
From nobody Mon Apr  3 09:33:05 2017
Return-Path: <ghudson@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 91C39129481 for <kitten@ietfa.amsl.com>; Mon,  3 Apr 2017 09:33:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Sk6Z0i0YumK3 for <kitten@ietfa.amsl.com>; Mon,  3 Apr 2017 09:33:01 -0700 (PDT)
Received: from dmz-mailsec-scanner-5.mit.edu (dmz-mailsec-scanner-5.mit.edu [18.7.68.34]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2CF6212947F for <kitten@ietf.org>; Mon,  3 Apr 2017 09:33:00 -0700 (PDT)
X-AuditID: 12074422-eefff70000003b20-ff-58e2793a96bc
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id 63.24.15136.A3972E85; Mon,  3 Apr 2017 12:32:59 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id v33GWvQl028036; Mon, 3 Apr 2017 12:32:58 -0400
Received: from [18.101.8.131] (vpn-18-101-8-131.mit.edu [18.101.8.131]) (authenticated bits=0) (User authenticated as ghudson@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v33GWtFL029539 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Mon, 3 Apr 2017 12:32:56 -0400
To: Matt Rogers <mrogers@redhat.com>
References: <x7dzige39sj.fsf@equal-rites.mit.edu> <CAAeFVfwexk8THERJZ5Qm+sTB+FVMWsRSOXninGFmMWehzwiz-A@mail.gmail.com>
Cc: kitten@ietf.org
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <2ccb915d-4a10-1ced-d8c8-298e1aec6373@mit.edu>
Date: Mon, 3 Apr 2017 12:32:55 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.5.1
MIME-Version: 1.0
In-Reply-To: <CAAeFVfwexk8THERJZ5Qm+sTB+FVMWsRSOXninGFmMWehzwiz-A@mail.gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrKIsWRmVeSWpSXmKPExsUixCmqrGtd+SjCYO4Ofoujm1exWNyfGOfA 5LFkyU8mj/f7rrIFMEVx2aSk5mSWpRbp2yVwZWyb+ZC94JZaRWPTYZYGxs9yXYycHBICJhKT fsxl7mLk4hASaGOSuDx7IiOEs4FRYum7qUwQzhEmiXePNzKCtAgLeEk8nrKUpYuRg0NEQEVi 7g5RkLCQQIXE8uZlzCA2s4CwxPI1Z9lAbDYBZYn1+7eClfMKWEm8u1IOEmYB6jz5ZjE7SFhU IEKi4XA6SJhXQFDi5MwnLCA2p0CgxIJZD1ghJqpL/Jl3CWq6vMT2t3OYJzAKzELSMgtJ2Swk ZQsYmVcxyqbkVunmJmbmFKcm6xYnJ+blpRbpmurlZpbopaaUbmIEhSi7i9IOxon/vA4xCnAw KvHwejg8ihBiTSwrrsw9xCjJwaQkyvtBASjEl5SfUpmRWJwRX1Sak1p8iFGCg1lJhJcjHijH m5JYWZValA+TkuZgURLnFddojBASSE8sSc1OTS1ILYLJynBwKEnwVpYDNQoWpaanVqRl5pQg pJk4OEGG8wANfw5Sw1tckJhbnJkOkT/FqMsxZ/buN0xCLHn5ealS4rwNIEUCIEUZpXlwc8Cp JZWj+RWjONBbwrzVIFU8wLQEN+kV0BImoCVP7jwEWVKSiJCSamBcwsTP7a+55uDr/y9OOXz5 fXxfxdvW7013eoRcY5l9r/0MV9g3w/xhlZO22tW56zk6fnLc1tz2Il0k+yijNF+Ks3rXwRtK D6Z8juW458P93eaG48ZGhq4L8274elR3PvFQnCmlE8bUUVr6Ys3+gt+Hlq7Z6PNl7y+LqZ+f Slen+7kxzE9UXpynxFKckWioxVxUnAgA32XzpwgDAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/BxeuoVfXzD0UjgDTidkrood7ZFg>
Subject: Re: [kitten] Review of draft-ietf-kitten-krb-service-discovery-00
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 03 Apr 2017 16:33:03 -0000

On 03/30/2017 02:51 PM, Matt Rogers wrote:
>> * RFC 7553 is informational and this document is standards track, which
>>   is a down reference (see RFC 3967).  Also, RFC 7553 contains ambiguous
>>   guidance about URI records labels which some readers have interpreted
>>   as being incompatible with our use of labels.  I think at one point we
>>   received advice to reference the IANA registration of the URI record
>>   type instead of RFC; unfortunately I do not know the mechanics of that
>>   kind of reference.

> The IANA registration entry refers to RFC 7553:
> https://www.iana.org/assignments/dns-parameters/dns-parameters.xhtml
> Perhaps it should just be an informative reference instead.

There is also a "completed template" in the IANA assignment:

https://www.iana.org/assignments/dns-parameters/URI/uri-completed-template

I hadn't read this before.  It says (in section E):

  The URI RR has service information encoded in its ownername.  In
  order to encode the service for a specific owner name one uses
  service parameters.  Valid service parameters used are either
  Enumservice Registrations registered by IANA, or prefixes used
  for the SRV resource record.

which seems like a slightly more restrictive statement than the one in
RFC 7553.  We may need some guidance from the chairs or ADs on the
mechanics of moving forward here.  Simply making the reference
informative doesn't seem sufficient, as the URI RR type is fundamental
to this standard.

(To be clear, I think what we're doing ought to be fine, and that it's
generally pointless to include a transport label in a URI record owner
name like one would in a SRV owner name.  The question is one of
conformance with the pre-existing standard, not practicality.)

>> * Similarly, MS-KKDCP is in the normative references section, and is not
>>   a standards-track IETF document.  It is only used as the reference in
>>   the initial contents of the transport registry, so perhaps it can just
>>   be an informative reference.
>>
> I'll make this an informative reference.

The MS-KKDCP reference is obvious controlling when using the kkdcp
transport.  Since this is just an initial transport registration, it may
be okay to use an informative reference.

>> * "REALM indicates the translation of the Kerberos realm to a DNS
>>    domain" seems to invoke some kind of translation procedure without a
>>    reference.  RFC 4120 doesn't really define any such translation
>>    procedure; it just says in section 6.1 that a realm might be in
>>    domain style with some specifics on what that means, and in section
>>    7.2.3.2 that "The realm MUST be a domain-style realm name".
>>
>>    (Section 6 has this same wording again.)
> 
> How about "..client MUST query the following URI DNS record, where
> REALM is a domain-style realm name."

I'm okay with that.

>> * The wording here seems too general.  I think we want to specifically
>>   say that URI records should be preferred over SRV records.

> How about: "Clients that support service discovery through both URI
> and SRV records SHOULD perform the URI discovery first. If no URI
> record is found, the client MAY then attempt SRV discovery."

Sure.

There is an argument for a MUST here.  DNS administrators will commonly
want to set up both URI and SRV records for a realm, and the behavior of
trying URI first may be important (e.g. if the URI record includes a
kkdcp entry).

>> * The reference here is "TBD".  Is there a plan?  Is the reference
>>   supposed to be to this RFC once a number is assigned?
>>
> 
> It should be changed to the assigned number, yes. It was suggested
> that instead of TBD we use [This Document], which I think is the
> convention for this kind of reference.

That seems okay.  There might also need to be an RFC editor guidance
section pointing out the need for a substitution there.  For instance,
in https://tools.ietf.org/html/draft-ietf-krb-wg-crypto-07 see the
"Notes to RFC Editor" section at the end.

> "The security implication of using DNS URI records is identical to
> that of using DNS for any Kerberos service or host mapping; without
> secure DNS the results can be forged.  The same precautions regarding
> the use of insecure DNS with Kerberos outlined in RFC 4120 should be
> followed."

RFC 4120 primarily talks about DNS in the context of prohibiting the use
of insecure DNS to map between service names, which is irrelevant to
this standard.

Since RFC 4120 assumes a hostile network environment (and so does RFC
3244), it is usually uninteresting whether an attacker subverts
communication via a DNS attack or a network attack.  However, we should
note in security considerations that the added security benefits of
MS-KKDCP (such as confidentiality of client and server principal names)
are eroded when using insecure DNS to discover the server URL.


From nobody Tue Apr  4 21:56:01 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D95AF126C0F for <kitten@ietfa.amsl.com>; Tue,  4 Apr 2017 21:55:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.222
X-Spam-Level: 
X-Spam-Status: No, score=-4.222 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UVaKM6hi2ro0 for <kitten@ietfa.amsl.com>; Tue,  4 Apr 2017 21:55:58 -0700 (PDT)
Received: from dmz-mailsec-scanner-7.mit.edu (dmz-mailsec-scanner-7.mit.edu [18.7.68.36]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EE0711204DA for <kitten@ietf.org>; Tue,  4 Apr 2017 21:55:57 -0700 (PDT)
X-AuditID: 12074424-987ff70000007ab7-6f-58e478dad8fd
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id A8.E3.31415.AD874E85; Wed,  5 Apr 2017 00:55:55 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id v354trTG006528 for <kitten@ietf.org>; Wed, 5 Apr 2017 00:55:54 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v354togL021804 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Wed, 5 Apr 2017 00:55:53 -0400
Date: Tue, 4 Apr 2017 23:55:50 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: kitten@ietf.org
Message-ID: <20170405045550.GJ30306@kduck.kaduk.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.6.1 (2016-04-27)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrNIsWRmVeSWpSXmKPExsUixG6nonu74kmEwfZnLBZHN69icWD0WLLk J1MAYxSXTUpqTmZZapG+XQJXxvf270wFGwUrJi3VbmC8xtfFyMkhIWAicfTSJ9YuRi4OIYE2 Jol/zzewQTjHGCWmzv3GDOG8YpLYuQ0kw8nBIqAisb/hFZjNBmQ3dF9mBrFFBIQldm99B2YL C8hIHGzfx9TFyMHBC7TiSLsHSJhXQFDi5MwnLCA2s4CWxI1/L8FKmAWkJZb/4wAJiwooSzTM eMA8gZF3FpKOWUg6ZiF0LGBkXsUom5JbpZubmJlTnJqsW5ycmJeXWqRrrpebWaKXmlK6iREc Ri4qOxi7e7wPMQpwMCrx8FZMexwhxJpYVlyZe4hRkoNJSZRXwedJhBBfUn5KZUZicUZ8UWlO avEhRgkOZiUR3s05QDnelMTKqtSifJiUNAeLkjivuEZjhJBAemJJanZqakFqEUxWhoNDSYKX DxgvQoJFqempFWmZOSUIaSYOTpDhPEDDN5aDDC8uSMwtzkyHyJ9iVJQS570JkhAASWSU5sH1 guJcInt/zStGcaBXhHkfgVTxAFMEXPcroMFMQIOf3HkIMrgkESEl1cBYpPdJiyGWwcyl8cuD SNkD2u89eRo931w98Ll8S2WAC1uqs7bydcHHu2eFSCXIlK7YwrTVsulgyJNg++LToSyz9efn zHD4aV28N/LL45fLxEvNpOUutJSe0X+hfeTtVrYou5fCxW7HbwqbOZ88f2hiId8VZiX3l+ek Jgjkh5Rs+fdnUYnmLwUlluKMREMt5qLiRAAzeCfIzgIAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/euaNHUHgctnFbzKYET-Vfg2IWT8>
Subject: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 04:56:00 -0000

Hi all,

Now that we've cleared a fair bit of backlog, publishing a few old
documents and getting ready to kick more up to the IESG, it seems
apropos to consider what "new" work to adopt (many of which have
been lingering as individual documents for a while and are not
exactly new).

To give some historical perspective on the sense of the working
group, back in Buenos Aires the chairs had a (very broad!) list of:
draft-williams-kitten-krb5-pkcross
draft-williams-kitten-krb5-extra-rt
draft-williams-kitten-generic-naming-attributes
draft-williams-kitten-impersonation-naming-attr
draft-vanrein-kitten-rfbsasl
draft-vanrein-dnstxt-krb1
draft-vanrein-krb5-kdh
draft-vanrein-kitten-krb5-pseudonymity
draft-mccallum-kitten-krb-spake-preauth
draft-kaduk-kitten-des-des-des-die-die-die
draft-howard-gssapi-aead
draft-mccallum-kitten-krb-service-discovery

and the sense of the room was that
draft-mccallum-kitten-krb-spake-preauth and
draft-williams-kitten-krb5-pkcross were the most promising.

(draft-mccallum-kitten-krb-service-discovery has since been adopted)

Recall that our current work items are listed at:
https://datatracker.ietf.org/wg/kitten/documents/ , some of which
are believed to be ready to send to the IESG or nearly so.

What do people currently feel are the top one or two highest
priority items for the WG to consider?  (Such items need not be
limited to the above list, of course; note that, e.g.,
draft-schmaus-kitten-sasl-ht-00 has recently appeared on the list of
related internet-drafts.)

I'll also note that we should be able to ask the curdle WG to take
on draft-kaduk-kitten-des-des-des-die-die-die, which is simple
deprecation of RC4 and 3DES (and some registry cleanup from RFC
6649).  I'll plan to do that unless people want to do it in kitten
instead.  One might also ask about moving
draft-ietf-kitten-pkinit-alg-agility to curdle (since it moves
PKINIT off SHA1), but that's a little more complicated since it
first has to add the agility to do so, and judging by the reviews
accumulated and noted at
https://github.com/kittenwg/draft-ietf-kitten-pkinit-alg-agility ,
it should be basically done already.

Thanks,

Ben
for the Chairs


From nobody Wed Apr  5 02:21:54 2017
Return-Path: <rick@openfortress.nl>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A95D4129420 for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 02:21:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.621
X-Spam-Level: 
X-Spam-Status: No, score=-2.621 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CzKtFGOLv5R8 for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 02:21:50 -0700 (PDT)
Received: from lb1-smtp-cloud6.xs4all.net (lb1-smtp-cloud6.xs4all.net [194.109.24.24]) (using TLSv1 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D8279129412 for <kitten@ietf.org>; Wed,  5 Apr 2017 02:21:47 -0700 (PDT)
Received: from airhead.local ([IPv6:2001:980:93a5:1:6197:4fec:596a:2de0]) by smtp-cloud6.xs4all.net with ESMTP id 4ZMk1v00H1d9kyW01ZMleQ; Wed, 05 Apr 2017 11:21:46 +0200
Message-ID: <58E4B727.1050103@openfortress.nl>
Date: Wed, 05 Apr 2017 11:21:43 +0200
From: Rick van Rein <rick@openfortress.nl>
User-Agent: Postbox 3.0.11 (Macintosh/20140602)
MIME-Version: 1.0
To: Benjamin Kaduk <kaduk@mit.edu>
CC: kitten@ietf.org
References: <20170405045550.GJ30306@kduck.kaduk.org>
In-Reply-To: <20170405045550.GJ30306@kduck.kaduk.org>
X-Enigmail-Version: 1.2.3
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/gjZW5BDCqaKzuXGHGg1ShISoDSc>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 09:21:53 -0000

Hi,

Good news, Ben :)

Let me at least sort the list of drafts I wrote.

> What do people currently feel are the top one or two highest
> priority items for the WG to consider?

IMHO, draft-vanrein-dnstxt-krb1would be a quick win.  It's with the RFC
Editor and I'm working on and off to get it adopted into MIT krb5.  Nico
has reviewed it and the RFC Editor is mainly waiting for a 2nd reviewer.

Also up shortly in our work is Kerberos Realm Crossover, bet there's no
I-D yet.

In the TLS WG, I'm working on TLS-KDH, which may need some discussion in
Kitten on the allocation of numbers (such as unencrypted algorithm
numbers, because TLS takes care of the encryption).

Cheers,
 -Rick


From nobody Wed Apr  5 05:41:00 2017
Return-Path: <prvs=1268e6793a=jaltman@secure-endpoints.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1B31D1286AB for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 05:40:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=secure-endpoints.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9sM4kuImV3Ns for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 05:40:57 -0700 (PDT)
Received: from sequoia-grove.secure-endpoints.com (sequoia-grove.ad.secure-endpoints.com [208.125.0.235]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8C573127863 for <kitten@ietf.org>; Wed,  5 Apr 2017 05:40:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/relaxed; d=secure-endpoints.com; s=MDaemon; t=1491396032; x=1492000832; i=jaltman@secure-endpoints.com; q=dns/txt; h=VBR-Info:Subject:To: References:From:Openpgp:Organization:Message-ID:Date:User-Agent: MIME-Version:In-Reply-To:Content-Type; bh=g31b3jRDlrLEjajbo/MAUo EPP8VIkDzuTr9x6nrAwcM=; b=Y1UuIkxCDHxIfESPdW7xoYw+BzCTZdwYZ9Wlq/ 1Bx6RSQPDaJG9IVi+aYF9pMSFOOg8w/r/1RblWrIla6mqBbhlx5+h0/6LLQRlgjH 93RgME8Cr8olwtg3C6L/HpVIZ674KIy4SsOSxLw1g0+pivvYvMnhsHlBl65bbv/l SYOHU=
X-MDAV-Result: clean
X-MDAV-Processed: sequoia-grove.secure-endpoints.com, Wed, 05 Apr 2017 08:40:32 -0400
X-Spam-Processed: sequoia-grove.secure-endpoints.com, Wed, 05 Apr 2017 08:40:30 -0400
Received: from [IPv6:2001:470:1f07:f77:d804:1659:6eb:7670] by secure-endpoints.com (IPv6:2001:470:1f07:f77:28d9:68fb:855d:c2a5) (MDaemon PRO v17.0.0)  with ESMTPSA id md50001309075.msg; Wed, 05 Apr 2017 08:40:29 -0400
VBR-Info: md=secure-endpoints.com; mc=all; mv=vbr.emailcertification.org;
X-MDRemoteIP: 2001:470:1f07:f77:d804:1659:6eb:7670
X-MDHelo: [IPv6:2001:470:1f07:f77:d804:1659:6eb:7670]
X-MDArrival-Date: Wed, 05 Apr 2017 08:40:29 -0400
X-Authenticated-Sender: jaltman@secure-endpoints.com
X-Return-Path: prvs=1268e6793a=jaltman@secure-endpoints.com
X-Envelope-From: jaltman@secure-endpoints.com
X-MDaemon-Deliver-To: kitten@ietf.org
X-CAV-Result: clean
To: kitten@ietf.org
References: <20170405045550.GJ30306@kduck.kaduk.org>
From: Jeffrey Altman <jaltman@secure-endpoints.com>
Openpgp: id=FA444AF197F449B24CF3E699F77A735592B69A04; url=https://pgp.mit.edu
Organization: Secure Endpoints Inc.
Message-ID: <fa13dc36-a2b7-190e-a64d-109161123fac@secure-endpoints.com>
Date: Wed, 5 Apr 2017 08:40:27 -0400
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.8.0
MIME-Version: 1.0
In-Reply-To: <20170405045550.GJ30306@kduck.kaduk.org>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha-256; boundary="------------ms040501060207090503080604"
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/u07Q9AHLkM9md6vdPAPcG6kM3fo>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 12:40:59 -0000

This is a cryptographically signed message in MIME format.

