpBaBJOV4eBQkuDVqANqFCxKTU+tSMvMKUFIM3FwggznARq+HKSGt7ggMbc4 Mx0if4pRl2PBj9trmYRY8vLzUqXEeZ+CXCAAUpRRmgc3B5wwUjiOvGIUB3pLmLcKZBQPMNnA TXoFtIQJaAnD6/0gS0oSEVJSDYxszV5HGJd9rjg+wU7ypinXai+HB7c0VaQXyG7bmpe26uO1 SR+/2e+YFmy9X/xPR9rW0MLdq2S/Mfktk7vML/8wY+fT6QW8Tj//1nurX2dIKPV5ZJdS/j1W 5WdUb7Ntpm3I4jMrEkPZYv2/xJRU9gscsznieOPbQoY9T551sbhuKWD9XZE600uJpTgj0VCL uag4EQCe91B/8wIAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/KEeVyg55lCoKzpDCaT0ev2p2x1k>
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-aes-cts-hmac-sha2-11.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 28 Aug 2016 06:07:38 -0000

On 08/26/2016 12:34 PM, internet-drafts@ietf.org wrote:
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-kitten-aes-cts-hmac-sha2-11

I have looked over these changes and they all seem fine.


From nobody Sun Aug 28 11:56:50 2016
Return-Path: <prvs=1048daf746=jaltman@secure-endpoints.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 55E1712D091 for <kitten@ietfa.amsl.com>; Sun, 28 Aug 2016 11:56:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=secure-endpoints.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id apGLgtuwBLSQ for <kitten@ietfa.amsl.com>; Sun, 28 Aug 2016 11:56:48 -0700 (PDT)
Received: from sequoia-grove.secure-endpoints.com (sequoia-grove.ad.secure-endpoints.com [208.125.0.235]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E955E12B054 for <kitten@ietf.org>; Sun, 28 Aug 2016 11:56:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=secure-endpoints.com; s=MDaemon; t=1472410606; x=1473015406; i=jaltman@secure-endpoints.com; q=dns/txt; h=VBR-Info:From: Subject:To:References:Openpgp:Organization:Message-ID:Date: User-Agent:MIME-Version:In-Reply-To:Content-Type; bh=2Umq1/SiUj+ 4fgLlN/LUSg8LQC+SUf6+oN67UNvVXnI=; b=QxjhZT+VvhV7NxQf9N1bHLG3PJn HMTGYkTcT80vhHfDwFY97C3Qk1BGQJrg2g3ICbANm5Muu0hbJEUnOJkeNVkdPC19 dC6WJCBp6rheFNo1s18VJv4yJ4HpIFoSHc9WFkGSEBtZrj6csgaW9XAz/kvBtrGL vX8n1WDgO4UGCwIs=
X-MDAV-Result: clean
X-MDAV-Processed: sequoia-grove.secure-endpoints.com, Sun, 28 Aug 2016 14:56:46 -0400
X-Spam-Processed: sequoia-grove.secure-endpoints.com, Sun, 28 Aug 2016 14:56:46 -0400
Received: from [x.x.x.x] by secure-endpoints.com (Cipher TLSv1:AES-SHA:256) (MDaemon PRO v16.0.4)  with ESMTPSA id md50001141512.msg for <kitten@ietf.org>; Sun, 28 Aug 2016 14:56:46 -0400
VBR-Info: md=secure-endpoints.com; mc=all; mv=vbr.emailcertification.org;
X-MDArrival-Date: Sun, 28 Aug 2016 14:56:46 -0400
X-Authenticated-Sender: jaltman@secure-endpoints.com
X-Return-Path: prvs=1048daf746=jaltman@secure-endpoints.com
X-Envelope-From: jaltman@secure-endpoints.com
X-MDaemon-Deliver-To: kitten@ietf.org
From: Jeffrey Altman <jaltman@secure-endpoints.com>
To: kitten@ietf.org
References: <147222928720.28387.15678500124278170272.idtracker@ietfa.amsl.com> <CAC2=hne-s-7r_z6xuafOxgSBsp+zj_f-FPYbgh1J=oMRWm57vw@mail.gmail.com>
Openpgp: id=FA444AF197F449B24CF3E699F77A735592B69A04; url=http://pgp.mit.edu
Organization: Secure Endpoints Inc.
Message-ID: <65e6b5e7-f34a-8166-7425-e5ccd395aa36@secure-endpoints.com>
Date: Sun, 28 Aug 2016 14:56:45 -0400
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.2.0
MIME-Version: 1.0
In-Reply-To: <CAC2=hne-s-7r_z6xuafOxgSBsp+zj_f-FPYbgh1J=oMRWm57vw@mail.gmail.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha-256; boundary="------------ms040800080302050406090508"
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/iNNikuNEHi7ZBNBQi3mUZrU5rKU>
Subject: Re: [kitten] Fwd: I-D Action: draft-ietf-kitten-aes-cts-hmac-sha2-11.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 28 Aug 2016 18:56:49 -0000

This is a cryptographically signed message in MIME format.

--------------ms040800080302050406090508
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

On 8/26/2016 1:11 PM, Michael Jenkins wrote:
> This update is in response to comments made so far during IESG review. =
It
> contains several clarifications but no changes that required test vecto=
r
> regeneration.


The changes look good to me.

Thank you.

Jeffrey Altman




--------------ms040800080302050406090508
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCC
DFkwggYVMIIE/aADAgECAhBwEYNf9/MBLeKNZZ697cPvMA0GCSqGSIb3DQEBCwUAMIGmMQsw
CQYDVQQGEwJVUzEdMBsGA1UEChMUU3ltYW50ZWMgQ29ycG9yYXRpb24xHzAdBgNVBAsTFlN5
bWFudGVjIFRydXN0IE5ldHdvcmsxHjAcBgNVBAsTFVBlcnNvbmEgTm90IFZhbGlkYXRlZDE3
MDUGA1UEAxMuU3ltYW50ZWMgQ2xhc3MgMSBJbmRpdmlkdWFsIFN1YnNjcmliZXIgQ0EgLSBH
NTAeFw0xNTEyMjAwMDAwMDBaFw0xNjEyMjAyMzU5NTlaMIGvMS4wLAYDVQQDDCVQZXJzb25h
IE5vdCBWYWxpZGF0ZWQgLSAxNDUwNTc0MTU1Njc5MSswKQYJKoZIhvcNAQkBFhxqYWx0bWFu
QHNlY3VyZS1lbmRwb2ludHMuY29tMQ8wDQYDVQQLDAZTL01JTUUxHjAcBgNVBAsMFVBlcnNv
bmEgTm90IFZhbGlkYXRlZDEfMB0GA1UECwwWU3ltYW50ZWMgVHJ1c3QgTmV0d29yazCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM0X8uixbo9Tu+sKS20bZeCbN9brFQbtkQ5x
/6MrkGsQNTzQ/2WZFJzH89ZoC8auZRFQdA6/yh4wXdCNQ6hBO8Lom26t0LHGhoWtzdkP7MWu
YeLMZiuOsC6N6ejHEbtt0KLjphNIUvBVFx5JQzgAwJ1I08LSZg/bIGAVF3SfLOVFu2Iiq5kj
psHOv/ECV13fGSvYwBXJN1C1To6wxDgn4pl3m6fFfe4xiVEpc3t6GbKcI+4blK9w76fDaVXw
U2uJQAG1UYxbChwocBmb3ka1MlUb2ug3oYBpnufD9zk8u3UqaFlfYyr6/2cr6fqiz1U4+xcb
Q3otvVWwzRecpmPEiIcCAwEAAaOCAjIwggIuMAwGA1UdEwEB/wQCMAAwDgYDVR0PAQH/BAQD
AgWgMCAGA1UdJQEB/wQWMBQGCCsGAQUFBwMEBggrBgEFBQcDAjAdBgNVHQ4EFgQU2Pc1OxE6
W8hcBZ5L2346cucbFa8wJwYDVR0RBCAwHoEcamFsdG1hbkBzZWN1cmUtZW5kcG9pbnRzLmNv
bTBsBgNVHSAEZTBjMGEGC2CGSAGG+EUBBxcBMFIwJgYIKwYBBQUHAgEWGmh0dHA6Ly93d3cu
c3ltYXV0aC5jb20vY3BzMCgGCCsGAQUFBwICMBwaGmh0dHA6Ly93d3cuc3ltYXV0aC5jb20v
cnBhMF0GA1UdHwRWMFQwUqBQoE6GTGh0dHA6Ly9wa2ktY3JsLnN5bWF1dGguY29tL2NhXzU3
ZGU3YTIzOGQ0NWQ4ZDRmYzcxZjhhNWM2YjgxYzkzL0xhdGVzdENSTC5jcmwwTgYIKwYBBQUH
AQEEQjBAMD4GCCsGAQUFBzAChjJodHRwOi8vY2FjZXIuc3ltYXV0aC5jb20vbXBraS9zeW1j
YzFpbmRzdWJjYWc1LmNydDAfBgNVHSMEGDAWgBRnGbY9pXm7M2DYLVPTjAk9B6wYcDArBgpg
hkgBhvhFARADBB0wGwYSYIZIAYb4RQEQAQICBAGt7pITFgUxMDkyMjA5BgpghkgBhvhFARAF
BCswKQIBABYkYUhSMGNITTZMeTl3YTJrdGNtRXVjM2x0WVhWMGFDNWpiMjA9MA0GCSqGSIb3
DQEBCwUAA4IBAQBvO/+L6Tms91Ed1ZJzgT0y9jBK/Armb6Y/EnR1swCDMqRfBzGSGtzOCuN7
PteBvlaB5vmnwEwiZR/FtsDhhORd8Xy5wdmCunhwPbf0ClnBqichI+4UZNS5fCQTciIqHFxq
7EKuHOQm4/ssEH2Xr8yIpCd+Dx9oPEG7MqUno6oxcIDdur4iNKxOBtjWNiXM7rn733qtuFlw
1jIX3eFIsrBALikTU1UbY2KwfewXbiVaFWY0ysl5uOgfWdmj2xBk7aft/L/fnuyWyeeM9IBg
6vdUjPhmJwtFdEdefgP5cRRdYgG8zgJf8Rq84slkea0bwis8PvKVksJ/k2scaDHzKTe2MIIG
PDCCBSSgAwIBAgIQBwKiGoW4S2WeGApu5vWjZTANBgkqhkiG9w0BAQsFADCByjELMAkGA1UE
BhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQLExZWZXJpU2lnbiBUcnVz
dCBOZXR3b3JrMTowOAYDVQQLEzEoYykgMTk5OSBWZXJpU2lnbiwgSW5jLiAtIEZvciBhdXRo
b3JpemVkIHVzZSBvbmx5MUUwQwYDVQQDEzxWZXJpU2lnbiBDbGFzcyAxIFB1YmxpYyBQcmlt
YXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5IC0gRzMwHhcNMTUxMDAxMDAwMDAwWhcNMjUw
OTMwMjM1OTU5WjCBpjELMAkGA1UEBhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0
aW9uMR8wHQYDVQQLExZTeW1hbnRlYyBUcnVzdCBOZXR3b3JrMR4wHAYDVQQLExVQZXJzb25h
IE5vdCBWYWxpZGF0ZWQxNzA1BgNVBAMTLlN5bWFudGVjIENsYXNzIDEgSW5kaXZpZHVhbCBT
dWJzY3JpYmVyIENBIC0gRzUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDW+w0x
SSLADLrvTi0XuLQw5TTSrAnuyYkAXfSuExGzE45VzyIYqCAGpv0ly2iUtKCCkA5ulpJE7hW5
tOz6z3k9adScH9wgmg4o1Q21xp468dRlGcCEM02O2orx1ie5A6DR+iicgpNs9w2FfVvpTpli
/pNC0u4+s3FXhpdGy98N4caEWrMNj/X0EIoFXZ9oRuwIsFhCgva+LRBGpiQLJ/6YFFODk4Lb
6sA/T6JYYbVLcmkSXzNZ9vmzTABkzoXFhpIMbhzrKM9xqZCpdJl0JOtI4Q5daBKoAWbo7pqy
L/g9zbd4JM6lYHzoFj1J8Qe6M74yK8JnoxbHb8DSWpQEwmtFAgMBAAGjggI+MIICOjA3Bggr
BgEFBQcBAQQrMCkwJwYIKwYBBQUHMAGGG2h0dHA6Ly9wa2ktb2NzcC5zeW1hdXRoLmNvbTAS
BgNVHRMBAf8ECDAGAQH/AgEAMGwGA1UdIARlMGMwYQYLYIZIAYb4RQEHFwEwUjAmBggrBgEF
BQcCARYaaHR0cDovL3d3dy5zeW1hdXRoLmNvbS9jcHMwKAYIKwYBBQUHAgIwHBoaaHR0cDov
L3d3dy5zeW1hdXRoLmNvbS9ycGEwLwYDVR0fBCgwJjAkoCKgIIYeaHR0cDovL3Muc3ltY2Iu
Y29tL3BjYTEtZzMuY3JsMA4GA1UdDwEB/wQEAwIBBjApBgNVHREEIjAgpB4wHDEaMBgGA1UE
AxMRU3ltYW50ZWNQS0ktMi0yMTcwHQYDVR0OBBYEFGcZtj2lebszYNgtU9OMCT0HrBhwMIHx
BgNVHSMEgekwgeahgdCkgc0wgcoxCzAJBgNVBAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwg
SW5jLjEfMB0GA1UECxMWVmVyaVNpZ24gVHJ1c3QgTmV0d29yazE6MDgGA1UECxMxKGMpIDE5
OTkgVmVyaVNpZ24sIEluYy4gLSBGb3IgYXV0aG9yaXplZCB1c2Ugb25seTFFMEMGA1UEAxM8
VmVyaVNpZ24gQ2xhc3MgMSBQdWJsaWMgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0
eSAtIEczghEAi1t1VoRUhQsAz684SM6xpDANBgkqhkiG9w0BAQsFAAOCAQEARhnkJ3U7vq/i
2qIUYI8eRJCBaStjSTWN6Xa6n5iPE4HXy/xlG/gOY96UKHT742/YySp6DlSmg64pSvYrUf09
OBK73WNF+2TMPlSGf05CbSO3HQv9+swNjpM1yuVF+c8vf3k9YxjHRyNK9qkUAK1+WVUaiSfb
lKCROMb+QJWjYPZduMjFFu2cZmkURhBKynAqb9FQ4CYa01K0R3KLRdK9A7ml3NkI85CrdHCr
yqBO8MBO5OC+T5ARYCcMKxzf52zKdbQl55FIqpK0UXVfKZtHFxy9yerPda11I8/yxd9aq7dr
yru4XqvVo3DUaPMXepsLoBQ8++iBVmjoz118c7guvDGCBGIwggReAgEBMIG7MIGmMQswCQYD
VQQGEwJVUzEdMBsGA1UEChMUU3ltYW50ZWMgQ29ycG9yYXRpb24xHzAdBgNVBAsTFlN5bWFu
dGVjIFRydXN0IE5ldHdvcmsxHjAcBgNVBAsTFVBlcnNvbmEgTm90IFZhbGlkYXRlZDE3MDUG
A1UEAxMuU3ltYW50ZWMgQ2xhc3MgMSBJbmRpdmlkdWFsIFN1YnNjcmliZXIgQ0EgLSBHNQIQ
cBGDX/fzAS3ijWWeve3D7zANBglghkgBZQMEAgEFAKCCAncwGAYJKoZIhvcNAQkDMQsGCSqG
SIb3DQEHATAcBgkqhkiG9w0BCQUxDxcNMTYwODI4MTg1NjQ1WjAvBgkqhkiG9w0BCQQxIgQg
Py7/i0M7LV0EaL23dJxkQ5E7IeT+9Dmsp+cElzPyMswwbAYJKoZIhvcNAQkPMV8wXTALBglg
hkgBZQMEASowCwYJYIZIAWUDBAECMAoGCCqGSIb3DQMHMA4GCCqGSIb3DQMCAgIAgDANBggq
hkiG9w0DAgIBQDAHBgUrDgMCBzANBggqhkiG9w0DAgIBKDCBzAYJKwYBBAGCNxAEMYG+MIG7
MIGmMQswCQYDVQQGEwJVUzEdMBsGA1UEChMUU3ltYW50ZWMgQ29ycG9yYXRpb24xHzAdBgNV
BAsTFlN5bWFudGVjIFRydXN0IE5ldHdvcmsxHjAcBgNVBAsTFVBlcnNvbmEgTm90IFZhbGlk
YXRlZDE3MDUGA1UEAxMuU3ltYW50ZWMgQ2xhc3MgMSBJbmRpdmlkdWFsIFN1YnNjcmliZXIg
Q0EgLSBHNQIQcBGDX/fzAS3ijWWeve3D7zCBzgYLKoZIhvcNAQkQAgsxgb6ggbswgaYxCzAJ
BgNVBAYTAlVTMR0wGwYDVQQKExRTeW1hbnRlYyBDb3Jwb3JhdGlvbjEfMB0GA1UECxMWU3lt
YW50ZWMgVHJ1c3QgTmV0d29yazEeMBwGA1UECxMVUGVyc29uYSBOb3QgVmFsaWRhdGVkMTcw
NQYDVQQDEy5TeW1hbnRlYyBDbGFzcyAxIEluZGl2aWR1YWwgU3Vic2NyaWJlciBDQSAtIEc1
AhBwEYNf9/MBLeKNZZ697cPvMA0GCSqGSIb3DQEBAQUABIIBALpL8S53yzQecHj4HIB0tHFQ
v0q1Y6fP9XTbRaoYHEgKQ9X1SNLK62HosSimih6xZHmBwhIJD1PlUICRaferOYjqrtK2NnVf
4FhNunY9ODHCtHCUS/JO9E63jLAGYo6xlzfbkmY2CC4pvmlNtuz7emlIxAjBWugzNyf6ezSq
ppIx29VPVvkEOjIfC4fOxYuj2vjU3imM+Ep92bqWdLbHySkVLDnhg3UNsgacm5VOMEOMwXV2
oOrDJr/tQL//DEg5AI5vwvr82cKVKO/sEvyj3XBTv0OjhueQTvwErVbs2qJGXgVNKO8qiOLC
GxxiU4xq/3V3rXkuajaKfMMkH9RGQ38AAAAAAAA=
--------------ms040800080302050406090508--