--------------ms040501060207090503080604
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

On 4/5/2017 12:55 AM, Benjamin Kaduk wrote:
>
> To give some historical perspective on the sense of the working
> group, back in Buenos Aires the chairs had a (very broad!) list of:
> draft-williams-kitten-krb5-pkcross
> draft-williams-kitten-krb5-extra-rt
> draft-williams-kitten-generic-naming-attributes
> draft-williams-kitten-impersonation-naming-attr
> draft-vanrein-kitten-rfbsasl
> draft-vanrein-dnstxt-krb1
> draft-vanrein-krb5-kdh
> draft-vanrein-kitten-krb5-pseudonymity
> draft-mccallum-kitten-krb-spake-preauth
> draft-kaduk-kitten-des-des-des-die-die-die
> draft-howard-gssapi-aead
> draft-mccallum-kitten-krb-service-discovery

Not on this list (possibly because the draft was expired at the time of
the Buenos Aires meeting) is

  https://datatracker.ietf.org/doc/draft-cantor-ietf-kitten-saml-ec/

which has an open source implementation for Shibboleth at

  https://github.com/fedushare/mech_saml_ec

> and the sense of the room was that
> draft-mccallum-kitten-krb-spake-preauth and
> draft-williams-kitten-krb5-pkcross were the most promising.
>=20
> (draft-mccallum-kitten-krb-service-discovery has since been adopted)
>=20
> Recall that our current work items are listed at:
> https://datatracker.ietf.org/wg/kitten/documents/ , some of which
> are believed to be ready to send to the IESG or nearly so.
>=20
> What do people currently feel are the top one or two highest
> priority items for the WG to consider?  (Such items need not be
> limited to the above list, of course; note that, e.g.,
> draft-schmaus-kitten-sasl-ht-00 has recently appeared on the list of
> related internet-drafts.)
>=20
> I'll also note that we should be able to ask the curdle WG to take
> on draft-kaduk-kitten-des-des-des-die-die-die, which is simple
> deprecation of RC4 and 3DES (and some registry cleanup from RFC
> 6649).  I'll plan to do that unless people want to do it in kitten
> instead.  One might also ask about moving
> draft-ietf-kitten-pkinit-alg-agility to curdle (since it moves
> PKINIT off SHA1), but that's a little more complicated since it
> first has to add the agility to do so, and judging by the reviews
> accumulated and noted at
> https://github.com/kittenwg/draft-ietf-kitten-pkinit-alg-agility ,
> it should be basically done already.

I believe that draft-kaduk-kitten-des-des-des-die-die-die fine as-is and
should simply be published by Kitten.

I would like to see the following documents be adopted

  draft-williams-kitten-krb5-pkcross
  draft-howard-gssapi-aead
  draft-cantor-ietf-kitten-saml-ec

Jeffrey Altman






--------------ms040501060207090503080604
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCC
DJswggYCMIIE6qADAgECAhBAAVgjEN7WFoCIXylZ1uvSMA0GCSqGSIb3DQEBCwUAMDoxCzAJ
BgNVBAYTAlVTMRIwEAYDVQQKEwlJZGVuVHJ1c3QxFzAVBgNVBAMTDlRydXN0SUQgQ0EgQTEy
MB4XDTE2MTEwMjAzMjQxOFoXDTE3MTEwMjAzMjQxOFowgZYxNTAzBgNVBAsMLFZlcmlmaWVk
IEVtYWlsOiBqYWx0bWFuQHNlY3VyZS1lbmRwb2ludHMuY29tMSswKQYJKoZIhvcNAQkBFhxq
YWx0bWFuQHNlY3VyZS1lbmRwb2ludHMuY29tMTAwLgYKCZImiZPyLGQBARMgN0YwMDAwMDEw
MDAwMDE1ODIzMTBERUE3MDAwMDA3QjQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDPaPDUdwWkzLcNsJjjlDs5lo4ySDKmCgzQsuDt+VY3wP0IZBbu8f/LM3zWCH7zVRJ/XuY5
qN44jFEXwj5fGY71Esm5pKv5sUpys6Q3c6BKXiHv/IUusI3qTJ46QBEAiHu2lxB75UnIYgm+
ZbKmcAR48Z1Sl/Ku86e9GPuts9R51SeHW1pjq89LAi6C0ERuAUIK0rVZGDmKWtRNs9EykXzk
mU2Z1ZLuPL0jIggFPeT8TyH6TH/XvapbC+7rHJrzuBY4NDqLgqDJUf0JidL9JeK9+IxxPCab
EbVmOf5sBgO5mg92l4+f+Q4xefZcI4C7RPFdRTRWsQs7Z3DpE28BDbjDAgMBAAGjggKlMIIC
oTAOBgNVHQ8BAf8EBAMCBaAwgYQGCCsGAQUFBwEBBHgwdjAwBggrBgEFBQcwAYYkaHR0cDov
L2NvbW1lcmNpYWwub2NzcC5pZGVudHJ1c3QuY29tMEIGCCsGAQUFBzAChjZodHRwOi8vdmFs
aWRhdGlvbi5pZGVudHJ1c3QuY29tL2NlcnRzL3RydXN0aWRjYWExMi5wN2MwHwYDVR0jBBgw
FoAUpHPa72k1inXMoBl7CDL4a4nkQuwwCQYDVR0TBAIwADCCASwGA1UdIASCASMwggEfMIIB
GwYLYIZIAYb5LwAGCwEwggEKMEoGCCsGAQUFBwIBFj5odHRwczovL3NlY3VyZS5pZGVudHJ1
c3QuY29tL2NlcnRpZmljYXRlcy9wb2xpY3kvdHMvaW5kZXguaHRtbDCBuwYIKwYBBQUHAgIw
ga4agatUaGlzIFRydXN0SUQgQ2VydGlmaWNhdGUgaGFzIGJlZW4gaXNzdWVkIGluIGFjY29y
ZGFuY2Ugd2l0aCAKSWRlblRydXN0J3MgVHJ1c3RJRCBDZXJ0aWZpY2F0ZSBQb2xpY3kgZm91
bmQgYXQgaHR0cHM6Ly9zZWN1cmUuaWRlbnRydXN0LmNvbS9jZXJ0aWZpY2F0ZXMvcG9saWN5
L3RzL2luZGV4Lmh0bWwwRQYDVR0fBD4wPDA6oDigNoY0aHR0cDovL3ZhbGlkYXRpb24uaWRl
bnRydXN0LmNvbS9jcmwvdHJ1c3RpZGNhYTEyLmNybDAnBgNVHREEIDAegRxqYWx0bWFuQHNl
Y3VyZS1lbmRwb2ludHMuY29tMB0GA1UdDgQWBBSP11Voh/Sg9hmecftn2BV5ZQd9OTAdBgNV
HSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwQwDQYJKoZIhvcNAQELBQADggEBAC9cnqRj+ViE
efFsiYNMUC8tZf6PXcWDecOR5Pdv/Vd/O6y10mYyilPrcd0sJux1idTZIOzHAsh36BfBdNSt
BFAuBZD66L649U3XqBnh9nbuzmCwNc3tWjOaY/Xe7R90lqrXaW0Dw0U++zwmNyCO2CRgBdrU
8cTqFpOtpe/gCAMhjajrUfb+m8Vcd5R0RVIvdljblqv2t9IXQIHwWSm8E7v302z7yW4o4iPH
kegez5vq37ICikQjkkVyAJr0wtirJyQuFzMgpoWVpm0CKBiMwJPki2kiHlNiMHBr2ch4fC+H
SjbMg4OzTZJCz1xhKvpyRDOM8JRb2BNSU8JjmrxZgFIwggaRMIIEeaADAgECAhEA+d5Wf8lN
DHdw+WAbUtoVOzANBgkqhkiG9w0BAQsFADBKMQswCQYDVQQGEwJVUzESMBAGA1UEChMJSWRl
blRydXN0MScwJQYDVQQDEx5JZGVuVHJ1c3QgQ29tbWVyY2lhbCBSb290IENBIDEwHhcNMTUw
MjE4MjIyNTE5WhcNMjMwMjE4MjIyNTE5WjA6MQswCQYDVQQGEwJVUzESMBAGA1UEChMJSWRl
blRydXN0MRcwFQYDVQQDEw5UcnVzdElEIENBIEExMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBANGRTTzPCic0kq5L6ZrUJWt5LE/n6tbPXPhGt2Egv7plJMoEpvVJJDqGqDYy
maAsd8Hn9ZMAuKUEFdlx5PgCkfu7jL5zgiMNnAFVD9PyrsuF+poqmlxhlQ06sFY2hbhQkVVQ
00KCNgUzKcBUIvjv04w+fhNPkwGW5M7Ae5K5OGFGwOoRck9GG6MUVKvTNkBw2/vNMOd29VGV
TtR0tjH5PS5yDXss48Yl1P4hDStO2L4wTsW2P37QGD27//XGN8K6amWB6F2XOgff/PmlQjQO
ORT95PmLkwwvma5nj0AS0CVp8kv0K2RHV7GonllKpFDMT0CkxMQKwoj+tWEWJTiDKSsCAwEA
AaOCAoAwggJ8MIGJBggrBgEFBQcBAQR9MHswMAYIKwYBBQUHMAGGJGh0dHA6Ly9jb21tZXJj
aWFsLm9jc3AuaWRlbnRydXN0LmNvbTBHBggrBgEFBQcwAoY7aHR0cDovL3ZhbGlkYXRpb24u
aWRlbnRydXN0LmNvbS9yb290cy9jb21tZXJjaWFscm9vdGNhMS5wN2MwHwYDVR0jBBgwFoAU
7UQZwNPwBovupHu+QucmVMiONnYwDwYDVR0TAQH/BAUwAwEB/zCCASAGA1UdIASCARcwggET
MIIBDwYEVR0gADCCAQUwggEBBggrBgEFBQcCAjCB9DBFFj5odHRwczovL3NlY3VyZS5pZGVu
dHJ1c3QuY29tL2NlcnRpZmljYXRlcy9wb2xpY3kvdHMvaW5kZXguaHRtbDADAgEBGoGqVGhp
cyBUcnVzdElEIENlcnRpZmljYXRlIGhhcyBiZWVuIGlzc3VlZCBpbiBhY2NvcmRhbmNlIHdp
dGggSWRlblRydXN0J3MgVHJ1c3RJRCBDZXJ0aWZpY2F0ZSBQb2xpY3kgZm91bmQgYXQgaHR0
cHM6Ly9zZWN1cmUuaWRlbnRydXN0LmNvbS9jZXJ0aWZpY2F0ZXMvcG9saWN5L3RzL2luZGV4
Lmh0bWwwSgYDVR0fBEMwQTA/oD2gO4Y5aHR0cDovL3ZhbGlkYXRpb24uaWRlbnRydXN0LmNv
bS9jcmwvY29tbWVyY2lhbHJvb3RjYTEuY3JsMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEF
BQcDBDAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0OBBYEFKRz2u9pNYp1zKAZewgy+GuJ5ELsMA0G
CSqGSIb3DQEBCwUAA4ICAQAN4YKu0vv062MZfg+xMSNUXYKvHwvZIk+6H1pUmivyDI4I6A3w
Wzxlr83ZJm0oGIF6PBsbgKJ/fhyyIzb+vAYFJmyI8I/0mGlc+nIQNuV2XY8cypPoVJKgpnzp
/7cECXkX8R4NyPtEn8KecbNdGBdEaG4a7AkZ3ujlJofZqYdHxN29tZPdDlZ8fR36/mAFeCEq
0wOtOOc0Eyhs29+9MIZYjyxaPoTS+l8xLcuYX3RWlirRyH6RPfeAi5kySOEhG1quNHe06QIw
pigjyFT6v/vRqoIBr7WpDOSt1VzXPVbSj1PcWBgkwyGKHlQUOuSbHbHcjOD8w8wHSDbL+L2h
e8hNN54doy1e1wJHKmnfb0uBAeISoxRbJnMMWvgAlH5FVrQWlgajeH/6NbYbBSRxALuEOqEQ
epmJM6qz4oD2sxdq4GMN5adAdYEswkY/o0bRKyFXTD3mdqeRXce0jYQbWm7oapqSZBccFvUg
YOrB78tB6c1bxIgaQKRShtWR1zMM0JfqUfD9u8Fg7G5SVO0IG/GcxkSvZeRjhYcbTfqF2eAg
prpyzLWmdr0mou3bv1Sq4OuBhmTQCnqxAXr4yVTRYHkp5lCvRgeJAme1OTVpVPth/O7HJ7Vu
EP9GOr6kCXCXmjB4P3UJ2oU0NqfoQdcSSSt9hliALnExTEjii20B2nSDojGCAxQwggMQAgEB
ME4wOjELMAkGA1UEBhMCVVMxEjAQBgNVBAoTCUlkZW5UcnVzdDEXMBUGA1UEAxMOVHJ1c3RJ
RCBDQSBBMTICEEABWCMQ3tYWgIhfKVnW69IwDQYJYIZIAWUDBAIBBQCgggGXMBgGCSqGSIb3
DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTE3MDQwNTEyNDAyN1owLwYJKoZI
hvcNAQkEMSIEIEYUuLEMbtNl62T4INAH5NLH7ZtvtQUiJORd45JcWAPgMF0GCSsGAQQBgjcQ
BDFQME4wOjELMAkGA1UEBhMCVVMxEjAQBgNVBAoTCUlkZW5UcnVzdDEXMBUGA1UEAxMOVHJ1
c3RJRCBDQSBBMTICEEABWCMQ3tYWgIhfKVnW69IwXwYLKoZIhvcNAQkQAgsxUKBOMDoxCzAJ
BgNVBAYTAlVTMRIwEAYDVQQKEwlJZGVuVHJ1c3QxFzAVBgNVBAMTDlRydXN0SUQgQ0EgQTEy
AhBAAVgjEN7WFoCIXylZ1uvSMGwGCSqGSIb3DQEJDzFfMF0wCwYJYIZIAWUDBAEqMAsGCWCG
SAFlAwQBAjAKBggqhkiG9w0DBzAOBggqhkiG9w0DAgICAIAwDQYIKoZIhvcNAwICAUAwBwYF
Kw4DAgcwDQYIKoZIhvcNAwICASgwDQYJKoZIhvcNAQEBBQAEggEAcvTM4woz62YUp8rrVg9r
lzWDQtGaYLDftkjPwKXR6F2XbicWBDs675UAS5P45h3GNVdd+5sQMe3V1CNvw0Sd3F/0ILD9
yfLDRoYLmesOumhI/gRsf4XDHi74+pJX4CDGj0Xpg0U/AcEnwFpVh82e7Qez6RLK177Fuwvy
fpXopXTqaRj7yP1D6E5fs9oBLWQixzkTN0CuWL3cSAScTyFzjbxXa4Dl+UTyDCL/ciTOvszS
9ypyKXtq3dYVbfu7PaYoc+xDAUYoL/6LsQn/qCX5Y3x/o/OId9+wJFgixbeEUxABozBu7Xz/
I3yXfhw/cn9CuU+q6HTVulATu02FHtEh4AAAAAAAAA==
--------------ms040501060207090503080604--


From nobody Wed Apr  5 08:13:47 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7C79F126DC2 for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:13:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.202
X-Spam-Level: 
X-Spam-Status: No, score=-4.202 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KHtqVgmrwVOV for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:13:43 -0700 (PDT)
Received: from dmz-mailsec-scanner-4.mit.edu (dmz-mailsec-scanner-4.mit.edu [18.9.25.15]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 55112128D2E for <kitten@ietf.org>; Wed,  5 Apr 2017 08:13:43 -0700 (PDT)
X-AuditID: 1209190f-05bff7000000329e-65-58e509a5960b
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id EF.3E.12958.6A905E85; Wed,  5 Apr 2017 11:13:42 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id v35FDeIf028576; Wed, 5 Apr 2017 11:13:41 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v35FDaR7005955 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 5 Apr 2017 11:13:39 -0400
Date: Wed, 5 Apr 2017 10:13:36 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: Jeffrey Altman <jaltman@secure-endpoints.com>
Cc: kitten@ietf.org
Message-ID: <20170405151336.GK30306@kduck.kaduk.org>
References: <20170405045550.GJ30306@kduck.kaduk.org> <fa13dc36-a2b7-190e-a64d-109161123fac@secure-endpoints.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <fa13dc36-a2b7-190e-a64d-109161123fac@secure-endpoints.com>
User-Agent: Mutt/1.6.1 (2016-04-27)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrFIsWRmVeSWpSXmKPExsUixCmqrLuM82mEwekzIhZ/Vk5iszi6eRWL A5PHkiU/mTxO9p1nDWCK4rJJSc3JLEst0rdL4Mr403WYpaBTtqJx0T3GBsaH4l2MnBwSAiYS myY+Yeti5OIQEmhjkngxdyUzhLOBUeJK6zQWCOcKk8SXf4eAyjg4WARUJNZe9QLpZgMyG7ov M4PYIgKGEm3/b7KC2MwCwhLL15xlA7GFBTQlmh9vYgKxeYG2vb/yEiwuJFAksWfJakaIuKDE yZlPWCB6tSRu/HvJBLKKWUBaYvk/DpAwp4CHxJP2DWCrRAWUJRpmPGCewCgwC0n3LCTdsxC6 FzAyr2KUTcmt0s1NzMwpTk3WLU5OzMtLLdI10cvNLNFLTSndxAgOUkn+HYxzGrwPMQpwMCrx 8Ho8fhIhxJpYVlyZe4hRkoNJSZRXwQcoxJeUn1KZkVicEV9UmpNafIhRgoNZSYR3P+PTCCHe lMTKqtSifJiUNAeLkjivuEZjhJBAemJJanZqakFqEUxWhoNDSYI3nwOoUbAoNT21Ii0zpwQh zcTBCTKcB2i4KUgNb3FBYm5xZjpE/hSjopQ47xKQhABIIqM0D64XlEQksvfXvGIUB3pFmPcT SBUPMAHBdb8CGswENPjJnYcgg0sSEVJSDYz7FL+cnR19Vv9B8Os+jUzhiJf+jnZVsgl5Ht8i 3z+sed5pEuZiFJ76T+LZ+pbQRolvOpXrZ/vfqm861PpaOuPcvGDhgFeXjnc5Vfvc2TQjpURB gzlg+e3bUnv5WJU0QlM0bn+9brszTOPe/Bc6V5z3bttqqip8ojbxZmOVwwV1kyYbln2swkos xRmJhlrMRcWJAMMxj4T9AgAA
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/ixM7DwXUEZoPHT-_HwXLC-SQu10>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 15:13:45 -0000

On Wed, Apr 05, 2017 at 08:40:27AM -0400, Jeffrey Altman wrote:
> On 4/5/2017 12:55 AM, Benjamin Kaduk wrote:
> >
> > To give some historical perspective on the sense of the working
> > group, back in Buenos Aires the chairs had a (very broad!) list of:
> > draft-williams-kitten-krb5-pkcross
> > draft-williams-kitten-krb5-extra-rt
> > draft-williams-kitten-generic-naming-attributes
> > draft-williams-kitten-impersonation-naming-attr
> > draft-vanrein-kitten-rfbsasl
> > draft-vanrein-dnstxt-krb1
> > draft-vanrein-krb5-kdh
> > draft-vanrein-kitten-krb5-pseudonymity
> > draft-mccallum-kitten-krb-spake-preauth
> > draft-kaduk-kitten-des-des-des-die-die-die
> > draft-howard-gssapi-aead
> > draft-mccallum-kitten-krb-service-discovery
> 
> Not on this list (possibly because the draft was expired at the time of
> the Buenos Aires meeting) is
> 
>   https://datatracker.ietf.org/doc/draft-cantor-ietf-kitten-saml-ec/


That was adopted years ago and became
https://datatracker.ietf.org/doc/draft-ietf-kitten-sasl-saml-ec/ ,
though apparently no one set the right metadata to show it as
replacing the draft-cantor version.

If you think it is ready to publish, please send a review of the
latest version to the list (or a link to one you already sent), and
we can make a github repo to track reviews of that document and try
to move it forward.  I did not un-expire it with my batch from last
week because I was unsure if there was any WG interest in moving it
forward, though it seems I now have the answer to that question.

> which has an open source implementation for Shibboleth at
> 
>   https://github.com/fedushare/mech_saml_ec
> 
> > and the sense of the room was that
> > draft-mccallum-kitten-krb-spake-preauth and
> > draft-williams-kitten-krb5-pkcross were the most promising.
> > 
> > (draft-mccallum-kitten-krb-service-discovery has since been adopted)
> > 
> > Recall that our current work items are listed at:
> > https://datatracker.ietf.org/wg/kitten/documents/ , some of which
> > are believed to be ready to send to the IESG or nearly so.
> > 
> > What do people currently feel are the top one or two highest
> > priority items for the WG to consider?  (Such items need not be
> > limited to the above list, of course; note that, e.g.,
> > draft-schmaus-kitten-sasl-ht-00 has recently appeared on the list of
> > related internet-drafts.)
> > 
> > I'll also note that we should be able to ask the curdle WG to take
> > on draft-kaduk-kitten-des-des-des-die-die-die, which is simple
> > deprecation of RC4 and 3DES (and some registry cleanup from RFC
> > 6649).  I'll plan to do that unless people want to do it in kitten
> > instead.  One might also ask about moving
> > draft-ietf-kitten-pkinit-alg-agility to curdle (since it moves
> > PKINIT off SHA1), but that's a little more complicated since it
> > first has to add the agility to do so, and judging by the reviews
> > accumulated and noted at
> > https://github.com/kittenwg/draft-ietf-kitten-pkinit-alg-agility ,
> > it should be basically done already.
> 
> I believe that draft-kaduk-kitten-des-des-des-die-die-die fine as-is and
> should simply be published by Kitten.

Have you reviewed a specific revision of it so as to form that
opinion?  Again, if we don't have a number of reviews that we can
track, the document is just going to sit there and not move forward.

> I would like to see the following documents be adopted
> 
>   draft-williams-kitten-krb5-pkcross
>   draft-howard-gssapi-aead
>   draft-cantor-ietf-kitten-saml-ec

Hmm, that is only "one or two" on a technicality (the
draft-cantor-ietf-kitten-saml-ec is already a WG item).

-Ben


From nobody Wed Apr  5 08:22:10 2017
Return-Path: <prvs=1268e6793a=jaltman@secure-endpoints.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7A8F412945C for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:22:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=secure-endpoints.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yra2N_KNDN7L for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:22:06 -0700 (PDT)
Received: from sequoia-grove.secure-endpoints.com (sequoia-grove.ad.secure-endpoints.com [208.125.0.235]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 52B33129481 for <kitten@ietf.org>; Wed,  5 Apr 2017 08:22:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/relaxed; d=secure-endpoints.com; s=MDaemon; t=1491405701; x=1492010501; i=jaltman@secure-endpoints.com; q=dns/txt; h=VBR-Info:Subject:To: References:Cc:From:Openpgp:Organization:Message-ID:Date: User-Agent:MIME-Version:In-Reply-To:Content-Type; bh=+VvIOjNVGpf ifbwUdzK1VKkyqKLdE7vNZZvbodYx8AE=; b=XpJ5wYVyd8XCA4sIgrCQ+MjN0zM av5RXL0L8x2iQRsvHjJdCHx5p3KrSm0E57PDkIEdgmFH9HXaB2Y1A4envuwwoC6Y XrsNiVm/6iZuKSSMtVR06JbZ9uYHD8pC3JXREA1ISdBIydLd/llT0AbqZJN3yBmi 7s10USA8ApqXWWDY=
X-MDAV-Result: clean
X-MDAV-Processed: sequoia-grove.secure-endpoints.com, Wed, 05 Apr 2017 11:21:40 -0400
X-Spam-Processed: sequoia-grove.secure-endpoints.com, Wed, 05 Apr 2017 11:21:37 -0400
Received: from [IPv6:2001:470:1f07:f77:d804:1659:6eb:7670] by secure-endpoints.com (IPv6:2001:470:1f07:f77:28d9:68fb:855d:c2a5) (MDaemon PRO v17.0.0)  with ESMTPSA id md50001309305.msg; Wed, 05 Apr 2017 11:21:36 -0400
VBR-Info: md=secure-endpoints.com; mc=all; mv=vbr.emailcertification.org;
X-MDRemoteIP: 2001:470:1f07:f77:d804:1659:6eb:7670
X-MDHelo: [IPv6:2001:470:1f07:f77:d804:1659:6eb:7670]
X-MDArrival-Date: Wed, 05 Apr 2017 11:21:36 -0400
X-Authenticated-Sender: jaltman@secure-endpoints.com
X-Return-Path: prvs=1268e6793a=jaltman@secure-endpoints.com
X-Envelope-From: jaltman@secure-endpoints.com
X-MDaemon-Deliver-To: kitten@ietf.org
X-CAV-Result: clean
To: Benjamin Kaduk <kaduk@mit.edu>
References: <20170405045550.GJ30306@kduck.kaduk.org> <fa13dc36-a2b7-190e-a64d-109161123fac@secure-endpoints.com> <20170405151336.GK30306@kduck.kaduk.org>
Cc: kitten@ietf.org
From: Jeffrey Altman <jaltman@secure-endpoints.com>
Openpgp: id=FA444AF197F449B24CF3E699F77A735592B69A04; url=https://pgp.mit.edu
Organization: Secure Endpoints Inc.
Message-ID: <c69af66b-b105-b8ce-27da-14cfd176ff14@secure-endpoints.com>
Date: Wed, 5 Apr 2017 11:21:32 -0400
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.8.0
MIME-Version: 1.0
In-Reply-To: <20170405151336.GK30306@kduck.kaduk.org>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha-256; boundary="------------ms040503050900020809060400"
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/pQ43CKId2oi8LwPvGtC28Gh3XBc>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 15:22:08 -0000

This is a cryptographically signed message in MIME format.

--------------ms040503050900020809060400
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

On 4/5/2017 11:13 AM, Benjamin Kaduk wrote:
> On Wed, Apr 05, 2017 at 08:40:27AM -0400, Jeffrey Altman wrote:
>> On 4/5/2017 12:55 AM, Benjamin Kaduk wrote:
>>>
>>> To give some historical perspective on the sense of the working
>>> group, back in Buenos Aires the chairs had a (very broad!) list of:
>>> draft-williams-kitten-krb5-pkcross
>>> draft-williams-kitten-krb5-extra-rt
>>> draft-williams-kitten-generic-naming-attributes
>>> draft-williams-kitten-impersonation-naming-attr
>>> draft-vanrein-kitten-rfbsasl
>>> draft-vanrein-dnstxt-krb1
>>> draft-vanrein-krb5-kdh
>>> draft-vanrein-kitten-krb5-pseudonymity
>>> draft-mccallum-kitten-krb-spake-preauth
>>> draft-kaduk-kitten-des-des-des-die-die-die
>>> draft-howard-gssapi-aead
>>> draft-mccallum-kitten-krb-service-discovery
>>
>> Not on this list (possibly because the draft was expired at the time o=
f
>> the Buenos Aires meeting) is
>>
>>   https://datatracker.ietf.org/doc/draft-cantor-ietf-kitten-saml-ec/
>=20
>=20
> That was adopted years ago and became
> https://datatracker.ietf.org/doc/draft-ietf-kitten-sasl-saml-ec/ ,
> though apparently no one set the right metadata to show it as
> replacing the draft-cantor version.

The document

  https://datatracker.ietf.org/doc/draft-ietf-kitten-sasl-saml-ec/ ,

is not listed at

  https://datatracker.ietf.org/wg/kitten/documents/

possibly because it is expired and archived.

> If you think it is ready to publish, please send a review of the
> latest version to the list (or a link to one you already sent), and
> we can make a github repo to track reviews of that document and try
> to move it forward.  I did not un-expire it with my batch from last
> week because I was unsure if there was any WG interest in moving it
> forward, though it seems I now have the answer to that question.
>=20
>> which has an open source implementation for Shibboleth at
>>
>>   https://github.com/fedushare/mech_saml_ec
>>
>>> and the sense of the room was that
>>> draft-mccallum-kitten-krb-spake-preauth and
>>> draft-williams-kitten-krb5-pkcross were the most promising.
>>>
>>> (draft-mccallum-kitten-krb-service-discovery has since been adopted)
>>>
>>> Recall that our current work items are listed at:
>>> https://datatracker.ietf.org/wg/kitten/documents/ , some of which
>>> are believed to be ready to send to the IESG or nearly so.
>>>
>>> What do people currently feel are the top one or two highest
>>> priority items for the WG to consider?  (Such items need not be
>>> limited to the above list, of course; note that, e.g.,
>>> draft-schmaus-kitten-sasl-ht-00 has recently appeared on the list of
>>> related internet-drafts.)
>>>
>>> I'll also note that we should be able to ask the curdle WG to take
>>> on draft-kaduk-kitten-des-des-des-die-die-die, which is simple
>>> deprecation of RC4 and 3DES (and some registry cleanup from RFC
>>> 6649).  I'll plan to do that unless people want to do it in kitten
>>> instead.  One might also ask about moving
>>> draft-ietf-kitten-pkinit-alg-agility to curdle (since it moves
>>> PKINIT off SHA1), but that's a little more complicated since it
>>> first has to add the agility to do so, and judging by the reviews
>>> accumulated and noted at
>>> https://github.com/kittenwg/draft-ietf-kitten-pkinit-alg-agility ,
>>> it should be basically done already.
>>
>> I believe that draft-kaduk-kitten-des-des-des-die-die-die fine as-is a=
nd
>> should simply be published by Kitten.
>=20
> Have you reviewed a specific revision of it so as to form that
> opinion?  Again, if we don't have a number of reviews that we can
> track, the document is just going to sit there and not move forward.

This is only one revision of


https://datatracker.ietf.org/doc/html/draft-kaduk-kitten-des-des-des-die-=
die-die

I have reviewed it.  Given that it is a document describing deprecation
of encryption types I don't think it requires perfection.

>> I would like to see the following documents be adopted
>>
>>   draft-williams-kitten-krb5-pkcross
>>   draft-howard-gssapi-aead
>>   draft-cantor-ietf-kitten-saml-ec
>=20
> Hmm, that is only "one or two" on a technicality (the
> draft-cantor-ietf-kitten-saml-ec is already a WG item).
>=20
> -Ben
>=20