From nobody Mon Aug 29 21:14:39 2016
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EACDF12D0F4 for <kitten@ietfa.amsl.com>; Mon, 29 Aug 2016 21:14:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.749
X-Spam-Level: 
X-Spam-Status: No, score=-4.749 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.548, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7Bi2sWR59aBj for <kitten@ietfa.amsl.com>; Mon, 29 Aug 2016 21:14:36 -0700 (PDT)
Received: from dmz-mailsec-scanner-6.mit.edu (dmz-mailsec-scanner-6.mit.edu [18.7.68.35]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3F29812D0E7 for <kitten@ietf.org>; Mon, 29 Aug 2016 21:14:36 -0700 (PDT)
X-AuditID: 12074423-9b7ff70000005a36-f7-57c5082ac3fc
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id 30.E0.23094.A2805C75; Tue, 30 Aug 2016 00:14:35 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id u7U4EXkR031158; Tue, 30 Aug 2016 00:14:34 -0400
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id u7U4EVh8029802 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Tue, 30 Aug 2016 00:14:33 -0400
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id u7U4EUri010695; Tue, 30 Aug 2016 00:14:30 -0400 (EDT)
Date: Tue, 30 Aug 2016 00:14:30 -0400 (EDT)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Michael Jenkins <m.jenkins.364706@gmail.com>
In-Reply-To: <CAC2=hne-s-7r_z6xuafOxgSBsp+zj_f-FPYbgh1J=oMRWm57vw@mail.gmail.com>
Message-ID: <alpine.GSO.1.10.1608300014220.5272@multics.mit.edu>
References: <147222928720.28387.15678500124278170272.idtracker@ietfa.amsl.com> <CAC2=hne-s-7r_z6xuafOxgSBsp+zj_f-FPYbgh1J=oMRWm57vw@mail.gmail.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrEIsWRmVeSWpSXmKPExsUixG6noqvNcTTc4MIpJoujm1exWCz7dpXN gclj56y77B5LlvxkCmCK4rJJSc3JLEst0rdL4MrYtXc2c0GHUEXL/CmsDYyfebsYOTkkBEwk WlddY+xi5OIQEmhjkrh36DKUs5FRYtKKaUwQziEmieZn99khnAZGiUOdixhB+lkEtCUaPrxi AbHZBFQkZr7ZyAZiiwgYSCyatA7MZhYQllh/bgZzFyMHh7BAsMT/NxkgYU6BQIljZ3+ClfAK OEi8e3+LFWL+ZEaJ03PbwGaKCuhIrN4/hQWiSFDi5MwnLBAztSSWT9/GMoFRYBaS1CwkqQWM TKsYZVNyq3RzEzNzilOTdYuTE/PyUot0zfRyM0v0UlNKNzGCg9JFeQfjyz7vQ4wCHIxKPLwW TkfChVgTy4orcw8xSnIwKYnyTo0HCvEl5adUZiQWZ8QXleakFh9ilOBgVhLhfcd2NFyINyWx siq1KB8mJc3BoiTO2zXjQLiQQHpiSWp2ampBahFMVoaDQ0mCV40dqFGwKDU9tSItM6cEIc3E wQkynAdoeDRIDW9xQWJucWY6RP4Uo6KUOK8JyFYBkERGaR5cLzhp7GZSfcUoDvSKMK8rSDsP MOHAdb8CGswENLjgzmGQwSWJCCmpBkbtIxlzFa5YvV1/RdaFhd/j47IPBXbFZ3neHenZ/Fl8 82HunVqabQ2fs6Of/nDyvXkioMRKfN73YNc0XTnTg9dXvxK5KSiuua8+Id3UbnJI87zbS197 iDd1tUcJnBThY3ucIBm1+uyCr2obT/woPD1bcccjq6R9/YskrSzncytUq7r2nfWed06JpTgj 0VCLuag4EQCM0vuh9QIAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/lZlNtW7A37cFB7eEJR6mB-uugls>
Cc: kitten@ietf.org
Subject: Re: [kitten] Fwd: I-D Action: draft-ietf-kitten-aes-cts-hmac-sha2-11.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 Aug 2016 04:14:38 -0000

Thanks for the updates; they look good to me.