--------------ms040503050900020809060400
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCC
DJswggYCMIIE6qADAgECAhBAAVgjEN7WFoCIXylZ1uvSMA0GCSqGSIb3DQEBCwUAMDoxCzAJ
BgNVBAYTAlVTMRIwEAYDVQQKEwlJZGVuVHJ1c3QxFzAVBgNVBAMTDlRydXN0SUQgQ0EgQTEy
MB4XDTE2MTEwMjAzMjQxOFoXDTE3MTEwMjAzMjQxOFowgZYxNTAzBgNVBAsMLFZlcmlmaWVk
IEVtYWlsOiBqYWx0bWFuQHNlY3VyZS1lbmRwb2ludHMuY29tMSswKQYJKoZIhvcNAQkBFhxq
YWx0bWFuQHNlY3VyZS1lbmRwb2ludHMuY29tMTAwLgYKCZImiZPyLGQBARMgN0YwMDAwMDEw
MDAwMDE1ODIzMTBERUE3MDAwMDA3QjQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDPaPDUdwWkzLcNsJjjlDs5lo4ySDKmCgzQsuDt+VY3wP0IZBbu8f/LM3zWCH7zVRJ/XuY5
qN44jFEXwj5fGY71Esm5pKv5sUpys6Q3c6BKXiHv/IUusI3qTJ46QBEAiHu2lxB75UnIYgm+
ZbKmcAR48Z1Sl/Ku86e9GPuts9R51SeHW1pjq89LAi6C0ERuAUIK0rVZGDmKWtRNs9EykXzk
mU2Z1ZLuPL0jIggFPeT8TyH6TH/XvapbC+7rHJrzuBY4NDqLgqDJUf0JidL9JeK9+IxxPCab
EbVmOf5sBgO5mg92l4+f+Q4xefZcI4C7RPFdRTRWsQs7Z3DpE28BDbjDAgMBAAGjggKlMIIC
oTAOBgNVHQ8BAf8EBAMCBaAwgYQGCCsGAQUFBwEBBHgwdjAwBggrBgEFBQcwAYYkaHR0cDov
L2NvbW1lcmNpYWwub2NzcC5pZGVudHJ1c3QuY29tMEIGCCsGAQUFBzAChjZodHRwOi8vdmFs
aWRhdGlvbi5pZGVudHJ1c3QuY29tL2NlcnRzL3RydXN0aWRjYWExMi5wN2MwHwYDVR0jBBgw
FoAUpHPa72k1inXMoBl7CDL4a4nkQuwwCQYDVR0TBAIwADCCASwGA1UdIASCASMwggEfMIIB
GwYLYIZIAYb5LwAGCwEwggEKMEoGCCsGAQUFBwIBFj5odHRwczovL3NlY3VyZS5pZGVudHJ1
c3QuY29tL2NlcnRpZmljYXRlcy9wb2xpY3kvdHMvaW5kZXguaHRtbDCBuwYIKwYBBQUHAgIw
ga4agatUaGlzIFRydXN0SUQgQ2VydGlmaWNhdGUgaGFzIGJlZW4gaXNzdWVkIGluIGFjY29y
ZGFuY2Ugd2l0aCAKSWRlblRydXN0J3MgVHJ1c3RJRCBDZXJ0aWZpY2F0ZSBQb2xpY3kgZm91
bmQgYXQgaHR0cHM6Ly9zZWN1cmUuaWRlbnRydXN0LmNvbS9jZXJ0aWZpY2F0ZXMvcG9saWN5
L3RzL2luZGV4Lmh0bWwwRQYDVR0fBD4wPDA6oDigNoY0aHR0cDovL3ZhbGlkYXRpb24uaWRl
bnRydXN0LmNvbS9jcmwvdHJ1c3RpZGNhYTEyLmNybDAnBgNVHREEIDAegRxqYWx0bWFuQHNl
Y3VyZS1lbmRwb2ludHMuY29tMB0GA1UdDgQWBBSP11Voh/Sg9hmecftn2BV5ZQd9OTAdBgNV
HSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwQwDQYJKoZIhvcNAQELBQADggEBAC9cnqRj+ViE
efFsiYNMUC8tZf6PXcWDecOR5Pdv/Vd/O6y10mYyilPrcd0sJux1idTZIOzHAsh36BfBdNSt
BFAuBZD66L649U3XqBnh9nbuzmCwNc3tWjOaY/Xe7R90lqrXaW0Dw0U++zwmNyCO2CRgBdrU
8cTqFpOtpe/gCAMhjajrUfb+m8Vcd5R0RVIvdljblqv2t9IXQIHwWSm8E7v302z7yW4o4iPH
kegez5vq37ICikQjkkVyAJr0wtirJyQuFzMgpoWVpm0CKBiMwJPki2kiHlNiMHBr2ch4fC+H
SjbMg4OzTZJCz1xhKvpyRDOM8JRb2BNSU8JjmrxZgFIwggaRMIIEeaADAgECAhEA+d5Wf8lN
DHdw+WAbUtoVOzANBgkqhkiG9w0BAQsFADBKMQswCQYDVQQGEwJVUzESMBAGA1UEChMJSWRl
blRydXN0MScwJQYDVQQDEx5JZGVuVHJ1c3QgQ29tbWVyY2lhbCBSb290IENBIDEwHhcNMTUw
MjE4MjIyNTE5WhcNMjMwMjE4MjIyNTE5WjA6MQswCQYDVQQGEwJVUzESMBAGA1UEChMJSWRl
blRydXN0MRcwFQYDVQQDEw5UcnVzdElEIENBIEExMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBANGRTTzPCic0kq5L6ZrUJWt5LE/n6tbPXPhGt2Egv7plJMoEpvVJJDqGqDYy
maAsd8Hn9ZMAuKUEFdlx5PgCkfu7jL5zgiMNnAFVD9PyrsuF+poqmlxhlQ06sFY2hbhQkVVQ
00KCNgUzKcBUIvjv04w+fhNPkwGW5M7Ae5K5OGFGwOoRck9GG6MUVKvTNkBw2/vNMOd29VGV
TtR0tjH5PS5yDXss48Yl1P4hDStO2L4wTsW2P37QGD27//XGN8K6amWB6F2XOgff/PmlQjQO
ORT95PmLkwwvma5nj0AS0CVp8kv0K2RHV7GonllKpFDMT0CkxMQKwoj+tWEWJTiDKSsCAwEA
AaOCAoAwggJ8MIGJBggrBgEFBQcBAQR9MHswMAYIKwYBBQUHMAGGJGh0dHA6Ly9jb21tZXJj
aWFsLm9jc3AuaWRlbnRydXN0LmNvbTBHBggrBgEFBQcwAoY7aHR0cDovL3ZhbGlkYXRpb24u
aWRlbnRydXN0LmNvbS9yb290cy9jb21tZXJjaWFscm9vdGNhMS5wN2MwHwYDVR0jBBgwFoAU
7UQZwNPwBovupHu+QucmVMiONnYwDwYDVR0TAQH/BAUwAwEB/zCCASAGA1UdIASCARcwggET
MIIBDwYEVR0gADCCAQUwggEBBggrBgEFBQcCAjCB9DBFFj5odHRwczovL3NlY3VyZS5pZGVu
dHJ1c3QuY29tL2NlcnRpZmljYXRlcy9wb2xpY3kvdHMvaW5kZXguaHRtbDADAgEBGoGqVGhp
cyBUcnVzdElEIENlcnRpZmljYXRlIGhhcyBiZWVuIGlzc3VlZCBpbiBhY2NvcmRhbmNlIHdp
dGggSWRlblRydXN0J3MgVHJ1c3RJRCBDZXJ0aWZpY2F0ZSBQb2xpY3kgZm91bmQgYXQgaHR0
cHM6Ly9zZWN1cmUuaWRlbnRydXN0LmNvbS9jZXJ0aWZpY2F0ZXMvcG9saWN5L3RzL2luZGV4
Lmh0bWwwSgYDVR0fBEMwQTA/oD2gO4Y5aHR0cDovL3ZhbGlkYXRpb24uaWRlbnRydXN0LmNv
bS9jcmwvY29tbWVyY2lhbHJvb3RjYTEuY3JsMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEF
BQcDBDAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0OBBYEFKRz2u9pNYp1zKAZewgy+GuJ5ELsMA0G
CSqGSIb3DQEBCwUAA4ICAQAN4YKu0vv062MZfg+xMSNUXYKvHwvZIk+6H1pUmivyDI4I6A3w
Wzxlr83ZJm0oGIF6PBsbgKJ/fhyyIzb+vAYFJmyI8I/0mGlc+nIQNuV2XY8cypPoVJKgpnzp
/7cECXkX8R4NyPtEn8KecbNdGBdEaG4a7AkZ3ujlJofZqYdHxN29tZPdDlZ8fR36/mAFeCEq
0wOtOOc0Eyhs29+9MIZYjyxaPoTS+l8xLcuYX3RWlirRyH6RPfeAi5kySOEhG1quNHe06QIw
pigjyFT6v/vRqoIBr7WpDOSt1VzXPVbSj1PcWBgkwyGKHlQUOuSbHbHcjOD8w8wHSDbL+L2h
e8hNN54doy1e1wJHKmnfb0uBAeISoxRbJnMMWvgAlH5FVrQWlgajeH/6NbYbBSRxALuEOqEQ
epmJM6qz4oD2sxdq4GMN5adAdYEswkY/o0bRKyFXTD3mdqeRXce0jYQbWm7oapqSZBccFvUg
YOrB78tB6c1bxIgaQKRShtWR1zMM0JfqUfD9u8Fg7G5SVO0IG/GcxkSvZeRjhYcbTfqF2eAg
prpyzLWmdr0mou3bv1Sq4OuBhmTQCnqxAXr4yVTRYHkp5lCvRgeJAme1OTVpVPth/O7HJ7Vu
EP9GOr6kCXCXmjB4P3UJ2oU0NqfoQdcSSSt9hliALnExTEjii20B2nSDojGCAxQwggMQAgEB
ME4wOjELMAkGA1UEBhMCVVMxEjAQBgNVBAoTCUlkZW5UcnVzdDEXMBUGA1UEAxMOVHJ1c3RJ
RCBDQSBBMTICEEABWCMQ3tYWgIhfKVnW69IwDQYJYIZIAWUDBAIBBQCgggGXMBgGCSqGSIb3
DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTE3MDQwNTE1MjEzMlowLwYJKoZI
hvcNAQkEMSIEID94abLtyJK0UmfSWKCdYkvzmjfY/7xSqObGNxf7R1WhMF0GCSsGAQQBgjcQ
BDFQME4wOjELMAkGA1UEBhMCVVMxEjAQBgNVBAoTCUlkZW5UcnVzdDEXMBUGA1UEAxMOVHJ1
c3RJRCBDQSBBMTICEEABWCMQ3tYWgIhfKVnW69IwXwYLKoZIhvcNAQkQAgsxUKBOMDoxCzAJ
BgNVBAYTAlVTMRIwEAYDVQQKEwlJZGVuVHJ1c3QxFzAVBgNVBAMTDlRydXN0SUQgQ0EgQTEy
AhBAAVgjEN7WFoCIXylZ1uvSMGwGCSqGSIb3DQEJDzFfMF0wCwYJYIZIAWUDBAEqMAsGCWCG
SAFlAwQBAjAKBggqhkiG9w0DBzAOBggqhkiG9w0DAgICAIAwDQYIKoZIhvcNAwICAUAwBwYF
Kw4DAgcwDQYIKoZIhvcNAwICASgwDQYJKoZIhvcNAQEBBQAEggEAsLEa1IGWB7cTsOvLUeym
1cu4RAvZRGeevbTmsFkG0ixcCoDcDlVt3bOgrDOtZtCVD7v9OU2RKhqHIdNd1HHSAEKqHTwK
0k+H6dnGAND7IGZLMbOGb868Gubx1TeQ2w1EM4IbwGqsPql9NMACWinIBNa+MihANq7U4BUb
R92DiBdDwu4sE4+oqHMMOda198lodlsszd/nFJIlpLF9hpFfeCl/ywtSDdiXQs7+TwpPvJQ5
LULjVT4vbAaTBq+8bscY6/4WJlD61pijznErxHf2x/DrznJeFp2gZCdHiqTuGHosQuL8fb1l
fidKgg6fldNxZYMzt99K0TzfdXqxdb9iHgAAAAAAAA==
--------------ms040503050900020809060400--


From nobody Wed Apr  5 08:29:34 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1A81512941C for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:29:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.202
X-Spam-Level: 
X-Spam-Status: No, score=-4.202 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MQnQ0TKB466n for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:29:30 -0700 (PDT)
Received: from dmz-mailsec-scanner-1.mit.edu (dmz-mailsec-scanner-1.mit.edu [18.9.25.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0E76C12945C for <kitten@ietf.org>; Wed,  5 Apr 2017 08:29:24 -0700 (PDT)
X-AuditID: 1209190c-30fff70000005d5d-7b-58e50d53ae60
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id D0.F2.23901.35D05E85; Wed,  5 Apr 2017 11:29:24 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id v35FTMWQ007231 for <kitten@ietf.org>; Wed, 5 Apr 2017 11:29:23 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v35FTJkm012640 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Wed, 5 Apr 2017 11:29:22 -0400
Date: Wed, 5 Apr 2017 10:29:19 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: kitten@ietf.org
Message-ID: <20170405152919.GL30306@kduck.kaduk.org>
References: <20170405045550.GJ30306@kduck.kaduk.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20170405045550.GJ30306@kduck.kaduk.org>
User-Agent: Mutt/1.6.1 (2016-04-27)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrEIsWRmVeSWpSXmKPExsUixG6nohvC+zTCYOkZZoujm1exODB6LFny kymAMYrLJiU1J7MstUjfLoEro7X1JkvBXI6K9ubbLA2Mt9m6GDk4JARMJC4u4+1i5OIQEmhj ktj08Co7hHOMUWLi309sEM4rJolLLZPZQTpYBFQktuzm6mLk5GADMhu6LzOD2CICwhK7t74D s4UFNCWaH29iArF5gRas7WgDs4WA7H39T9gg4oISJ2c+YQGxmQW0JG78e8kEMp5ZQFpi+T8O EJNTwFTi71EpkApRAWWJhhkPmCcw8s9C0jwLSfMshOYFjMyrGGVTcqt0cxMzc4pTk3WLkxPz 8lKLdA31cjNL9FJTSjcxgoKOU5JnB+OZN16HGAU4GJV4eBc8fRIhxJpYVlyZe4hRkoNJSZRX wQcoxJeUn1KZkVicEV9UmpNafIhRgoNZSYQ3lftphBBvSmJlVWpRPkxKmoNFSZxXQqMxQkgg PbEkNTs1tSC1CCYrw8GhJMF7BaRRsCg1PbUiLTOnBCHNxMEJMpwHaLg92PDigsTc4sx0iPwp RkUpcd7pIAkBkERGaR5cLygpSGTvr3nFKA70ijAvCw9QFQ8wocB1vwIazAQ0+MmdhyCDSxIR UlINjKdOHyq+8HiVXdjscC/hGvaNOjncXN+Vdu85yJm158PpY8X3VadLyWrPy7kzQfL67OfO r3fLpX49F7dZ/gLLpza7mZOFUjYsi+7mljvLsXuxLG+BwPqemXtmBXFtSZjowfL1a9nZt6VB h3wN1OsXeH67NTtjQ78065MvtRaR+Zsu3lwvefvjGlMlluKMREMt5qLiRACaZzRq5QIAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/re5xGj_sWsaWyZyiavwkiWc1ryQ>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 15:29:32 -0000

On Tue, Apr 04, 2017 at 11:55:50PM -0500, Benjamin Kaduk wrote:
> 
> What do people currently feel are the top one or two highest
> priority items for the WG to consider?  (Such items need not be
> limited to the above list, of course; note that, e.g.,
> draft-schmaus-kitten-sasl-ht-00 has recently appeared on the list of
> related internet-drafts.)

Taking off my chair hat, I think that
draft-mccallum-kitten-krb-spake-preauth is the most pressing item.
Currently, our claims to security rely on users selecting strong
passwords, which is a laughable assumption given dumps from password
database leaks/etc.  Being able to close off avenues for offline
attacks, which also providing an integrated way to include a second
factor that cannot be attacked separately from the password, seems
like a huge security win.

When I talked to Kenny Paterson about the potential impact of RC4
weaknesses on Kerberos, he said that directly using password-derived
keys is a far bigger problem than the statistical weakenesses of
RC4.

-Ben


From nobody Wed Apr  5 08:35:13 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A541A129477 for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:35:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.202
X-Spam-Level: 
X-Spam-Status: No, score=-4.202 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OfseKJf7qN8K for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:35:09 -0700 (PDT)
Received: from dmz-mailsec-scanner-5.mit.edu (dmz-mailsec-scanner-5.mit.edu [18.7.68.34]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9F804129487 for <kitten@ietf.org>; Wed,  5 Apr 2017 08:35:04 -0700 (PDT)
X-AuditID: 12074422-847ff700000053c1-51-58e50ea6d304
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id 2D.D4.21441.6AE05E85; Wed,  5 Apr 2017 11:35:03 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id v35FZ1ff032251; Wed, 5 Apr 2017 11:35:02 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v35FYvDi014719 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 5 Apr 2017 11:35:00 -0400
Date: Wed, 5 Apr 2017 10:34:58 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: Jeffrey Altman <jaltman@secure-endpoints.com>
Cc: kitten@ietf.org
Message-ID: <20170405153457.GM30306@kduck.kaduk.org>
References: <20170405045550.GJ30306@kduck.kaduk.org> <fa13dc36-a2b7-190e-a64d-109161123fac@secure-endpoints.com> <20170405151336.GK30306@kduck.kaduk.org> <c69af66b-b105-b8ce-27da-14cfd176ff14@secure-endpoints.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <c69af66b-b105-b8ce-27da-14cfd176ff14@secure-endpoints.com>
User-Agent: Mutt/1.6.1 (2016-04-27)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrNIsWRmVeSWpSXmKPExsUixCmqrLuc72mEwaSrOhZ/Vk5iszi6eRWL A5PHkiU/mTxO9p1nDWCK4rJJSc3JLEst0rdL4Mp4+WIFe8Fyvop7v5ewNjCe5O5i5OSQEDCR eL3gO2sXIxeHkEAbk8TX51egnA2MEkded7OBVAkJXGGSOLo+AsRmEVCR6Dl6gBXEZgOyG7ov M4PYIgKGEm3/b4LFmQWEJZavOQvWKyygKdH8eBMTiM0LtK338j0miAW3GSX6131kh0gISpyc +YQFollL4sa/l0BFHEC2tMTyfxwgYU4BD4lFZ2eDzRQVUJZomPGAeQKjwCwk3bOQdM9C6F7A yLyKUTYlt0o3NzEzpzg1Wbc4OTEvL7VI11QvN7NELzWldBMjKEzZXZR2ME7853WIUYCDUYmH d8HTJxFCrIllxZW5hxglOZiURHkVfIBCfEn5KZUZicUZ8UWlOanFhxglOJiVRHhTuZ9GCPGm JFZWpRblw6SkOViUxHnFNRojhATSE0tSs1NTC1KLYLIyHBxKErz2vECNgkWp6akVaZk5JQhp Jg5OkOE8QMNjQGp4iwsSc4sz0yHypxgVpcR53/MAJQRAEhmleXC9oDQikb2/5hWjONArwrzf QKp4gCkIrvsV0GAmoMFP7jwEGVySiJCSamAMm/P3H8OVRwsEF185UHiLxeJsf3plhIhMrGNZ eFFp6fuISknfLXu1jvwQCimJViy9/2bepF3aDqYPg+9Mu9N56cHRM9YGr/hPN0VKLJK9mROw ZN5Er0c3owT52XxXeU8Vr3z/4r/9DMmXwbPTxZLKjLeaz9EX+Ry59cYjs3o3r5sTyormFR1U YinOSDTUYi4qTgQAgJJ/JP4CAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/ZJtpZqbhRmT5-cF7MtlFtjoebAI>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 15:35:12 -0000

On Wed, Apr 05, 2017 at 11:21:32AM -0400, Jeffrey Altman wrote:
> On 4/5/2017 11:13 AM, Benjamin Kaduk wrote:
> > 
> > That was adopted years ago and became
> > https://datatracker.ietf.org/doc/draft-ietf-kitten-sasl-saml-ec/ ,
> > though apparently no one set the right metadata to show it as
> > replacing the draft-cantor version.
> 
> The document
> 
>   https://datatracker.ietf.org/doc/draft-ietf-kitten-sasl-saml-ec/ ,
> 
> is not listed at
> 
>   https://datatracker.ietf.org/wg/kitten/documents/
> 
> possibly because it is expired and archived.

Yes, the datatracker has in the past year or two gotten more
aggressive about not displaying expired/archived documents.  They
still show up in a document search, though.

I will take an action item to post a new no-change revision to
un-expire it and return it to the WG dashboard, since you have
expressed interest in it.

> >>
> >> I believe that draft-kaduk-kitten-des-des-des-die-die-die fine as-is and
> >> should simply be published by Kitten.
> > 
> > Have you reviewed a specific revision of it so as to form that
> > opinion?  Again, if we don't have a number of reviews that we can
> > track, the document is just going to sit there and not move forward.
> 
> This is only one revision of
> 
> 
> https://datatracker.ietf.org/doc/html/draft-kaduk-kitten-des-des-des-die-die-die
> 
> I have reviewed it.  Given that it is a document describing deprecation
> of encryption types I don't think it requires perfection.

I see a -00 and a -01 available at that link, though the diff
(https://tools.ietf.org/rfcdiff?url2=draft-kaduk-kitten-des-des-des-die-die-die-01.txt)
is just updating for external events, such as the publication of RFC
7465 deprecating RC4 for TLS, and the end-of-life of Windows Server
2003.