-Ben

On Fri, 26 Aug 2016, Michael Jenkins wrote:

> This update is in response to comments made so far during IESG review. It
> contains several clarifications but no changes that required test vector
> regeneration.
>
> ---------- Forwarded message ----------
> From: <internet-drafts@ietf.org>
> Date: Fri, Aug 26, 2016 at 12:34 PM
> Subject: [kitten] I-D Action: draft-ietf-kitten-aes-cts-hmac-sha2-11.txt
> To: i-d-announce@ietf.org
> Cc: kitten@ietf.org
>
>
>
> A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
> This draft is a work item of the Common Authentication Technology Next
> Generation of the IETF.
>
>         Title           : AES Encryption with HMAC-SHA2 for Kerberos 5
>         Authors         : Michael J. Jenkins
>                           Michael A. Peck
>                           Kelley W. Burgin
>         Filename        : draft-ietf-kitten-aes-cts-hmac-sha2-11.txt
>         Pages           : 18
>         Date            : 2016-08-26
>
> Abstract:
>    This document specifies two encryption types and two corresponding
>    checksum types for Kerberos 5.  The new types use AES in CTS mode
>    (CBC mode with ciphertext stealing) for confidentiality and HMAC with
>    a SHA-2 hash for integrity.
>
>
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-kitten-aes-cts-hmac-sha2/
>
> There's also a htmlized version available at:
> https://tools.ietf.org/html/draft-ietf-kitten-aes-cts-hmac-sha2-11
>
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-kitten-aes-cts-hmac-sha2-11
>
>
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
> _______________________________________________
> Kitten mailing list
> Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten
>
>
>
> --
> Mike Jenkins
> mjjenki@tycho.ncsc.mil - if you want me to read it only at my desk
> m.jenkins.364706@gmail.com - to read everywhere
> 443-634-3951
>


From nobody Mon Aug 29 21:38:00 2016
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8DA6512D09B for <kitten@ietfa.amsl.com>; Mon, 29 Aug 2016 21:37:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.749
X-Spam-Level: 
X-Spam-Status: No, score=-4.749 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.548, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nDeV-rweqg7A for <kitten@ietfa.amsl.com>; Mon, 29 Aug 2016 21:37:57 -0700 (PDT)
Received: from dmz-mailsec-scanner-2.mit.edu (dmz-mailsec-scanner-2.mit.edu [18.9.25.13]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D33D5127A90 for <kitten@ietf.org>; Mon, 29 Aug 2016 21:37:56 -0700 (PDT)
X-AuditID: 1209190d-517ff700000061ff-9e-57c50da30a7a
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id 9C.32.25087.3AD05C75; Tue, 30 Aug 2016 00:37:55 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id u7U4btiH032536 for <kitten@ietf.org>; Tue, 30 Aug 2016 00:37:55 -0400
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id u7U4bqKe001860 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Tue, 30 Aug 2016 00:37:54 -0400
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id u7U4bpJZ013628; Tue, 30 Aug 2016 00:37:51 -0400 (EDT)
Date: Tue, 30 Aug 2016 00:37:51 -0400 (EDT)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
Message-ID: <alpine.GSO.1.10.1608300036380.5272@multics.mit.edu>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: MULTIPART/MIXED; BOUNDARY="-559023410-68439564-1472531871=:5272"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFjrNIsWRmVeSWpSXmKPExsUixG6noruY92i4wf8uPYujm1exODB6LFny kymAMYrLJiU1J7MstUjfLoErY8XOS0wF03grZl36xdjA+JSri5GTQ0LARGL+s37WLkYuDiGB NiaJW3+/QDnHGSU6vr9kgXBuMElMmvAEymlglJhzZA4TSD+LgLbE2snnWUBsNgEViZlvNrKB 2CICwhK7t75jBrGFBcIkljw+CVTDwcEr4CCx8oQ9SFhUQEdi9f4pYK28AoISJ2c+AbOZBfwk tr68xTKBkXcWktQsJCkIW12i8cFZNghbW+L+zTa2BYwsqxhlU3KrdHMTM3OKU5N1i5MT8/JS i3SN9HIzS/RSU0o3MYLCjFOSdwfjv7tehxgFOBiVeHgtnI6EC7EmlhVX5h5ilORgUhLlnRoP FOJLyk+pzEgszogvKs1JLT7EKMHBrCTC+47taLgQb0piZVVqUT5MSpqDRUmct2vGgXAhgfTE ktTs1NSC1CKYrAwHh5IE7yEeoEbBotT01Iq0zJwShDQTByfIcB6g4Qy8IMOLCxJzizPTIfKn GBWlxHnPgTQLgCQySvPgesFpYDeT6itGcaBXhHnNQKp4gCkErvsV0GAmoMEFdw6DDC5JREhJ NTA6n7l6eNP22p06O9r5VdQZbvkaJ7Mw7vNctLk9irNwo1Xz7HdC2eZVn6trnBZyW8rPNN/s 0vX67PULak98ip4bbzO59ffJD+EwaZ4Pds+O13kUKbIvu7hPYk/f8b/3DVgUmjJk7EI4WQxb lwZa5E1IKvudzfbVfJ1WUf4H03VrTtc9Fr1toqfEUpyRaKjFXFScCADh5PmO3gIAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/G5qFRQqBAwOrQiiRR9VziFbx76c>
Subject: Re: [kitten] call for reviews of draft-ietf-kitten-krb-auth-indicator (fwd)
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 Aug 2016 04:37:58 -0000

  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

---559023410-68439564-1472531871=:5272
Content-Type: TEXT/PLAIN; charset=utf-8
Content-Transfer-Encoding: QUOTED-PRINTABLE

I don't see this message in the archives at
https://www.ietf.org/mail-archive/web/kitten/current/maillist.html, so I'm
forwarding a copy to get it in the records.

-Ben

---------- Forwarded message ----------
Date: Tue, 9 Aug 2016 19:48:35 -0400
From: Gerard Gagliano <gerardg@comcast.net>
To: Benjamin Kaduk <kaduk@mit.edu>
Cc: kitten@ietf.org
Subject: Re: [kitten] call for reviews of draft-ietf-kitten-krb-auth-indica=
tor

Thanks for this important work.  I=E2=80=99m glad to see this finally codif=
ied, it will be very important.  I think it looks great (especially the ass=
ignment of the AD type 97!).