-Ben


From nobody Wed Apr  5 08:45:55 2017
Return-Path: <daedulus@btconnect.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 817E9129420 for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:45:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.922
X-Spam-Level: 
X-Spam-Status: No, score=-1.922 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=btconnect.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MgCLVPXQDnZN for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:45:51 -0700 (PDT)
Received: from EUR01-DB5-obe.outbound.protection.outlook.com (mail-db5eur01on0134.outbound.protection.outlook.com [104.47.2.134]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0CE4312704B for <kitten@ietf.org>; Wed,  5 Apr 2017 08:45:50 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=btconnect.onmicrosoft.com; s=selector1-btconnect-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=DiGc9vajonicpJcTTpH3T3BJpIr/i8THYBzGQ/svgoY=; b=CM7XN2vB+Zr4ovbIp293xr2hKHPmOBsoBXAHynR+WJIazkwo7i+RaDVD1WEBHYx+khpFrMeXGjP3Hi+0ctvn60sA3CtjZU4wYDN89B2KKuZtfinepUweN2Kv1ywcaKEByYJ6KT1+1qg6QpI0zo0kBsWHFJbJAc2cIwcv4ex+ujw=
Authentication-Results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=btconnect.com;
Received: from pc6 (86.169.157.161) by DB5PR07MB1557.eurprd07.prod.outlook.com (2a01:111:e400:5bc7::7) with Microsoft SMTP Server (version=TLS1_2,  cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1019.8; Wed, 5 Apr 2017 15:45:48 +0000
Message-ID: <00f701d2ae23$6d83ac80$4001a8c0@gateway.2wire.net>
From: tom p. <daedulus@btconnect.com>
To: <kitten@ietf.org>
References: <149089878562.15595.17069295528887995710@ietfa.amsl.com>
Date: Wed, 5 Apr 2017 16:43:46 +0100
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
X-Originating-IP: [86.169.157.161]
X-ClientProxiedBy: DB6PR0202CA0039.eurprd02.prod.outlook.com (2603:10a6:4:a5::25) To DB5PR07MB1557.eurprd07.prod.outlook.com (2a01:111:e400:5bc7::7)
X-MS-Office365-Filtering-Correlation-Id: a69feb06-47ef-416e-414e-08d47c3ad4fa
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(201703131423075)(201703031133081); SRVR:DB5PR07MB1557; 
X-Microsoft-Exchange-Diagnostics: 1; DB5PR07MB1557; 3:8sfhhdbCGPwWxuFLgNWXmRSarrPhKGZlSiZKE1hkkTTtk7YAMULviDSQIv+STDJv/ksNUEDVZsjNtSAPEFw6tvGAF+df69XxFgf1GnoRRJT+DwoNiW3KWhZnK4Y3ImhcEb+2UnOnkSGnGO0HchmWUqLoJjTwzByhencrsIV0ts3ErIEib16DA9W6CdOeBPg1+1EXe9Gt6ZSU+N47NXnWo1Zh/Tv8msgAR/S4FEasVg0tBd6iU3g7yjkHWhDkD+AQiwNMdzebNT5bSOrg9FG9N6DClHG0kde/J4D2sQsGI6AQtkl0xnnPzctUanHzHKMUTqbZ0i5f699qQZmtWM+U1A==; 25:BkooHc1YjdqPjiTxkEBPCLnUvRrGy9cF4IQPx5FIp1A4+Ru4o49BCyGmM74QBtstPeO9W2HKWMNolSYNEsp44GTy0t3Hh91a7aFPzrUG3QGk0UIcabupELwCqiYBYbUhakT0DyKn9CbEIju2aMQBbzrHwadxX1R3O11/6iicDP1JgofmflzYlF0dwqoDk18RIy+deJmpgdqQPorQhwda70hvPgJYIYHdfHgK0nr2pwfdreVAmTgHXZj2uk5+N2Uwnqyg3khVPWYuh/CcUyUBtgJZPcwylgj05gq6l3phTrqdIFnZN+AAuso/V4tW0KJUMBerbGH1cBmEFma+es0s7d+mLqO2KIo2a4hGp+u5BLf4qdMo9ULpvwobpBw0CSj1dqhDTv2aklaUx64imGnmfMvzGRtgMTByQlHfTJdXxaFM1qxQLE7kW9alCUfp8ckhQ8Bd1eKKbA+0ocT20E8AOw==
X-Microsoft-Exchange-Diagnostics: 1; DB5PR07MB1557; 31:tyo8F7LU/JX/KmIwR+nRSNZei8EpPXT7IzaMSdWgLxxK41X3bmt2U+aAb7QieQRUTQlqx08EFBvqBTTrUNvhtAiKZaznWTTRCUu3f3d0WuORKq4l+vy1BzBnXh/Gv4f92w2t4DCfDF7AE/Chg0rz7G7cnzR1G6pYTDS1azeykRRHgwb+B0tPOOW37+aFdG4LPmKTCDcACXDNwXKSFTQ7eiYQLZgjKohi02tvO+LpVC6wUCTQuQjam6tX66rmEBjEsaAyHMPP2GlzRpX5VwDTCQ==
X-Microsoft-Antispam-PRVS: <DB5PR07MB155793F1E430DA1A24FEFE90C60A0@DB5PR07MB1557.eurprd07.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(120809045254105);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040450)(601004)(2401047)(8121501046)(5005006)(3002001)(10201501046)(93006095)(93001095)(6041248)(20161123555025)(20161123564025)(20161123562025)(201703131423075)(201702281528075)(201703061421075)(20161123560025)(6072148); SRVR:DB5PR07MB1557; BCL:0; PCL:0; RULEID:; SRVR:DB5PR07MB1557; 
X-Microsoft-Exchange-Diagnostics: 1; DB5PR07MB1557; 4:F8nap9YS3tIhXFXC5K2DJL2oOFjtmHp7Cbg2Ik/3nw3nb2j/NxaAWnq7qG+eSsHZGMvEgE9Fz3vq/ngzIcBD0U21oDeGSOzNFaMpMtvlC9XGrblhy/69/GgZoTfNjfhloWCO+cIOhgQQxDfkS+ErIuKBPj2xrBuuwtdBiD8G3M26hivmw47uB7XPwddP/WTzCvtpS7skvkzfMN3QogUw7nz2/Jpi2bqYwq9isW5672I3DcNsUvVh9u9khalmreOqC17n9QoamNcIiD5j6mhjrWWHcDGZYmwgoqNOd/hA01+CNv6yBTjK72d6R9j/vPFt4QvptLt8XVzxHRdhmDaCdJxtKoDfoeMGfvvP3KQe2phkVRo3yjnVKsDL5h/97iQTBNSjjt+4bWpvA9Qby4dQ885KLDRTYSheOQSIzFayt5Y7uZSHAlyPSbI8ASfdhX+ypdjKvuTKB1C/G6m943D1rTWm/pGuCWg0hFAh0BTMA3FEkG2V8wo6wYC7PWIqvkDKDVxRhvQ/6Z++HvsdrGZ6mJE2MtSX8Jl2s5iK26wBi5rVK8s5hu2buIA+McMJABVHT1knj5LyShqOdqSRVreIi7lWgc6Hkz8S4HCRsX7nQJujlPudPEl5o3KjgtKmEWVdTHj1IXm3ruLkILitp6k4NhrOlZpsSFeLWekghI3U3XFbFgR21opB1SrnHDVLrk1ilPIIAlJdDjMSg105kkajPf5d3KqPbkSg7GOpbVO1YAh4pzEME3TWx64j+xIcRmlOhRXuvGHTP5M0vCjEBZrYrg==
X-Forefront-PRVS: 0268246AE7
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(4630300001)(6009001)(39400400002)(39850400002)(39840400002)(39410400002)(39860400002)(39450400003)(377454003)(13464003)(377424004)(116806002)(33646002)(2351001)(3846002)(6116002)(230783001)(5660300001)(6916009)(1456003)(76176999)(81816999)(50986999)(66066001)(47776003)(44716002)(50466002)(230700001)(25786009)(86362001)(4720700003)(966004)(1556002)(42186005)(53546009)(50226002)(6306002)(62236002)(81686999)(9686003)(2906002)(23756003)(6486002)(110136004)(53936002)(84392002)(38730400002)(14496001)(6496005)(61296003)(7736002)(8676002)(189998001)(81166006)(44736005)(305945005)(74416001)(7726001); DIR:OUT; SFP:1102; SCL:1; SRVR:DB5PR07MB1557; H:pc6; FPR:; SPF:None; MLV:nov;  PTR:InfoNoRecords; LANG:en; 
X-Microsoft-Exchange-Diagnostics: =?iso-8859-1?Q?1; DB5PR07MB1557; 23:Sy4Os3ZF0/llDbftPFVNnl6g0cvcpfYsmiDdwhn?= =?iso-8859-1?Q?aNq/U6YUjHtXjflDDaJTLOFvWJ7+C+jIEjiyiId4/7xMu9DI14ZtcZ3zl+?= =?iso-8859-1?Q?pDlsaRCF2fcnP+ePg5HqX/+XuuvOqYzOts9lBaw+mu+3I6OUCR1Dgt6wPc?= =?iso-8859-1?Q?i5VgsPUPkeQesaPGxZPdmVmCzZ27TyuEJVPZkafvtMKRIiyXsxKXKEIFnK?= =?iso-8859-1?Q?mnjIljEdyjqdlEpnGQILCEwPZYeCHUmCreQsEiswPQxn6HAVwiRdveytZZ?= =?iso-8859-1?Q?RldioMI1JMs9Lx1rWWtzY+DdQ5rVEFdCH7ISmjBqSroY/KmM68+GlZwPrP?= =?iso-8859-1?Q?2pl7KgHCyJQGjuIxuh7HtgHGsg9z3MV9pXQsQJXKax7VRO3nz8RQGh2iFs?= =?iso-8859-1?Q?gHa71lz29AVAEo1FWtKUjTTNKQfxtCd/2xN/I3tC1XtSgkuO00xqgwQO3d?= =?iso-8859-1?Q?/323Gts1BufK4Q1Q2jFNFOLshmiIaSq4efK7Q9t/CDGzZDjI8P/8Zd62OH?= =?iso-8859-1?Q?E0vYW0doxdXSb+YpmoX+fL0n4lCN22zRY3znptf6s+1u2Aa/y8vswtzhGY?= =?iso-8859-1?Q?jDCyujkOEMW7F8I3NMyQuNuTiJ5Zml2bzjSvUW+mKJqP31ZTFvY8RowMX7?= =?iso-8859-1?Q?7tTeSrrr8K9Xdm+Z96ubOswZ1T4ibtRS7ukrxz4wpa3JMTIV1krvxGtZ+e?= =?iso-8859-1?Q?xIH8buB+a6VafRZ49YNdaFxk+O0Ip3fMtARVLouGg1iWRSg22buw7jOBZW?= =?iso-8859-1?Q?CAB5Q5zXQnc7DQ9W7WGuwBbglWZ5POm7zzSgHWJsa6CMQeQp2PtjOdEHCb?= =?iso-8859-1?Q?H71JWjFsdSn6MgJscXIGUJpcgTPjMYWKLQmzN2zgvxdJ3UM97rj2wOJHxV?= =?iso-8859-1?Q?W8CgUKoa+lpDWGPBbOaqV0pa3aH6iZ7j6Im9kZKf5dOBp2Niw7TmSeHs3/?= =?iso-8859-1?Q?ALFFRahFJdhgqgjoATKLAtQg74hndeIFftnZ0f/5VY2Di/eY2doeweLVxb?= =?iso-8859-1?Q?r1sbg4RKAG3CPmnT0y3yAooJYp1ugcFJBSc/4oXJGLb44mc4c22Bo1GRMP?= =?iso-8859-1?Q?JMzbZzs5DT84pi/NHV8CCDRRIbrKQKL6s7H6/BrkEM24gfCEYMAxgjDgl6?= =?iso-8859-1?Q?JvXkzJnOTcSTS1+/rNMw8FerVySwuzLpIBU6wPvgFXkzkrtocvdfGi12Ck?= =?iso-8859-1?Q?SgV0GjJWRYZvywAR4yuIGYHJ3CoisNbeCjtotl1jCk9ovKteLTbf0c09yK?= =?iso-8859-1?Q?9QGGojWi9cV2GtfIBvtgmfhaQpuShcwcxQ6gRak5v3gdRuLQHJWaJujfzi?= =?iso-8859-1?Q?aio1QYJPrOznfXWLEpYinvQQyA4fLGwJQngOT7Ci/ls1zP8q+seGDLanBM?= =?iso-8859-1?Q?rXQtRkN6+P/ltlCY0Wl7pZ97gEtiRWaXOd2+HvZyeL+ss6e2SeuYZcxxg1?= =?iso-8859-1?Q?k4I4jOpfCPcPcCQTlN1s3upBnzFfcNZ5xRQ?=
X-Microsoft-Exchange-Diagnostics: 1; DB5PR07MB1557; 6:93bBnRTCoYgjfmK+ItfdeHlld7dVM9JwHEbtvT7ufgFv9ffsUvGZ4uHb72Ql3y9cqZe0Ysb1FOZe1hbLFkE2J678UABiNvAxOAlzNq82Leh+RT3gP8Rgkd3udQFTncKv4IFPgksb6AcIZNBA9sjsq3g1LlUNbPsRKXziVBSL4EuW3mQeFUmukAiRdayM07LmjuSNx9YMIwRL4xb8cNi0B5r7QM0V+/nGrlyqalFU0sGuxjSMhnbyWFfXnsk7hHo6EwhEnraXYKy/60AVrh9BMX/Qc71p5vL2e2pKm30ft/pRFy3jvTEYAMq60zzEyYer68TfL16AXy+LP19okR3am0+pgN9SjfIlJatk8I5cxqrybF3pj+tr26bf8sOOtZlN80FePl824Y4FF0P1/zcjUK/27fx1om1bnB0Pg1jXWPyj8O/sQ1cCyf7XKa9JkDdVmDv1AiIEFjngoV6qfmIK7A==; 5:7KuR9KFhA6dNgLSnBnULpB5MtvsPNtkjzsage9G4rkx3asAe7urPBRlw3gRB8VBzKEzZWM0T72Bag6+tL9aac6HYTRoANy+pNm4sD/4g/us2B0H+dhi1C2x6NfPQmmrcS6ZXa4lyoGN/YdKSnV9MVA==; 24:wgZ6YK3ATOFjzx32TchznS8QebgHcgu6+FPiCV2pNIkzVBJ9AOaOem7cgOUQjORnQA9NqFTx3tNveJ2q8XmH38w7ZAgND2fXZF5B4Ay/yE0=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; DB5PR07MB1557; 7:KkdglusGiUtCGhpM4ECW8VBT+0toxm2tETvRlO1nwFF9A+KZVTWjJwdnCCeUe55LfQgIiN2PExEBlA2pfxSyb0VFMIx2wphe3pTtxZT658avnKorXLxmrBp5aSep9fD2Cq+mULbtnwjuiWoSF5pFc/Y6aXEeKTYHmd1NElzJau4z1CB5YrlYZO7i1QKqyVia90sNsM+Iv2+UFazLiIDqHrwR4H5C0ugRxjZ84fKYxxZ9w5UX4ugLxyJjPqxp6O7/KG37Wy18zesSBH/SBeGBvDHkOFJZDaR6mUcNOiAICz4Bo/h9S3/BfCPPoS0ETYWNA7105j5h55pL51CX43qWmA==
X-OriginatorOrg: btconnect.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 05 Apr 2017 15:45:48.7268 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB5PR07MB1557
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/Ek7wtsT4wUk2bFeH83v2Zu3-aj8>
Subject: [kitten] draft-kaduk-kitten-des-des-des-die-die-die-01.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 15:45:54 -0000

>From the title, I was expecting an equivalent to RFC7465 but that is not
what this is; I think it should be.  Which WG is best placed to do this,
I am easy about.

Tom Petch


----- Original Message -----
From: <internet-drafts@ietf.org>
To: <i-d-announce@ietf.org>
Sent: Thursday, March 30, 2017 7:33 PM
Subject: I-D Action: draft-kaduk-kitten-des-des-des-die-die-die-01.txt


>
> A New Internet-Draft is available from the on-line Internet-Drafts
directories.
>
>
>         Title           : Deprecate 3DES and RC4 in Kerberos
>         Authors         : Benjamin Kaduk
>                           Michiko Short
> Filename        : draft-kaduk-kitten-des-des-des-die-die-die-01.txt
> Pages           : 9
> Date            : 2017-03-30
>
> Abstract:
>    The 3DES and RC4 encryption types are steadily weakening in
>    cryptographic strength, and the deprecation process should be begun
>    for their use in Kerberos.
>
>
> The IETF datatracker status page for this draft is:
>
https://datatracker.ietf.org/doc/draft-kaduk-kitten-des-des-des-die-die-
die/
>
> There are also htmlized versions available at:
>
https://tools.ietf.org/html/draft-kaduk-kitten-des-des-des-die-die-die-0
1
>
https://datatracker.ietf.org/doc/html/draft-kaduk-kitten-des-des-des-die
-die-die-01
>
> A diff from the previous version is available at:
>
https://www.ietf.org/rfcdiff?url2=draft-kaduk-kitten-des-des-des-die-die
-die-01
>
>
> Please note that it may take a couple of minutes from the time of
submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
> _______________________________________________
> I-D-Announce mailing list
> I-D-Announce@ietf.org
> https://www.ietf.org/mailman/listinfo/i-d-announce
> Internet-Draft directories: http://www.ietf.org/shadow.html
> or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


From nobody Wed Apr  5 08:49:45 2017
Return-Path: <prvs=1268e6793a=jaltman@secure-endpoints.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A7A9F12704B for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:49:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=secure-endpoints.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id i7Q8x-NiKNiZ for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:49:41 -0700 (PDT)
Received: from sequoia-grove.secure-endpoints.com (sequoia-grove.ad.secure-endpoints.com [208.125.0.235]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6F89E124234 for <kitten@ietf.org>; Wed,  5 Apr 2017 08:49:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/relaxed; d=secure-endpoints.com; s=MDaemon; t=1491406738; x=1492011538; i=jaltman@secure-endpoints.com; q=dns/txt; h=VBR-Info:Subject:To: References:Cc:From:Openpgp:Organization:Message-ID:Date: User-Agent:MIME-Version:In-Reply-To:Content-Type; bh=GFjwcRLSv3v VQbTGCBD1yhq1Be933K8SytG3daTX0Tk=; b=BvnyafrL5RnZeXWBYUrD5AFq0M4 ARrSqiWXVLfydp+WagTOxMiDY74vZU/F482kVCa/dnTRWpcO9tJ15qSTny4CSxfp jpoOPAjGN/xhd710i08jbgCrf012YgVJ50I26Lp6IIYh4FU/CRsjjiEYuZhBDNrU 2Ar4iRrL2XakWHc8=
X-MDAV-Result: clean
X-MDAV-Processed: sequoia-grove.secure-endpoints.com, Wed, 05 Apr 2017 11:38:58 -0400
X-Spam-Processed: sequoia-grove.secure-endpoints.com, Wed, 05 Apr 2017 11:38:57 -0400
Received: from [IPv6:2001:470:1f07:f77:d804:1659:6eb:7670] by secure-endpoints.com (IPv6:2001:470:1f07:f77:28d9:68fb:855d:c2a5) (MDaemon PRO v17.0.0)  with ESMTPSA id md50001309320.msg; Wed, 05 Apr 2017 11:38:57 -0400
VBR-Info: md=secure-endpoints.com; mc=all; mv=vbr.emailcertification.org;
X-MDRemoteIP: 2001:470:1f07:f77:d804:1659:6eb:7670
X-MDHelo: [IPv6:2001:470:1f07:f77:d804:1659:6eb:7670]
X-MDArrival-Date: Wed, 05 Apr 2017 11:38:57 -0400
X-Authenticated-Sender: jaltman@secure-endpoints.com
X-Return-Path: prvs=1268e6793a=jaltman@secure-endpoints.com
X-Envelope-From: jaltman@secure-endpoints.com
X-MDaemon-Deliver-To: kitten@ietf.org
X-CAV-Result: clean
To: Benjamin Kaduk <kaduk@mit.edu>
References: <20170405045550.GJ30306@kduck.kaduk.org> <fa13dc36-a2b7-190e-a64d-109161123fac@secure-endpoints.com> <20170405151336.GK30306@kduck.kaduk.org> <c69af66b-b105-b8ce-27da-14cfd176ff14@secure-endpoints.com> <20170405153457.GM30306@kduck.kaduk.org>
Cc: kitten@ietf.org
From: Jeffrey Altman <jaltman@secure-endpoints.com>
Openpgp: id=FA444AF197F449B24CF3E699F77A735592B69A04; url=https://pgp.mit.edu
Organization: Secure Endpoints Inc.
Message-ID: <06c6e429-b4e8-23c1-a43b-ff40112cb4b5@secure-endpoints.com>
Date: Wed, 5 Apr 2017 11:38:49 -0400
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.8.0
MIME-Version: 1.0
In-Reply-To: <20170405153457.GM30306@kduck.kaduk.org>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha-256; boundary="------------ms090800040106020909010809"
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/s99YZKnFwrtawqr557pea6xEcO0>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 15:49:43 -0000

This is a cryptographically signed message in MIME format.

--------------ms090800040106020909010809
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

On 4/5/2017 11:34 AM, Benjamin Kaduk wrote:
> I see a -00 and a -01 available at that link, though the diff
> (https://tools.ietf.org/rfcdiff?url2=3Ddraft-kaduk-kitten-des-des-des-d=
ie-die-die-01.txt)
> is just updating for external events, such as the publication of RFC
> 7465 deprecating RC4 for TLS, and the end-of-life of Windows Server
> 2003.
>=20
> -Ben

To be explicit, I reviewed -01.

Jeff



--------------ms090800040106020909010809
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCC
DJswggYCMIIE6qADAgECAhBAAVgjEN7WFoCIXylZ1uvSMA0GCSqGSIb3DQEBCwUAMDoxCzAJ
BgNVBAYTAlVTMRIwEAYDVQQKEwlJZGVuVHJ1c3QxFzAVBgNVBAMTDlRydXN0SUQgQ0EgQTEy
MB4XDTE2MTEwMjAzMjQxOFoXDTE3MTEwMjAzMjQxOFowgZYxNTAzBgNVBAsMLFZlcmlmaWVk
IEVtYWlsOiBqYWx0bWFuQHNlY3VyZS1lbmRwb2ludHMuY29tMSswKQYJKoZIhvcNAQkBFhxq
YWx0bWFuQHNlY3VyZS1lbmRwb2ludHMuY29tMTAwLgYKCZImiZPyLGQBARMgN0YwMDAwMDEw
MDAwMDE1ODIzMTBERUE3MDAwMDA3QjQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDPaPDUdwWkzLcNsJjjlDs5lo4ySDKmCgzQsuDt+VY3wP0IZBbu8f/LM3zWCH7zVRJ/XuY5
qN44jFEXwj5fGY71Esm5pKv5sUpys6Q3c6BKXiHv/IUusI3qTJ46QBEAiHu2lxB75UnIYgm+
ZbKmcAR48Z1Sl/Ku86e9GPuts9R51SeHW1pjq89LAi6C0ERuAUIK0rVZGDmKWtRNs9EykXzk
mU2Z1ZLuPL0jIggFPeT8TyH6TH/XvapbC+7rHJrzuBY4NDqLgqDJUf0JidL9JeK9+IxxPCab
EbVmOf5sBgO5mg92l4+f+Q4xefZcI4C7RPFdRTRWsQs7Z3DpE28BDbjDAgMBAAGjggKlMIIC
oTAOBgNVHQ8BAf8EBAMCBaAwgYQGCCsGAQUFBwEBBHgwdjAwBggrBgEFBQcwAYYkaHR0cDov
L2NvbW1lcmNpYWwub2NzcC5pZGVudHJ1c3QuY29tMEIGCCsGAQUFBzAChjZodHRwOi8vdmFs
aWRhdGlvbi5pZGVudHJ1c3QuY29tL2NlcnRzL3RydXN0aWRjYWExMi5wN2MwHwYDVR0jBBgw
FoAUpHPa72k1inXMoBl7CDL4a4nkQuwwCQYDVR0TBAIwADCCASwGA1UdIASCASMwggEfMIIB
GwYLYIZIAYb5LwAGCwEwggEKMEoGCCsGAQUFBwIBFj5odHRwczovL3NlY3VyZS5pZGVudHJ1
c3QuY29tL2NlcnRpZmljYXRlcy9wb2xpY3kvdHMvaW5kZXguaHRtbDCBuwYIKwYBBQUHAgIw
ga4agatUaGlzIFRydXN0SUQgQ2VydGlmaWNhdGUgaGFzIGJlZW4gaXNzdWVkIGluIGFjY29y
ZGFuY2Ugd2l0aCAKSWRlblRydXN0J3MgVHJ1c3RJRCBDZXJ0aWZpY2F0ZSBQb2xpY3kgZm91
bmQgYXQgaHR0cHM6Ly9zZWN1cmUuaWRlbnRydXN0LmNvbS9jZXJ0aWZpY2F0ZXMvcG9saWN5
L3RzL2luZGV4Lmh0bWwwRQYDVR0fBD4wPDA6oDigNoY0aHR0cDovL3ZhbGlkYXRpb24uaWRl
bnRydXN0LmNvbS9jcmwvdHJ1c3RpZGNhYTEyLmNybDAnBgNVHREEIDAegRxqYWx0bWFuQHNl
Y3VyZS1lbmRwb2ludHMuY29tMB0GA1UdDgQWBBSP11Voh/Sg9hmecftn2BV5ZQd9OTAdBgNV
HSUEFjAUBggrBgEFBQcDAgYIKwYBBQUHAwQwDQYJKoZIhvcNAQELBQADggEBAC9cnqRj+ViE
efFsiYNMUC8tZf6PXcWDecOR5Pdv/Vd/O6y10mYyilPrcd0sJux1idTZIOzHAsh36BfBdNSt
BFAuBZD66L649U3XqBnh9nbuzmCwNc3tWjOaY/Xe7R90lqrXaW0Dw0U++zwmNyCO2CRgBdrU
8cTqFpOtpe/gCAMhjajrUfb+m8Vcd5R0RVIvdljblqv2t9IXQIHwWSm8E7v302z7yW4o4iPH
kegez5vq37ICikQjkkVyAJr0wtirJyQuFzMgpoWVpm0CKBiMwJPki2kiHlNiMHBr2ch4fC+H
SjbMg4OzTZJCz1xhKvpyRDOM8JRb2BNSU8JjmrxZgFIwggaRMIIEeaADAgECAhEA+d5Wf8lN
DHdw+WAbUtoVOzANBgkqhkiG9w0BAQsFADBKMQswCQYDVQQGEwJVUzESMBAGA1UEChMJSWRl
blRydXN0MScwJQYDVQQDEx5JZGVuVHJ1c3QgQ29tbWVyY2lhbCBSb290IENBIDEwHhcNMTUw
MjE4MjIyNTE5WhcNMjMwMjE4MjIyNTE5WjA6MQswCQYDVQQGEwJVUzESMBAGA1UEChMJSWRl
blRydXN0MRcwFQYDVQQDEw5UcnVzdElEIENBIEExMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBANGRTTzPCic0kq5L6ZrUJWt5LE/n6tbPXPhGt2Egv7plJMoEpvVJJDqGqDYy
maAsd8Hn9ZMAuKUEFdlx5PgCkfu7jL5zgiMNnAFVD9PyrsuF+poqmlxhlQ06sFY2hbhQkVVQ
00KCNgUzKcBUIvjv04w+fhNPkwGW5M7Ae5K5OGFGwOoRck9GG6MUVKvTNkBw2/vNMOd29VGV
TtR0tjH5PS5yDXss48Yl1P4hDStO2L4wTsW2P37QGD27//XGN8K6amWB6F2XOgff/PmlQjQO
ORT95PmLkwwvma5nj0AS0CVp8kv0K2RHV7GonllKpFDMT0CkxMQKwoj+tWEWJTiDKSsCAwEA
AaOCAoAwggJ8MIGJBggrBgEFBQcBAQR9MHswMAYIKwYBBQUHMAGGJGh0dHA6Ly9jb21tZXJj
aWFsLm9jc3AuaWRlbnRydXN0LmNvbTBHBggrBgEFBQcwAoY7aHR0cDovL3ZhbGlkYXRpb24u
aWRlbnRydXN0LmNvbS9yb290cy9jb21tZXJjaWFscm9vdGNhMS5wN2MwHwYDVR0jBBgwFoAU
7UQZwNPwBovupHu+QucmVMiONnYwDwYDVR0TAQH/BAUwAwEB/zCCASAGA1UdIASCARcwggET
MIIBDwYEVR0gADCCAQUwggEBBggrBgEFBQcCAjCB9DBFFj5odHRwczovL3NlY3VyZS5pZGVu
dHJ1c3QuY29tL2NlcnRpZmljYXRlcy9wb2xpY3kvdHMvaW5kZXguaHRtbDADAgEBGoGqVGhp
cyBUcnVzdElEIENlcnRpZmljYXRlIGhhcyBiZWVuIGlzc3VlZCBpbiBhY2NvcmRhbmNlIHdp
dGggSWRlblRydXN0J3MgVHJ1c3RJRCBDZXJ0aWZpY2F0ZSBQb2xpY3kgZm91bmQgYXQgaHR0
cHM6Ly9zZWN1cmUuaWRlbnRydXN0LmNvbS9jZXJ0aWZpY2F0ZXMvcG9saWN5L3RzL2luZGV4
Lmh0bWwwSgYDVR0fBEMwQTA/oD2gO4Y5aHR0cDovL3ZhbGlkYXRpb24uaWRlbnRydXN0LmNv
bS9jcmwvY29tbWVyY2lhbHJvb3RjYTEuY3JsMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEF
BQcDBDAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0OBBYEFKRz2u9pNYp1zKAZewgy+GuJ5ELsMA0G
CSqGSIb3DQEBCwUAA4ICAQAN4YKu0vv062MZfg+xMSNUXYKvHwvZIk+6H1pUmivyDI4I6A3w
Wzxlr83ZJm0oGIF6PBsbgKJ/fhyyIzb+vAYFJmyI8I/0mGlc+nIQNuV2XY8cypPoVJKgpnzp
/7cECXkX8R4NyPtEn8KecbNdGBdEaG4a7AkZ3ujlJofZqYdHxN29tZPdDlZ8fR36/mAFeCEq
0wOtOOc0Eyhs29+9MIZYjyxaPoTS+l8xLcuYX3RWlirRyH6RPfeAi5kySOEhG1quNHe06QIw
pigjyFT6v/vRqoIBr7WpDOSt1VzXPVbSj1PcWBgkwyGKHlQUOuSbHbHcjOD8w8wHSDbL+L2h
e8hNN54doy1e1wJHKmnfb0uBAeISoxRbJnMMWvgAlH5FVrQWlgajeH/6NbYbBSRxALuEOqEQ
epmJM6qz4oD2sxdq4GMN5adAdYEswkY/o0bRKyFXTD3mdqeRXce0jYQbWm7oapqSZBccFvUg
YOrB78tB6c1bxIgaQKRShtWR1zMM0JfqUfD9u8Fg7G5SVO0IG/GcxkSvZeRjhYcbTfqF2eAg
prpyzLWmdr0mou3bv1Sq4OuBhmTQCnqxAXr4yVTRYHkp5lCvRgeJAme1OTVpVPth/O7HJ7Vu
EP9GOr6kCXCXmjB4P3UJ2oU0NqfoQdcSSSt9hliALnExTEjii20B2nSDojGCAxQwggMQAgEB
ME4wOjELMAkGA1UEBhMCVVMxEjAQBgNVBAoTCUlkZW5UcnVzdDEXMBUGA1UEAxMOVHJ1c3RJ
RCBDQSBBMTICEEABWCMQ3tYWgIhfKVnW69IwDQYJYIZIAWUDBAIBBQCgggGXMBgGCSqGSIb3
DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTE3MDQwNTE1Mzg0OVowLwYJKoZI
hvcNAQkEMSIEIJ6idu3Cj9Je6PlYXBu7vyDIKHUgzWwRsslciaZ7Sxb5MF0GCSsGAQQBgjcQ
BDFQME4wOjELMAkGA1UEBhMCVVMxEjAQBgNVBAoTCUlkZW5UcnVzdDEXMBUGA1UEAxMOVHJ1
c3RJRCBDQSBBMTICEEABWCMQ3tYWgIhfKVnW69IwXwYLKoZIhvcNAQkQAgsxUKBOMDoxCzAJ
BgNVBAYTAlVTMRIwEAYDVQQKEwlJZGVuVHJ1c3QxFzAVBgNVBAMTDlRydXN0SUQgQ0EgQTEy
AhBAAVgjEN7WFoCIXylZ1uvSMGwGCSqGSIb3DQEJDzFfMF0wCwYJYIZIAWUDBAEqMAsGCWCG
SAFlAwQBAjAKBggqhkiG9w0DBzAOBggqhkiG9w0DAgICAIAwDQYIKoZIhvcNAwICAUAwBwYF
Kw4DAgcwDQYIKoZIhvcNAwICASgwDQYJKoZIhvcNAQEBBQAEggEAiFMyufAjoWl+5suds46G
FFfBJetAGlZXuQBfdapwxHS0t8sZRdaLfgrvflN2i4bF45FPGi8fRuIO8rKaHJWVTbhse8zW
KrEUSgiuuU3ysw4hME25zsCKwisuB2wPbRQLUf07de4N+ImeXOBYyMyBXXGxqwCU+sJSJi14
114E9IhBKCnx5/8tIiH/TU4K6VlwXXkrFte0QtUed/AAbNJOZYzjRGxC6awGgEG+OZeJyHQC
ka4+iIYnFNTMmA+N73JSdw1TSRJIRg7Z6z2L311mtAEBDk15yXcT7KxIVktpGxHrKzk8G+Sg
n9ZBPWMRiBbQuJ6bhiCoVA9iFGhhIWOlygAAAAAAAA==
--------------ms090800040106020909010809--


From nobody Wed Apr  5 08:53:28 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7CEFC12704B for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:53:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.202
X-Spam-Level: 
X-Spam-Status: No, score=-4.202 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TIRYvHoGrPKH for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 08:53:26 -0700 (PDT)
Received: from dmz-mailsec-scanner-8.mit.edu (dmz-mailsec-scanner-8.mit.edu [18.7.68.37]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3A971126CD8 for <kitten@ietf.org>; Wed,  5 Apr 2017 08:53:23 -0700 (PDT)
X-AuditID: 12074425-313ff70000005faf-17-58e512f10177
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id 7E.C4.24495.1F215E85; Wed,  5 Apr 2017 11:53:22 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id v35FrKmS015494; Wed, 5 Apr 2017 11:53:21 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v35FrGc7022006 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 5 Apr 2017 11:53:19 -0400
Date: Wed, 5 Apr 2017 10:53:16 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: "tom p." <daedulus@btconnect.com>
Cc: kitten@ietf.org
Message-ID: <20170405155316.GN30306@kduck.kaduk.org>
References: <149089878562.15595.17069295528887995710@ietfa.amsl.com> <00f701d2ae23$6d83ac80$4001a8c0@gateway.2wire.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <00f701d2ae23$6d83ac80$4001a8c0@gateway.2wire.net>
User-Agent: Mutt/1.6.1 (2016-04-27)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrCIsWRmVeSWpSXmKPExsUixCmqrftJ6GmEQetiPotVB+wsjm5exeLA 5LHr6A92jyVLfjIFMEVx2aSk5mSWpRbp2yVwZZzZsZGtoJ2lYlJ7ZAPjROYuRk4OCQETiZtb bzJ1MXJxCAm0MUn8mzmbDcLZwCixp+8FC0iVkMAVJok/GxxAbBYBFYmOH3/ZQGw2ILuh+zLY JBEBVYkH61YxgdjMAsISy9ecBasRFnCX+LN1HZjNC7TtwIe/TBAzKyWed01lgYgLSpyc+YQF oldL4sa/l0A1HEC2tMTyfxwgYU4Be4nTr04wgtiiAsoSDTMeME9gFJiFpHsWku5ZCN0LGJlX Mcqm5Fbp5iZm5hSnJusWJyfm5aUW6Vro5WaW6KWmlG5iBAUou4vqDsY5f70OMQpwMCrx8Ho8 fhIhxJpYVlyZe4hRkoNJSZRXwQcoxJeUn1KZkVicEV9UmpNafIhRgoNZSYR3If/TCCHelMTK qtSifJiUNAeLkjivuEZjhJBAemJJanZqakFqEUxWhoNDSYJXSxCoUbAoNT21Ii0zpwQhzcTB CTKcB2h4LEgNb3FBYm5xZjpE/hSjLseN4wfeMAmx5OXnpUqJ87qDFAmAFGWU5sHNASUWiez9 Na8YxYHeEuYtB6niASYluEmvgJYwAS15cuchyJKSRISUVAOjlnFI+/VNy/8v+pbJ6FWz5fXh oA8rj8aHSri+Myv8sar1Mc8Uy08CZ6o/5W01SFTRmsc2w8nwpubvB1OfPFRs/+B2ea3u+eI9 ufluriUHI3e2dDx9n/+ESWaeuK/RjC82sU8fXD+08INH7JmeFws9m34/kOHj+6ZjoTXNg6Uq f3qX3nMhntnHlViKMxINtZiLihMBGh2glQcDAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/-HCDJ-rrp8LyqnpyfNMJK2KWGBA>
Subject: Re: [kitten] draft-kaduk-kitten-des-des-des-die-die-die-01.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 15:53:27 -0000

On Wed, Apr 05, 2017 at 04:43:46PM +0100, tom p. wrote:
> From the title, I was expecting an equivalent to RFC7465 but that is not
> what this is; I think it should be.  Which WG is best placed to do this,
> I am easy about.