+1 for -02

Gerard

--
> On Aug 9, 2016, at 9:46 AM, Benjamin Kaduk <kaduk@mit.edu> wrote:
>
> This document is being implemented and is likely ready to advance to the
> IESG, but as Nathaniel noted at the end of June, it's only had Greg's
> review of the -02, my review of the precursor draft, and whatever review
> Tom did when the authdata number was assigned.  It would be good to get a
> couple more reviews before we send this document over to the IESG, even i=
f
> we are going to try out the new scheme that skips a formal WGLC.
>
> -Ben
> for the kitten chairs
>
> _______________________________________________
> Kitten mailing list
> Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten

---559023410-68439564-1472531871=:5272--


From nobody Tue Aug 30 18:51:54 2016
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C5C8512D870 for <kitten@ietfa.amsl.com>; Tue, 30 Aug 2016 18:51:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.769
X-Spam-Level: 
X-Spam-Status: No, score=-4.769 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.548, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fJl8lPhkXh6i for <kitten@ietfa.amsl.com>; Tue, 30 Aug 2016 18:51:50 -0700 (PDT)
Received: from dmz-mailsec-scanner-3.mit.edu (dmz-mailsec-scanner-3.mit.edu [18.9.25.14]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A51F412B032 for <kitten@ietf.org>; Tue, 30 Aug 2016 18:51:50 -0700 (PDT)
X-AuditID: 1209190e-297ff70000002766-52-57c6383500b5
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id 37.EE.10086.53836C75; Tue, 30 Aug 2016 21:51:49 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id u7V1pmXY008596; Tue, 30 Aug 2016 21:51:48 -0400
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id u7V1pjCB018192 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Tue, 30 Aug 2016 21:51:48 -0400
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id u7V1pi5E022585; Tue, 30 Aug 2016 21:51:44 -0400 (EDT)
Date: Tue, 30 Aug 2016 21:51:44 -0400 (EDT)
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: kitten@ietf.org
In-Reply-To: <1467033683.2592.2.camel@redhat.com>
Message-ID: <alpine.GSO.1.10.1608302133320.5272@multics.mit.edu>
References: <20160516161709.16705.29515.idtracker@ietfa.amsl.com> <1463416879.2542.15.camel@redhat.com> <1466709219.20951.3.camel@redhat.com> <alpine.GSO.1.10.1606252344350.18480@multics.mit.edu> <1467033683.2592.2.camel@redhat.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: MULTIPART/MIXED; boundary="-559023410-1861363274-1472607833=:5272"
Content-ID: <alpine.GSO.1.10.1608302148290.5272@multics.mit.edu>
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFlrKKsWRmVeSWpSXmKPExsUixG6nomtqcSzcYN89RYujm1exWMz9OovV gcljyZKfTB7v911lC2CK4rJJSc3JLEst0rdL4Mr49GgLa8E2g4pHh3ewNzD+Vuti5OSQEDCR uL1jKlsXIxeHkEAbk0Tz+6usEM5GRol/p/+wg1QJCRxiknjRoQaRaGCU+H+5jw0kwSKgLTF5 wwQmEJtNQEVi5puNYHERAWGJ3VvfMYPYzAJ6En2z1gMN4uAQFtCVOPpGEyTMKWAose3QPrBW XgEHie3HrjFDzH/FKHHy33ywXlEBHYnV+6ewQBQJSpyc+YQFZA6zQIDElG0CEKaDxNG7wRMY BWchKZqFUDQLoWgW2Dm6Em9WHWSCsLUl7t9sY4OwHSQOn9/PuoCRbRWjbEpulW5uYmZOcWqy bnFyYl5eapGusV5uZoleakrpJkZQDHBK8u1gnNTgfYhRgINRiYf3wKyj4UKsiWXFlbmHGCU5 mJREecP/AoX4kvJTKjMSizPii0pzUosPMUpwMCuJ8P4yPhYuxJuSWFmVWpQPk5LmYFES5+2a cSBcSCA9sSQ1OzW1ILUIJivDwaEkwfvLDKhRsCg1PbUiLTOnBCHNxMEJMpwHaPhykBre4oLE 3OLMdIj8KUZdjp4JN9YyCbHk5eelSonzRoIUCYAUZZTmwc0Bp67dTKqvGMWB3hLmTTAHquIB pj24ScD4AfpOhLfgzmGQJSWJCCmpBsZG3dkaacc+bzvUVjtZKJt/R2iXy4lK11exeSl1igqR /49E75Otumxy/NEP+wnVLhx5TwT/PxQ5HDa3dUXum30ha4S3qLyK4LLlLdxWsPDer1ruiYou +Xl31HPZ0iYy9C1/ePUBu1cmi+LmqUbXvGW9Hx9qTubMc63YqrSlJ7Fo0Wbzri4LFyWW4oxE Qy3mouJEAD9KveM4AwAA
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/OLH1iOZ5o-q5uatrHtp5SAWzxew>
Subject: [kitten] advancing some documents to the IESG
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 Aug 2016 01:51:53 -0000

  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

---559023410-1861363274-1472607833=:5272
Content-Type: TEXT/PLAIN; charset=ISO-8859-15
Content-Transfer-Encoding: QUOTED-PRINTABLE
Content-ID: <alpine.GSO.1.10.1608302148291.5272@multics.mit.edu>

(was Re: [kitten] I-D Action: draft-ietf-kitten-krb-auth-indicator-02.txt)

Looping back to this thread, now that we have the extra reviews from
Richard and Gerard, the chairs are comfortable advancing it to the IESG; I
will shepherd.  In accordance with our new workflow, there will not be an
additional WGLC, but feel free to comment (or object) at any time.

We also have draft-ietf-kitten-rfc6112bis active, for which Shawn has
published an updated version (with help from the secretariat).  It needs a
few more tweaks to the wording and attack description, but the core
protocol portions look good, so once the revisions are in place, that can
also move forward to the IESG.  As always, comments are always welcome.

draft-ietf-kitten-rfc5653bis went through WGLC at the same time as
rfc6112bis, and also has an updated version as a result of the comments
from WGLC.  (As a reminder: the main goal is to allow GSSAPI error tokens
to be generated along with the GSSException that indicates the failure,
but the review also indicated issues with the stream-based GSSContext
methods, leading to their removal from the current draft.)  Richard,
Gerard, and everyone else are encouraged to review that document.

draft-ietf-kitten-pkinit-freshness is waiting for a shepherd writeup and
then is expected to advance to the IESG.

In other PKINIT-related work, the most recent threads the chairs have
about draft-ietf-kitten-pkinit-alg-agility indicate that it should also be
ready to advance, but given how long ago they were, some additional
research is in order to verify that.  More (re-)reviews wouldn't hurt,
either!

Please feel free to contact the chairs (or the list) with any questions,
concerns, or most especially document reviews.

-Ben
for the kitten chairs



On Mon, 27 Jun 2016, Nathaniel McCallum wrote:

> I'm happy to do so. But, AFAIK, the only review thus far has been
> yours. There were several other +1's to WG adoption, but no other
> reviews.
>
> On Sat, 2016-06-25 at 23:46 -0400, Benjamin Kaduk wrote:
> > Yes, it would be good to move this document forward, especially since
> > it
> > already has implementation experience.=A0 Would you be interested in
> > trying
> > out the proposal to manually track reviews and (mostly) skip WGLC for
> > this
> > document?=A0 That thread has not gotten many responses yet...
> >
> > -Ben
> >
> > On Thu, 23 Jun 2016, Nathaniel McCallum wrote:
> >
> > > I propsed this and hear no response. Can we move this draft
> > forward?
> > >
> > > On Mon, 2016-05-16 at 12:41 -0400, Nathaniel McCallum wrote:
> > > > With this revision, I believe that we are in the home stretch on
> > this
> > > > draft. Unless anyone has any objections, I'd like to request that
> > the
> > > > chairs begin WGLC.
> > > >
> > > > On Mon, 2016-05-16 at 09:17 -0700, internet-drafts@ietf.org=A0wrote
> > :
> > > > > A New Internet-Draft is available from the on-line Internet-
> > Drafts
> > > > > directories.
> > > > > This draft is a work item of the Common Authentication
> > Technology
> > > > > Next Generation of the IETF.
> > > > >
> > > > > =A0=A0=A0=A0=A0=A0=A0=A0Title=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0: A=
uthentication Indicator in Kerberos
> > > > > Tickets
> > > > > =A0=A0=A0=A0=A0=A0=A0=A0Authors=A0=A0=A0=A0=A0=A0=A0=A0=A0: Anupa=
m Jain
> > > > > =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0Nathan Kinder
> > > > > =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0Nathaniel McCallum
> > > > >=A0=A0=A0Filename=A0=A0=A0=A0=A0=A0=A0=A0: draft-ietf-kitten-krb-a=
uth-indicator-02.txt
> > > > >=A0=A0=A0Pages=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0: 5
> > > > >=A0=A0=A0Date=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0: 2016-05-16
> > > > >
> > > > > Abstract:
> > > > > =A0=A0=A0This document specifies an extension in the Kerberos
> > protocol
> > > > > =A0=A0=A0[RFC4120].=A0=A0It defines a new authorization data type=
 AD-
> > > > > =A0=A0=A0AUTHENTICATION-INDICATOR.=A0=A0The purpose of introducin=
g this
> > data
> > > > > type
> > > > > =A0=A0=A0is to include an indicator of the strength of a client's
> > > > > =A0=A0=A0authentication in the service tickets so that applicatio=
n
> > > > > services
> > > > > =A0=A0=A0can use it as an input into policy decisions.
> > > > >
> > > > >
> > > > > The IETF datatracker status page for this draft is:
> > > > > https://datatracker.ietf.org/doc/draft-ietf-kitten-krb-auth-ind
> > icat
> > > > > or
> > > > > /
> > > > >
> > > > > There's also a htmlized version available at:
> > > > > https://tools.ietf.org/html/draft-ietf-kitten-krb-auth-indicato
> > r-02
> > > > >
> > > > > A diff from the previous version is available at:
> > > > > https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-kitten-krb-auth-in
> > dica
> > > > > to
> > > > > r-02
> > > > >
> > > > >
> > > > > Please note that it may take a couple of minutes from the time
> > of
> > > > > submission
> > > > > until the htmlized version and diff are available at
> > > > > tools.ietf.org.
> > > > >
> > > > > Internet-Drafts are also available by anonymous FTP at:
> > > > > ftp://ftp.ietf.org/internet-drafts/
> > > > >
> > > > > _______________________________________________
> > > > > Kitten mailing list
> > > > > Kitten@ietf.org
> > > > > https://www.ietf.org/mailman/listinfo/kitten
> > > >
> > > > _______________________________________________
> > > > Kitten mailing list
> > > > Kitten@ietf.org
> > > > https://www.ietf.org/mailman/listinfo/kitten
> > >
> > > _______________________________________________
> > > Kitten mailing list
> > > Kitten@ietf.org
> > > https://www.ietf.org/mailman/listinfo/kitten
> > >
>
---559023410-1861363274-1472607833=:5272--


From nobody Wed Aug 31 01:59:23 2016
Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CEA0212DA53 for <kitten@ietfa.amsl.com>; Wed, 31 Aug 2016 01:59:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.849
X-Spam-Level: 
X-Spam-Status: No, score=-4.849 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.548, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id r5j2na9a0O3w for <kitten@ietfa.amsl.com>; Wed, 31 Aug 2016 01:59:19 -0700 (PDT)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2A74E12DA55 for <kitten@ietf.org>; Wed, 31 Aug 2016 01:59:18 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id 036B7BE29; Wed, 31 Aug 2016 09:59:16 +0100 (IST)
X-Virus-Scanned: Debian amavisd-new at scss.tcd.ie
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Lbn3FQ-uj82C; Wed, 31 Aug 2016 09:59:08 +0100 (IST)
Received: from [10.87.48.210] (95-45-153-252-dynamic.agg2.phb.bdt-fng.eircom.net [95.45.153.252]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id 968F8BDD0; Wed, 31 Aug 2016 09:59:07 +0100 (IST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; s=mail; t=1472633948; bh=Yt0aOfc7tMvt9ZjOHlbdjh3d0YFCBBOMH5ktQ6aVP7U=; h=Subject:To:References:From:Date:In-Reply-To:From; b=ogBeKFhoHkKJiaHXaohF1q+nFCYX0LCCbKc3IGixtociaWj7Y4UqCYDLfiryq5/jg cV7nEUbmTa6CfFqptmSxv9KaQ3ahZrhGbqH95V6BePPtOCdBf1JkwDD0/Woifx/+6j Tc2DDPg+fnOqt/exA1lPUL8g2s0QKsnJaqKSRLyw=
To: Benjamin Kaduk <kaduk@MIT.EDU>, kitten@ietf.org
References: <20160516161709.16705.29515.idtracker@ietfa.amsl.com> <1463416879.2542.15.camel@redhat.com> <1466709219.20951.3.camel@redhat.com> <alpine.GSO.1.10.1606252344350.18480@multics.mit.edu> <1467033683.2592.2.camel@redhat.com> <alpine.GSO.1.10.1608302133320.5272@multics.mit.edu>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Openpgp: id=D66EA7906F0B897FB2E97D582F3C8736805F8DA2; url=
Message-ID: <09863e06-f7ae-d2ec-c30e-7986d39a50b0@cs.tcd.ie>
Date: Wed, 31 Aug 2016 09:59:07 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.2.0
MIME-Version: 1.0
In-Reply-To: <alpine.GSO.1.10.1608302133320.5272@multics.mit.edu>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha-256; boundary="------------ms080807060207070100050107"
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/n_nhpJmGpzZyUtbp84h8rH1LLYE>
Subject: Re: [kitten] advancing some documents to the IESG
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 Aug 2016 08:59:22 -0000

This is a cryptographically signed message in MIME format.

--------------ms080807060207070100050107
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


Thanks Ben! I look forward to us doing this queue-clearing and
hope the WG find the workflow better.

S.

On 31/08/16 02:51, Benjamin Kaduk wrote:
> (was Re: [kitten] I-D Action: draft-ietf-kitten-krb-auth-indicator-02.t=
xt)
>=20
> Looping back to this thread, now that we have the extra reviews from
> Richard and Gerard, the chairs are comfortable advancing it to the IESG=
; I
> will shepherd.  In accordance with our new workflow, there will not be =
an
> additional WGLC, but feel free to comment (or object) at any time.
>=20
> We also have draft-ietf-kitten-rfc6112bis active, for which Shawn has
> published an updated version (with help from the secretariat).  It need=
s a
> few more tweaks to the wording and attack description, but the core
> protocol portions look good, so once the revisions are in place, that c=
an
> also move forward to the IESG.  As always, comments are always welcome.=

>=20
> draft-ietf-kitten-rfc5653bis went through WGLC at the same time as
> rfc6112bis, and also has an updated version as a result of the comments=

> from WGLC.  (As a reminder: the main goal is to allow GSSAPI error toke=
ns
> to be generated along with the GSSException that indicates the failure,=