I'm not sure I understand the question.  You are interested in
prohibiting triple-DES cipher suites from use in TLS?  That would
best be done in the TLS WG.

This draft was given its name as a homage to RFC 6649, which AFAIK
was the first document to use that construction.

-Ben


From nobody Wed Apr  5 09:52:28 2017
Return-Path: <ghudson@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 794241294AB for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 09:52:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.221
X-Spam-Level: 
X-Spam-Status: No, score=-4.221 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ehPb4S-75far for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 09:52:26 -0700 (PDT)
Received: from dmz-mailsec-scanner-2.mit.edu (dmz-mailsec-scanner-2.mit.edu [18.9.25.13]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5EFC4129498 for <kitten@ietf.org>; Wed,  5 Apr 2017 09:52:25 -0700 (PDT)
X-AuditID: 1209190d-c5bff70000004073-d2-58e520c71733
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id A2.E6.16499.7C025E85; Wed,  5 Apr 2017 12:52:23 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id v35GqMFx001257 for <kitten@ietf.org>; Wed, 5 Apr 2017 12:52:23 -0400
Received: from [18.101.8.92] (vpn-18-101-8-92.mit.edu [18.101.8.92]) (authenticated bits=0) (User authenticated as ghudson@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v35GqKto012087 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT) for <kitten@ietf.org>; Wed, 5 Apr 2017 12:52:22 -0400
To: kitten@ietf.org
References: <20170405045550.GJ30306@kduck.kaduk.org> <20170405152919.GL30306@kduck.kaduk.org>
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <8571fc1a-1f7a-30dd-98ce-e7481b25c7bb@mit.edu>
Date: Wed, 5 Apr 2017 12:52:20 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.5.1
MIME-Version: 1.0
In-Reply-To: <20170405152919.GL30306@kduck.kaduk.org>
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrBIsWRmVeSWpSXmKPExsUixG6nrntc4WmEwaX5ahZHN69icWD0WLLk J1MAYxSXTUpqTmZZapG+XQJXRv/dmUwFaxgrZq3ezt7A2M3YxcjJISFgIvFifjd7FyMXh5BA G5PE95bHjBDOMUaJlqkvWCCc60wSJ442s4C0CAtoSjQ/3sQEYosICEvs3vqOGcQWEoiXeDbj FNhYNgFlifX7t4LV8wpYSfRdWs8KYrMIqEgcPfEAqJ6DQ1QgQqLhcDpEiaDEyZlPwMo5BUwl di9aA2YzC+hJ7Lj+ixXClpfY/nYO8wRG/llIWmYhKZuFpGwBI/MqRtmU3Crd3MTMnOLUZN3i 5MS8vNQiXSO93MwSvdSU0k2MoODjlOTdwfjvrtchRgEORiUeXo/HTyKEWBPLiitzDzFKcjAp ifIq+ACF+JLyUyozEosz4otKc1KLDzFKcDArifBOknkaIcSbklhZlVqUD5OS5mBREucV12iM EBJITyxJzU5NLUgtgsnKcHAoSfDWywM1ChalpqdWpGXmlCCkmTg4QYbzAA1/BVLDW1yQmFuc mQ6RP8VozHFq2s43TBw3jh94wyTEkpeflyolzhsAUioAUppRmgc3DZxAUjliXjGKAz0nzMsH TCdCPMDkAzfvFdAqJqBVT+48BFlVkoiQkmpgVGrM+639W8DkVPJfztyUuvmhal13nezvZHtk H2w9P/PyEqbFMy4aqtdUr2Cu23ql0TrKqPmT6dpTLVu37p+0PE47fPuT9feZWeQfpr1gmJKh Mm3L/J67bIciT1stXLP9rg2/Zr5FfN27TI2gmTf2Xw/oPryvTDjsxC6bFZb3V6dY/T1scFHk hBJLcUaioRZzUXEiADzKvVr7AgAA
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/EF8BjucF6SMT1YlkhyZ4KYDkEV4>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 16:52:27 -0000

On 04/05/2017 11:29 AM, Benjamin Kaduk wrote:
> Taking off my chair hat, I think that
> draft-mccallum-kitten-krb-spake-preauth is the most pressing item.

I agree.


From nobody Wed Apr  5 12:10:46 2017
Return-Path: <nico@cryptonector.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3581E127A90 for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 12:10:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.296
X-Spam-Level: 
X-Spam-Status: No, score=-4.296 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.796, RCVD_IN_SORBS_SPAM=0.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cryptonector.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PIK4V0NlEBHR for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 12:10:42 -0700 (PDT)
Received: from homiemail-a84.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 173C3128E19 for <kitten@ietf.org>; Wed,  5 Apr 2017 12:10:38 -0700 (PDT)
Received: from homiemail-a84.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a84.g.dreamhost.com (Postfix) with ESMTP id 9BFE8C00282C; Wed,  5 Apr 2017 12:10:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=cryptonector.com; h=date :from:to:cc:subject:message-id:references:mime-version :content-type:in-reply-to; s=cryptonector.com; bh=HIlyNsNt8HD1YN um9KyuR+GkDTk=; b=aBfRbbMrW5iwSy9hpK9L2ZoDoWC009G2Bz79d/dxNb2z5l Bi4ANVb4F3rxHcxEoh+olJtgzBUt8fV1bV6/hT9JRF+Kz4/wdOQ9VbVy1Vnb1QkL QuNq8szGmlv63U6x/KOxiW1cqN6SKZOkTrOozG+C8D+sfZvebEaG4MK5SuiGo=
Received: from localhost (gzac12-mdf2-1.aoa.twosigma.com [208.77.215.155]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: nico@cryptonector.com) by homiemail-a84.g.dreamhost.com (Postfix) with ESMTPSA id 30956C00282B; Wed,  5 Apr 2017 12:10:37 -0700 (PDT)
Date: Wed, 5 Apr 2017 14:10:35 -0500
From: Nico Williams <nico@cryptonector.com>
To: Benjamin Kaduk <kaduk@mit.edu>
Cc: kitten@ietf.org
Message-ID: <20170405191034.GF4004@localhost>
References: <20170405045550.GJ30306@kduck.kaduk.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20170405045550.GJ30306@kduck.kaduk.org>
User-Agent: Mutt/1.5.24 (2015-08-30)
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/7kYsVQxWKZ6obkb9gQ_puc2IKFw>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 19:10:44 -0000

On Tue, Apr 04, 2017 at 11:55:50PM -0500, Benjamin Kaduk wrote:
> Now that we've cleared a fair bit of backlog, publishing a few old
> documents and getting ready to kick more up to the IESG, it seems
> apropos to consider what "new" work to adopt (many of which have
> been lingering as individual documents for a while and are not
> exactly new).
> 
> To give some historical perspective on the sense of the working
> group, back in Buenos Aires the chairs had a (very broad!) list of:
> draft-williams-kitten-krb5-pkcross
> draft-williams-kitten-krb5-extra-rt
> draft-williams-kitten-generic-naming-attributes
> draft-williams-kitten-impersonation-naming-attr
> draft-vanrein-kitten-rfbsasl
> draft-vanrein-dnstxt-krb1
> draft-vanrein-krb5-kdh
> draft-vanrein-kitten-krb5-pseudonymity
> draft-mccallum-kitten-krb-spake-preauth
> draft-kaduk-kitten-des-des-des-die-die-die
> draft-howard-gssapi-aead
> draft-mccallum-kitten-krb-service-discovery

There's really a very large amount of work to do in KITTEN WG, but a
very small amount of energy.  The three primary implementors, and
several additional derivative implementors, all have different agendas
and insufficient energy for reviewing each others' work early on.

I think a lot of the above, and others not on that list, could be done
outside the IETF using IANA registries to avoid collisions and provide a
modicum of documentation.  We could then submit I-Ds and publish RFCs
after we gain deployment experience.

> What do people currently feel are the top one or two highest
> priority items for the WG to consider?

For me the highest priority areas would be:

 - AEAD (i.e., performance)

 - krb5-extra-rt (i.e., better user experience)

 - GSS naming attributes (first, because I need them, and secondly
   because I see others adding features that should be added as name
   attributes, but not doing it as name attributes, and that complicates
   my universe because I really want to pass around NAMEs or exported
   composite name tokens rather than security contexts)

 - We actually need to fix the Java bindings of GSS to say that GSSName
   implements Principal (that's a long story)

I am also very interested in various of the ones you listed above:

 - Channel bound flag...

 - SPAKE

 - KDH

 - PKCROSS

 - TLS-1.3-based GSS mechanism

 - Specification of how to use Kerberos tickets as TLS 1.3 session
   resumption tickets

I'm also interested in publishing at least an Informative track RFC
explaining how to key services using ECDH, and clustered services using
multi-party ECDH.  A combination of PKCROS, PKINIT (or SPAKE), and
ECDH-keyed services would yield a protocol that can easily recover from
KDC database compromise, and combined with periodic realm public key
rollover, and a cacheable PKIX-based LoA authz-data, could allow a level
of cryptographic assurance that can compete with PKIX.  But I wouldn't
have the energy for that any time soon.

Nico
-- 


From nobody Wed Apr  5 12:26:56 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C1FA712943C for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 12:26:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.222
X-Spam-Level: 
X-Spam-Status: No, score=-4.222 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jwBFtuglL7ed for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 12:26:53 -0700 (PDT)
Received: from dmz-mailsec-scanner-7.mit.edu (dmz-mailsec-scanner-7.mit.edu [18.7.68.36]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 385E3129493 for <kitten@ietf.org>; Wed,  5 Apr 2017 12:26:53 -0700 (PDT)
X-AuditID: 12074424-087ff70000002b2b-10-58e544fb27d8
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id 6B.DC.11051.BF445E85; Wed,  5 Apr 2017 15:26:52 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id v35JQpow020494; Wed, 5 Apr 2017 15:26:51 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v35JQkmm023987 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 5 Apr 2017 15:26:50 -0400
Date: Wed, 5 Apr 2017 14:26:46 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: Nico Williams <nico@cryptonector.com>
Cc: kitten@ietf.org
Message-ID: <20170405192646.GO30306@kduck.kaduk.org>
References: <20170405045550.GJ30306@kduck.kaduk.org> <20170405191034.GF4004@localhost>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20170405191034.GF4004@localhost>
User-Agent: Mutt/1.6.1 (2016-04-27)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrNIsWRmVeSWpSXmKPExsUixG6novvH5WmEwZS9fBZHN69isTh17Qib A5PHy1PnGD2WLPnJFMAUxWWTkpqTWZZapG+XwJWxrWM7c8E77oqNe9rZGhjncHYxcnJICJhI XOj/x9LFyMUhJNDGJPHgQQMThLOBUWLx78WMEM4VJon3Fy+zgrSwCKhIfFsxkwnEZgOyG7ov M4PYIgKaEtfnLWUDsZkFhCWWrzkLZgsDxZsfbwKr5wVa92bdebB6IYEIibm7d7NAxAUlTs58 wgLRqyVx499LoHoOIFtaYvk/DpAwp4CexN0PR8HGiAooSzTMeMA8gVFgFpLuWUi6ZyF0L2Bk XsUom5JbpZubmJlTnJqsW5ycmJeXWqRrrpebWaKXmlK6iREcpi4qOxi7e7wPMQpwMCrx8Ho8 fhIhxJpYVlyZe4hRkoNJSZRXwQcoxJeUn1KZkVicEV9UmpNafIhRgoNZSYQ31uFphBBvSmJl VWpRPkxKmoNFSZxXXKMxQkggPbEkNTs1tSC1CCYrw8GhJMHL6QzUKFiUmp5akZaZU4KQZuLg BBnOAzRcyAlkeHFBYm5xZjpE/hSjopQ4bxxIQgAkkVGaB9cLSiMS2ftrXjGKA70izHsEZAUP MAXBdb8CGswENPjJnYcgg0sSEVJSDYy7eqxW+Br8yf+mMeWrFWORvF3hTtamqQe/WYhNnhn8 /0BRJhvXjtcl58J2L9k4P+V3Z9qFzqmyHzRCDfZwXT548MgTE53l7xTW7n4yrU90gXz20pM1 h3923M/exbt6GetDR7sjO5NtOs9FZlWUr5Hh1J7KO7HohWWzHpd6hZS7b6x+9a6jrBuVWIoz Eg21mIuKEwHpwlaI/gIAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/ThHERTG2b5PzVCQ_tAMLr8azLKA>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 19:26:55 -0000

On Wed, Apr 05, 2017 at 02:10:35PM -0500, Nico Williams wrote:
> On Tue, Apr 04, 2017 at 11:55:50PM -0500, Benjamin Kaduk wrote:
> 
> There's really a very large amount of work to do in KITTEN WG, but a
> very small amount of energy.  The three primary implementors, and
> several additional derivative implementors, all have different agendas
> and insufficient energy for reviewing each others' work early on.

Yes, there's a lot of work to do.

> I think a lot of the above, and others not on that list, could be done
> outside the IETF using IANA registries to avoid collisions and provide a
> modicum of documentation.  We could then submit I-Ds and publish RFCs
> after we gain deployment experience.
> 
> > What do people currently feel are the top one or two highest
> > priority items for the WG to consider?
> 
> For me the highest priority areas would be:
> 
>  - AEAD (i.e., performance)
> 
>  - krb5-extra-rt (i.e., better user experience)
> 
>  - GSS naming attributes (first, because I need them, and secondly
>    because I see others adding features that should be added as name
>    attributes, but not doing it as name attributes, and that complicates
>    my universe because I really want to pass around NAMEs or exported
>    composite name tokens rather than security contexts)
> 
>  - We actually need to fix the Java bindings of GSS to say that GSSName
>    implements Principal (that's a long story)

but maybe you could narrow it down to a top two?

-Ben


From nobody Wed Apr  5 13:59:19 2017
Return-Path: <nico@cryptonector.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2C0941270A0 for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 13:59:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.296
X-Spam-Level: 
X-Spam-Status: No, score=-4.296 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.796, RCVD_IN_SORBS_SPAM=0.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cryptonector.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UhktsB99jg7W for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 13:59:15 -0700 (PDT)
Received: from homiemail-a106.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 790C9128DF3 for <kitten@ietf.org>; Wed,  5 Apr 2017 13:59:15 -0700 (PDT)
Received: from homiemail-a106.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a106.g.dreamhost.com (Postfix) with ESMTP id 1328230002928; Wed,  5 Apr 2017 13:59:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=cryptonector.com; h=date :from:to:cc:subject:message-id:references:mime-version :content-type:in-reply-to; s=cryptonector.com; bh=E4ThNC0XfLlnvS SZR0Gq9Izqheo=; b=NiRIfevZPPP058qVH2cR9icnKUZ0YekYPQd3kMwsksZNpf OhDCPBUxCTebNYgJIEsawmbNzk6Wy26yCu1OBinvUJePfecRcW5ZTbl3HRsQxDFv NnbFfQ66w5a/HZASfEOVpjLoq+7WZRtW55i0G/veGtaQLndZrIz8jJvQiKD38=
Received: from localhost (gzac12-mdf2-1.aoa.twosigma.com [208.77.215.155]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: nico@cryptonector.com) by homiemail-a106.g.dreamhost.com (Postfix) with ESMTPSA id AA16830002925; Wed,  5 Apr 2017 13:59:14 -0700 (PDT)
Date: Wed, 5 Apr 2017 15:59:12 -0500
From: Nico Williams <nico@cryptonector.com>
To: Benjamin Kaduk <kaduk@mit.edu>
Cc: kitten@ietf.org
Message-ID: <20170405205912.GG4004@localhost>
References: <20170405045550.GJ30306@kduck.kaduk.org> <20170405191034.GF4004@localhost> <20170405192646.GO30306@kduck.kaduk.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20170405192646.GO30306@kduck.kaduk.org>
User-Agent: Mutt/1.5.24 (2015-08-30)
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/Q67UBN3mPndoY0U9ufUSlb__DHc>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Apr 2017 20:59:17 -0000

On Wed, Apr 05, 2017 at 02:26:46PM -0500, Benjamin Kaduk wrote:
> On Wed, Apr 05, 2017 at 02:10:35PM -0500, Nico Williams wrote:
> > For me the highest priority areas would be:
> > 
> >  - AEAD (i.e., performance)
> > 
> >  - krb5-extra-rt (i.e., better user experience)
> > 
> >  - GSS naming attributes (first, because I need them, and secondly
> >    because I see others adding features that should be added as name
> >    attributes, but not doing it as name attributes, and that complicates
> >    my universe because I really want to pass around NAMEs or exported
> >    composite name tokens rather than security contexts)
> > 
> >  - We actually need to fix the Java bindings of GSS to say that GSSName
> >    implements Principal (that's a long story)
> 
> but maybe you could narrow it down to a top two?

I'll take any two of the above that others also want to work on.