> but the review also indicated issues with the stream-based GSSContext
> methods, leading to their removal from the current draft.)  Richard,
> Gerard, and everyone else are encouraged to review that document.
>=20
> draft-ietf-kitten-pkinit-freshness is waiting for a shepherd writeup an=
d
> then is expected to advance to the IESG.
>=20
> In other PKINIT-related work, the most recent threads the chairs have
> about draft-ietf-kitten-pkinit-alg-agility indicate that it should also=
 be
> ready to advance, but given how long ago they were, some additional
> research is in order to verify that.  More (re-)reviews wouldn't hurt,
> either!
>=20
> Please feel free to contact the chairs (or the list) with any questions=
,
> concerns, or most especially document reviews.
>=20
> -Ben
> for the kitten chairs
>=20
>=20
>=20
> On Mon, 27 Jun 2016, Nathaniel McCallum wrote:
>=20
>> I'm happy to do so. But, AFAIK, the only review thus far has been
>> yours. There were several other +1's to WG adoption, but no other
>> reviews.
>>
>> On Sat, 2016-06-25 at 23:46 -0400, Benjamin Kaduk wrote:
>>> Yes, it would be good to move this document forward, especially since=

>>> it
>>> already has implementation experience.  Would you be interested in
>>> trying
>>> out the proposal to manually track reviews and (mostly) skip WGLC for=

>>> this
>>> document?  That thread has not gotten many responses yet...
>>>
>>> -Ben
>>>
>>> On Thu, 23 Jun 2016, Nathaniel McCallum wrote:
>>>
>>>> I propsed this and hear no response. Can we move this draft
>>> forward?
>>>>
>>>> On Mon, 2016-05-16 at 12:41 -0400, Nathaniel McCallum wrote:
>>>>> With this revision, I believe that we are in the home stretch on
>>> this
>>>>> draft. Unless anyone has any objections, I'd like to request that
>>> the
>>>>> chairs begin WGLC.
>>>>>
>>>>> On Mon, 2016-05-16 at 09:17 -0700, internet-drafts@ietf.org wrote
>>> :
>>>>>> A New Internet-Draft is available from the on-line Internet-
>>> Drafts
>>>>>> directories.
>>>>>> This draft is a work item of the Common Authentication
>>> Technology
>>>>>> Next Generation of the IETF.
>>>>>>
>>>>>>         Title           : Authentication Indicator in Kerberos
>>>>>> Tickets
>>>>>>         Authors         : Anupam Jain
>>>>>>                           Nathan Kinder
>>>>>>                           Nathaniel McCallum
>>>>>>    Filename        : draft-ietf-kitten-krb-auth-indicator-02.txt
>>>>>>    Pages           : 5
>>>>>>    Date            : 2016-05-16
>>>>>>
>>>>>> Abstract:
>>>>>>    This document specifies an extension in the Kerberos
>>> protocol
>>>>>>    [RFC4120].  It defines a new authorization data type AD-
>>>>>>    AUTHENTICATION-INDICATOR.  The purpose of introducing this
>>> data
>>>>>> type
>>>>>>    is to include an indicator of the strength of a client's
>>>>>>    authentication in the service tickets so that application
>>>>>> services
>>>>>>    can use it as an input into policy decisions.
>>>>>>
>>>>>>
>>>>>> The IETF datatracker status page for this draft is:
>>>>>> https://datatracker.ietf.org/doc/draft-ietf-kitten-krb-auth-ind
>>> icat
>>>>>> or
>>>>>> /
>>>>>>
>>>>>> There's also a htmlized version available at:
>>>>>> https://tools.ietf.org/html/draft-ietf-kitten-krb-auth-indicato
>>> r-02
>>>>>>
>>>>>> A diff from the previous version is available at:
>>>>>> https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-kitten-krb-auth-in
>>> dica
>>>>>> to
>>>>>> r-02
>>>>>>
>>>>>>
>>>>>> Please note that it may take a couple of minutes from the time
>>> of
>>>>>> submission
>>>>>> until the htmlized version and diff are available at
>>>>>> tools.ietf.org.
>>>>>>
>>>>>> Internet-Drafts are also available by anonymous FTP at:
>>>>>> ftp://ftp.ietf.org/internet-drafts/
>>>>>>
>>>>>> _______________________________________________
>>>>>> Kitten mailing list
>>>>>> Kitten@ietf.org
>>>>>> https://www.ietf.org/mailman/listinfo/kitten
>>>>>
>>>>> _______________________________________________
>>>>> Kitten mailing list
>>>>> Kitten@ietf.org
>>>>> https://www.ietf.org/mailman/listinfo/kitten
>>>>
>>>> _______________________________________________
>>>> Kitten mailing list
>>>> Kitten@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/kitten
>>>>
>>
>=20
>=20
>=20
> _______________________________________________
> Kitten mailing list
> Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten
>=20


--------------ms080807060207070100050107
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCC
CvIwggUIMIID8KADAgECAhBPzaE7pzYviUJyhmHTFBdnMA0GCSqGSIb3DQEBCwUAMHUxCzAJ
BgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSkwJwYDVQQLEyBTdGFydENvbSBD
ZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTEjMCEGA1UEAxMaU3RhcnRDb20gQ2xhc3MgMSBDbGll
bnQgQ0EwHhcNMTYwMjA5MDkyODE1WhcNMTcwMjA5MDkyODE1WjBOMSIwIAYDVQQDDBlzdGVw
aGVuLmZhcnJlbGxAY3MudGNkLmllMSgwJgYJKoZIhvcNAQkBFhlzdGVwaGVuLmZhcnJlbGxA
Y3MudGNkLmllMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtuC0rYze/2JinSra
C9F2RjGdQZjNALLcW9C3WKTwYII3wBslobmHuPEYE5JaGItmzuKnAW619R1rD/kfoNWC19N3
rBZ6UX9Cmb9D9exCwYIwVuSwjrCQWGxgCtNQTrwKzCCpI790GRiMTvxvO7UmzmBrCaBLiZW5
R0fBjK5Yn6hUhAzGBkNbkIEL28cLJqH0yVz7Kl92OlzrQqTPEts5m6cDnNdY/ADfeAX18c1r
dxZqcAxhLotrCqgsVA4ilbQDMMXGTLlB5TP35HeWZuGBU7xu003rLcFLdOkD8xvpJoYZy9Kt
3oABXPS5yqtMK+XCNdqmMn+4mOtLwQSMmPCSiQIDAQABo4IBuTCCAbUwCwYDVR0PBAQDAgSw
MB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDBDAJBgNVHRMEAjAAMB0GA1UdDgQWBBQJ
QhvwQ5Fl372Z6xqo6fdn8XejTTAfBgNVHSMEGDAWgBQkgWw5Yb5JD4+3G0YrySi1J0htaDBv
BggrBgEFBQcBAQRjMGEwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLnN0YXJ0c3NsLmNvbTA5
BggrBgEFBQcwAoYtaHR0cDovL2FpYS5zdGFydHNzbC5jb20vY2VydHMvc2NhLmNsaWVudDEu
Y3J0MDgGA1UdHwQxMC8wLaAroCmGJ2h0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3NjYS1jbGll
bnQxLmNybDAkBgNVHREEHTAbgRlzdGVwaGVuLmZhcnJlbGxAY3MudGNkLmllMCMGA1UdEgQc
MBqGGGh0dHA6Ly93d3cuc3RhcnRzc2wuY29tLzBGBgNVHSAEPzA9MDsGCysGAQQBgbU3AQIE
MCwwKgYIKwYBBQUHAgEWHmh0dHA6Ly93d3cuc3RhcnRzc2wuY29tL3BvbGljeTANBgkqhkiG
9w0BAQsFAAOCAQEArzrSv2C8PlBBmGuiGrzm2Wma46/KHtXmZYS0bsd43pM66Pc/MsqPE0HD
C1GzMFfwB6BfkJn8ijNSIhlgj898WzjvnpM/SO8KStjlB8719ig/xKISrOl5mX55XbFlQtX9
U6MrqRgbDIATxhD9IDr+ryvovDzChqgQj7mt2jYr4mdlRjsjod3H1VY6XglRmaaNGZfsCARM
aE/TU5SXIiqauwt5KxNGYAY67QkOBs7O1FkSXpTk7+1MmzJMF4nP8QQ5n8vhVNseF+/Wm7ai
9mtnrkLbaznMsy/ULo/C2yuLUWTbZZbf4EKNmVdme6tUDgYkFjAFOblfA7W1fSPiQGagYzCC
BeIwggPKoAMCAQICEGunin0K14jWUQr5WeTntOEwDQYJKoZIhvcNAQELBQAwfTELMAkGA1UE
BhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFs
IENlcnRpZmljYXRlIFNpZ25pbmcxKTAnBgNVBAMTIFN0YXJ0Q29tIENlcnRpZmljYXRpb24g
QXV0aG9yaXR5MB4XDTE1MTIxNjAxMDAwNVoXDTMwMTIxNjAxMDAwNVowdTELMAkGA1UEBhMC
SUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKTAnBgNVBAsTIFN0YXJ0Q29tIENlcnRpZmlj
YXRpb24gQXV0aG9yaXR5MSMwIQYDVQQDExpTdGFydENvbSBDbGFzcyAxIENsaWVudCBDQTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL192vfDon2D9luC/dtbX64eG3XAtRmv
mCSsu1d52DXsCR58zJQbCtB2/A5uFqNxWacpXGGtTCRk9dEDBlmixEd8QiLkUfvHpJX/xKnm
VkS6Iye8wUbYzMsDzgnpazlPg19dnSqfhM+Cevdfa89VLnUztRr2cgmCfyO9Otrh7LJDPG+4
D8ZnAqDtVB8MKYJL6QgKyVhhaBc4y3bGWxKyXEtx7QIZZGxPwSkzK3WIN+VKNdkiwTubW5PI
dopmykwvIjLPqbJK7yPwFZYekKE015OsW6FV+s4DIM8UlVS8pkIsoGGJtMuWjLL4tq2hYQuu
N0jhrxK1ljz50hH23gA9cbMCAwEAAaOCAWQwggFgMA4GA1UdDwEB/wQEAwIBBjAdBgNVHSUE
FjAUBggrBgEFBQcDAgYIKwYBBQUHAwQwEgYDVR0TAQH/BAgwBgEB/wIBADAyBgNVHR8EKzAp
MCegJaAjhiFodHRwOi8vY3JsLnN0YXJ0c3NsLmNvbS9zZnNjYS5jcmwwZgYIKwYBBQUHAQEE
WjBYMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5zdGFydHNzbC5jb20wMAYIKwYBBQUHMAKG
JGh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL2NhLmNydDAdBgNVHQ4EFgQUJIFsOWG+
SQ+PtxtGK8kotSdIbWgwHwYDVR0jBBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwPwYDVR0g
BDgwNjA0BgRVHSAAMCwwKgYIKwYBBQUHAgEWHmh0dHA6Ly93d3cuc3RhcnRzc2wuY29tL3Bv
bGljeTANBgkqhkiG9w0BAQsFAAOCAgEAi+P3h+wBi4StDwECW5zhIycjBL008HACblIf26HY
0JdOruKbrWDsXUsiI0j/7Crft9S5oxvPiDtVqspBOB/y5uzSns1lZwh7sG96bYBZpcGzGxpF
NjDmQbcM3yl3WFIRS4WhNrsOY14V7y2IrUGsvetsD+bjyOngCIVeC/GmsmtbuLOzJ606tEc9
uRbhjTu/b0x2Fo+/e7UkQvKzNeo7OMhijixaULyINBfCBJb+e29bLafgu6JqjOUJ9eXXj20p
6q/CW+uVrZiSW57+q5an2P2i7hP85jQJcy5j4HzA0rSiF3YPhKGAWUxKPMAVGgcYoXzWydOv
Z3UDsTDTagXpRDIKQLZo02wrlxY6iMFqvlzsemVf1odhQJmi7Eh5TbxI40kDGcBOBHhwnaOu
mZhLP+SWJQnjpLpSlUOj95uf1zo9oz9e0NgIJoz/tdfrBzez76xtDsK0KfUDHt1/q59BvDI7
RX6gVr0fQoCyMczNzCTcRXYHY0tq2J0oT+bsb6sH2b4WVWAiJKnSYaWDjdA70qHX4mq9MIjO
/ZskmSY8wtAk24orAc0vwXgYanqNsBX5Yv4sN4Z9VyrwMdLcusP7HJgRdAGKpkR2I9U4zEsN
JQJewM7S4Jalo1DyPrLpL2nTET8ZrSl5Utp1UeGp/2deoprGevfnxWB+vHNQiu85o6MxggPM
MIIDyAIBATCBiTB1MQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjEpMCcG
A1UECxMgU3RhcnRDb20gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxIzAhBgNVBAMTGlN0YXJ0
Q29tIENsYXNzIDEgQ2xpZW50IENBAhBPzaE7pzYviUJyhmHTFBdnMA0GCWCGSAFlAwQCAQUA
oIICEzAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNjA4MzEw
ODU5MDdaMC8GCSqGSIb3DQEJBDEiBCAKwAFGCb2350k9gpgnl95gSysfv+qAIhJkeq25bdqH
MzBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjALBglghkgBZQMEAQIwCgYIKoZIhvcN
AwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAcGBSsOAwIHMA0GCCqGSIb3DQMC
AgEoMIGaBgkrBgEEAYI3EAQxgYwwgYkwdTELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0
Q29tIEx0ZC4xKTAnBgNVBAsTIFN0YXJ0Q29tIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MSMw
IQYDVQQDExpTdGFydENvbSBDbGFzcyAxIENsaWVudCBDQQIQT82hO6c2L4lCcoZh0xQXZzCB
nAYLKoZIhvcNAQkQAgsxgYyggYkwdTELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29t
IEx0ZC4xKTAnBgNVBAsTIFN0YXJ0Q29tIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MSMwIQYD
VQQDExpTdGFydENvbSBDbGFzcyAxIENsaWVudCBDQQIQT82hO6c2L4lCcoZh0xQXZzANBgkq
hkiG9w0BAQEFAASCAQBfrasDchX3KAMNgFLVdCk2zatVt16zuHhmxeDMuGWjdBRubVv7lM1H
SZUdXyZuQHlJ7vkJLTDXPUaZY14TqCQzipVhopxOEsaYobg2yIQR75GvyGAp0lCadH2pAT/l
SjqXUWX67CZ70CqfPQ/xrv8y/LHvYmi1GejlcDgvBicGmwqXbYKnRVlVNNSz16+FgCrQf7Xk
viw3XYCIB/p8/uLl+WG3+k2B3sAAhsMLpRqFxdBcvSZyLG3X2mojS3/3NW0ITSnlsgmTvtRt
Rf2W1O2IwFxQXtpn30YJhCkGXu0q57lEhyj4UDjqZv2/JL4fLhzorfZlwU0UUI51v6Ju69zw
AAAAAAAA
--------------ms080807060207070100050107--