From nobody Wed Apr  5 19:24:11 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 80CBE1288B8 for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 19:24:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.202
X-Spam-Level: 
X-Spam-Status: No, score=-4.202 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id W2A9vqy_qrq3 for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 19:24:07 -0700 (PDT)
Received: from dmz-mailsec-scanner-4.mit.edu (dmz-mailsec-scanner-4.mit.edu [18.9.25.15]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8A29D1270FC for <kitten@ietf.org>; Wed,  5 Apr 2017 19:24:06 -0700 (PDT)
X-AuditID: 1209190f-e83ff70000005fe4-8d-58e5a6c4b4c7
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id 9C.5C.24548.4C6A5E85; Wed,  5 Apr 2017 22:24:04 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id v362O33I018511; Wed, 5 Apr 2017 22:24:04 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v362Nw57031019 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 5 Apr 2017 22:24:02 -0400
Date: Wed, 5 Apr 2017 21:23:58 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: Rick van Rein <rick@openfortress.nl>
Cc: kitten@ietf.org
Message-ID: <20170406022358.GV30306@kduck.kaduk.org>
References: <20170405045550.GJ30306@kduck.kaduk.org> <58E4B727.1050103@openfortress.nl>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <58E4B727.1050103@openfortress.nl>
User-Agent: Mutt/1.6.1 (2016-04-27)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrFIsWRmVeSWpSXmKPExsUixG6nontk2dMIgy8XdS2Obl7FYvH01T02 ByaPJUt+Mnls+NfEFsAUxWWTkpqTWZZapG+XwJUx52AjY0EPZ0Xn5uPMDYzt7F2MnBwSAiYS F1avYwOxhQTamCSmNDh1MXIB2RsYJXruPWWHcK4wSSw+t44ZpIpFQEViw7PbYN1sQHZD92Ww uIiAhsTnX1PBJjELCEssX3MWzBYW0JRofryJCcTmBdp2Z/5PFohtkRKvzk1jhIgLSpyc+YQF oldL4sa/l0D1HEC2tMTyfxwgYU4BfYlJzy6BjREVUJZomPGAeQKjwCwk3bOQdM9C6F7AyLyK UTYlt0o3NzEzpzg1Wbc4OTEvL7VI10QvN7NELzWldBMjKEg5Jfl3MM5p8D7EKMDBqMTD6/H4 SYQQa2JZcWXuIUZJDiYlUV4FH6AQX1J+SmVGYnFGfFFpTmrxIUYJDmYlEd702U8jhHhTEiur UovyYVLSHCxK4rziGo0RQgLpiSWp2ampBalFMFkZDg4lCd5nS4AaBYtS01Mr0jJzShDSTByc IMN5gIbPBqnhLS5IzC3OTIfIn2JUlBLndVwKlBAASWSU5sH1gpKIRPb+mleM4kCvCPP+AKni ASYguO5XQIOZgAY/ufMQZHBJIkJKqoGxzMUgKPGr0ryDIulGcRXHtdRnz2d73ztXc7mHBrfO j40nrq/+PEFjj2Vh08ZfeyO5fZ5FX2d7zu2lVHV1f6njN3O/j8cf/raYPomB/4z9yvzeeBOL brf/hksvv785UbvBd8vaTVISPmJbZ1meffUuUsT04sWY1D71kyvs9uaZtzUEaV5f+XuTEktx RqKhFnNRcSIADJ/VU/0CAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/ZPi2i5VsH2Kx-5Xd24gr5O3J768>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Apr 2017 02:24:10 -0000

On Wed, Apr 05, 2017 at 11:21:43AM +0200, Rick van Rein wrote:
> Hi,
> 
> Good news, Ben :)
> 
> Let me at least sort the list of drafts I wrote.
> 
> > What do people currently feel are the top one or two highest
> > priority items for the WG to consider?
> 
> IMHO, draft-vanrein-dnstxt-krb1would be a quick win.  It's with the RFC
> Editor and I'm working on and off to get it adopted into MIT krb5.  Nico
> has reviewed it and the RFC Editor is mainly waiting for a 2nd reviewer.

Hmm, perhaps you mean Independent Submission Editor instead of RFC
Editor?  (I am not terribly familiar with that path to RFC
publication.)  In that case, it's unclear that pulling it into the
WG at this late stage would be productive, though folks here are of
course welcome to review it and help the ISE out.

> Also up shortly in our work is Kerberos Realm Crossover, bet there's no
> I-D yet.
> 
> In the TLS WG, I'm working on TLS-KDH, which may need some discussion in
> Kitten on the allocation of numbers (such as unencrypted algorithm
> numbers, because TLS takes care of the encryption).

Sure, we'll talk about that as it comes up.

-Ben


From nobody Wed Apr  5 19:34:43 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D57C9127286 for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 19:34:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.222
X-Spam-Level: 
X-Spam-Status: No, score=-4.222 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yp0L96qIpGcU for <kitten@ietfa.amsl.com>; Wed,  5 Apr 2017 19:34:40 -0700 (PDT)
Received: from dmz-mailsec-scanner-3.mit.edu (dmz-mailsec-scanner-3.mit.edu [18.9.25.14]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F17C3127097 for <kitten@ietf.org>; Wed,  5 Apr 2017 19:34:39 -0700 (PDT)
X-AuditID: 1209190e-fafff700000014f9-15-58e5a93d41cf
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id A3.4D.05369.E39A5E85; Wed,  5 Apr 2017 22:34:38 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id v362YbrC013012 for <kitten@ietf.org>; Wed, 5 Apr 2017 22:34:37 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v362YXs2001602 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Wed, 5 Apr 2017 22:34:36 -0400
Date: Wed, 5 Apr 2017 21:34:33 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: kitten@ietf.org
Message-ID: <20170406023433.GX30306@kduck.kaduk.org>
References: <20170405045550.GJ30306@kduck.kaduk.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20170405045550.GJ30306@kduck.kaduk.org>
User-Agent: Mutt/1.6.1 (2016-04-27)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrHIsWRmVeSWpSXmKPExsUixCmqrGu38mmEwcdOA4ujm1exODB6LFny kymAMYrLJiU1J7MstUjfLoEro+uJYME6lopHK+8zNzDuZ+5i5OSQEDCRWHDzJ5DNxSEk0MYk 0bXqMBuEc4xRomdKPxOE84pJ4tSSJjaQFhYBFYl7Mxazg9hsQHZD92WwUSICwhK7t74Ds4UF NCWaH28Caubg4AVa8XZtDEhYCMjc1/8EbAyvgKDEyZlPWEBsZgEtiRv/XoKVMwtISyz/xwFi cgqYSvw9KgVSISqgLNEw4wHzBEb+WUiaZyFpnoXQvICReRWjbEpulW5uYmZOcWqybnFyYl5e apGusV5uZoleakrpJkZw0Eny7WCc1OB9iFGAg1GJh3fB0ycRQqyJZcWVuYcYJTmYlER5FXyA QnxJ+SmVGYnFGfFFpTmpxYcYJTiYlUR402c/jRDiTUmsrEotyodJSXOwKInzims0RggJpCeW pGanphakFsFkZTg4lCR4vy4HahQsSk1PrUjLzClBSDNxcIIM5wEafgKkhre4IDG3ODMdIn+K UZdjzr2v75mEWPLy81KlxHnvLQMqEgApyijNg5sDShYS2ftrXjGKA70lzPsLZBQPMNHATXoF tIQJaMmTOw9BlpQkIqSkGhh5r/66eTPTd1PqRol3rX+YPgWKTq69MkNy69QftT4BspuOcHBf 2Vr6xuNi2E32ub6vGiteWLz5sMeE++GBlor5q1VKNNpkVp2yXbHKMM/JOz3gWc7c/T/uLf71 qGLjHMnX3wzC2sLsXITyjX9+Nff+e6G58u79vNcqqTr3OvrF7usWCFbMZ41TYinOSDTUYi4q TgQA5JMGpfECAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/Js9m-JNiAcEiYLWBi1c9trKnxlE>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Apr 2017 02:34:42 -0000

On Tue, Apr 04, 2017 at 11:55:50PM -0500, Benjamin Kaduk wrote:
> 
> What do people currently feel are the top one or two highest
> priority items for the WG to consider?  (Such items need not be
> limited to the above list, of course; note that, e.g.,
> draft-schmaus-kitten-sasl-ht-00 has recently appeared on the list of
> related internet-drafts.)

To sum up today's traffic, it looks like SPAKE (Greg/Me/Nico's
second tier) and GSS AEAD (Jeffrey/Nico) are the leaders, though of
course it would be good to get input from more people.

-Ben


From nobody Thu Apr  6 05:56:50 2017
Return-Path: <rharwood@redhat.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 162141294E8 for <kitten@ietfa.amsl.com>; Thu,  6 Apr 2017 05:56:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.922
X-Spam-Level: 
X-Spam-Status: No, score=-6.922 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sJAJK4oRuPwP for <kitten@ietfa.amsl.com>; Thu,  6 Apr 2017 05:56:47 -0700 (PDT)
Received: from mx1.redhat.com (mx1.redhat.com [209.132.183.28]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1745C124BFA for <kitten@ietf.org>; Thu,  6 Apr 2017 05:56:45 -0700 (PDT)
Received: from smtp.corp.redhat.com (int-mx04.intmail.prod.int.phx2.redhat.com [10.5.11.14]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 9B9268E3DA; Thu,  6 Apr 2017 12:56:44 +0000 (UTC)
DMARC-Filter: OpenDMARC Filter v1.3.2 mx1.redhat.com 9B9268E3DA
Authentication-Results: ext-mx01.extmail.prod.ext.phx2.redhat.com; dmarc=none (p=none dis=none) header.from=redhat.com
Authentication-Results: ext-mx01.extmail.prod.ext.phx2.redhat.com; spf=pass smtp.mailfrom=rharwood@redhat.com
DKIM-Filter: OpenDKIM Filter v2.11.0 mx1.redhat.com 9B9268E3DA
Received: from localhost (ovpn-64-2.rdu2.redhat.com [10.10.64.2]) by smtp.corp.redhat.com (Postfix) with ESMTP id 5C00598BF6; Thu,  6 Apr 2017 12:56:44 +0000 (UTC)
From: Robbie Harwood <rharwood@redhat.com>
To: Nico Williams <nico@cryptonector.com>, Benjamin Kaduk <kaduk@mit.edu>
Cc: kitten@ietf.org
In-Reply-To: <20170405191034.GF4004@localhost>
References: <20170405045550.GJ30306@kduck.kaduk.org> <20170405191034.GF4004@localhost>
Date: Thu, 06 Apr 2017 08:56:42 -0400
Message-ID: <jlglgrdbsol.fsf@thriss.redhat.com>
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature"
X-Scanned-By: MIMEDefang 2.79 on 10.5.11.14
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.25]); Thu, 06 Apr 2017 12:56:44 +0000 (UTC)
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/FWVeKUQWLwc5fOKKSpXxoFEr8Gg>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Apr 2017 12:56:49 -0000

--=-=-=
Content-Type: text/plain

Nico Williams <nico@cryptonector.com> writes:

> On Tue, Apr 04, 2017 at 11:55:50PM -0500, Benjamin Kaduk wrote:
>
>> What do people currently feel are the top one or two highest
>> priority items for the WG to consider?
>
>  - SPAKE

Biased of course, but this is my highest.

>  - Channel bound flag...

This is my second.

>  - TLS-1.3-based GSS mechanism

Also consider this one important.

--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEA5qc6hnelQjDaHWqJTL5F2qVpEIFAljmOwoACgkQJTL5F2qV
pELb4w//XLLjC/uglxPK+PxHSU0WUKwjN/sQbS7bQwmUAou7cHsktKY23wrg9lbF
EbuGZX8GSaLt/JMAEhzwR3uqwaTxCYHWXdlk4iQD7zdytppwbBoeIjc9XQtdEKj2
QskfWPzQc+ZU51G36PHbnPOBHeW6SxW4theyut+GTYa1gR9972wLqUEs1ZTOlubB
1IU68OumfGHSxvCsBiwgACfrW9OiNxP1elzKhVXFCnGQNTBMyQRRcBIlmSBJXhjM
0K5NiZfstpQ4+zRQbRQF1o2U0f4FzZRT6AriwS+v1vU+n9ovS1RKjbboj3WUpRkg
VSwJSQv1kLWlgFFcCxes7ExaEE68dpsaI8gg7KEToqhNpi4lupTbwBLcWg9fsIWo
a31tihjlz+QXePScc3v1oG4rdJTrwd1jpao4tzcKqLTkaNEFa4ZSAEUwJTRqeXKE
NMfu41i3DwezhzknKi2vGUmeyb+8M6JLqZwkXncHF9kMv5lJctYFmebEjWAUn9Tc
h2Q4p5al3NHc8IaJQUzJtrTc+H+27BslymWqVpN3D9GyfesZvveMS3sw5lKUEY+e
IOuzenswP4u7f7pGlbe683OH6kKd9TZb2XzW42HHPhdpM4ZmPzh5a+0CRCKKpfJe
5u9XbxuqdMr8M4qx8PsROaI6ysXiUaA1zyPYX+kw/Db6gCy8FvM=
=zW6z
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Thu Apr  6 07:01:03 2017
Return-Path: <cantor.2@osu.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EB2D3129513 for <kitten@ietfa.amsl.com>; Thu,  6 Apr 2017 07:01:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.798
X-Spam-Level: 
X-Spam-Status: No, score=-4.798 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.796, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=osu.edu
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BNE53HbmTv3O for <kitten@ietfa.amsl.com>; Thu,  6 Apr 2017 07:00:59 -0700 (PDT)
Received: from NAM01-SN1-obe.outbound.protection.outlook.com (mail-sn1nam01on0121.outbound.protection.outlook.com [104.47.32.121]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A8FE51294F0 for <kitten@ietf.org>; Thu,  6 Apr 2017 07:00:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=osu.edu; s=selector1;  h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=Sma/u5ydTO1yCiuq6M5BLmQB7PdeVLwYe8q+BEfbm7o=; b=mUgmFIIGv0102+WQ78aeU/MjW8MPiQpWhJAdBpOZv2VYPyTwdkkw8RZblLNr33r0QZL9hYfdKR8FiwP/QGiQNc6yg8OsYl2bttlo6a17w1KSM2+VH66Gy9gz0SQ2Awit6e4K/rZDYNCOcVRXFzMNOXH52XV+nwwSAeaaadosuqU=
Received: from BLUPR0101CA0040.prod.exchangelabs.com (10.163.116.178) by BN1PR0101MB0772.prod.exchangelabs.com (10.160.167.154) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1005.10; Thu, 6 Apr 2017 14:00:56 +0000
Received: from BY2NAM05FT037.eop-nam05.prod.protection.outlook.com (2a01:111:f400:7e52::204) by BLUPR0101CA0040.outlook.office365.com (2a01:111:e400:52e8::50) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1019.17 via Frontend Transport; Thu, 6 Apr 2017 14:00:55 +0000
Authentication-Results: spf=pass (sender IP is 164.107.81.218) smtp.mailfrom=osu.edu; ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=pass action=none header.from=osu.edu;
Received-SPF: Pass (protection.outlook.com: domain of osu.edu designates 164.107.81.218 as permitted sender) receiver=protection.outlook.com; client-ip=164.107.81.218; helo=cio-tnc-pf04.osuad.osu.edu;
Received: from cio-tnc-pf04.osuad.osu.edu (164.107.81.218) by BY2NAM05FT037.mail.protection.outlook.com (10.152.100.174) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.1005.5 via Frontend Transport; Thu, 6 Apr 2017 14:00:55 +0000
Received: from CIO-KRC-HT03.osuad.osu.edu (cio-krc-ht03.osuad.osu.edu [164.107.81.43]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by cio-tnc-pf04.osuad.osu.edu (Postfix) with ESMTPS id A218838005E; Thu,  6 Apr 2017 10:00:54 -0400 (EDT)
Received: from CIO-TNC-D2MBX02.osuad.osu.edu ([fe80::3960:dd86:ba2:ad26]) by CIO-KRC-HT03.osuad.osu.edu ([fe80::b12f:aa15:1901:8bcc%10]) with mapi id 14.03.0319.002; Thu, 6 Apr 2017 10:00:54 -0400
From: "Cantor, Scott" <cantor.2@osu.edu>
To: Benjamin Kaduk <kaduk@mit.edu>, Jeffrey Altman <jaltman@secure-endpoints.com>
CC: "kitten@ietf.org" <kitten@ietf.org>
Thread-Topic: [kitten] taking on new work?
Thread-Index: AQHSrcjtpSMMxP606Uuk3z1FGS6bqaG2+xaAgAAqywCAAAI3AIAAA8EAgAE0qYA=
Date: Thu, 6 Apr 2017 14:00:53 +0000
Message-ID: <9846A6064BD102419D06814DD0D78DE11C010F12@CIO-TNC-D2MBX02.osuad.osu.edu>
References: <20170405045550.GJ30306@kduck.kaduk.org> <fa13dc36-a2b7-190e-a64d-109161123fac@secure-endpoints.com> <20170405151336.GK30306@kduck.kaduk.org> <c69af66b-b105-b8ce-27da-14cfd176ff14@secure-endpoints.com> <20170405153457.GM30306@kduck.kaduk.org>
In-Reply-To: <20170405153457.GM30306@kduck.kaduk.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [164.107.247.163]
x-header-sapphire: true
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-EOPAttributedMessage: 0
X-Forefront-Antispam-Report: CIP:164.107.81.218; IPV:NLI; CTRY:US; EFV:NLI; SFV:NSPM; SFS:(10019020)(6009001)(39860400002)(39400400002)(39450400003)(39410400002)(39840400002)(39850400002)(2980300002)(438002)(199003)(189002)(356003)(2950100002)(8936002)(7696004)(5660300001)(4326008)(46406003)(75432002)(38730400002)(47776003)(7596002)(305945005)(7736002)(8676002)(5250100002)(8656002)(55016002)(106466001)(109096001)(86362001)(229853002)(97756001)(55846006)(6246003)(3846002)(102836003)(6116002)(23726003)(2920100001)(2900100001)(88552002)(2171002)(54356999)(50986999)(76176999)(66066001)(2906002)(33656002)(93886004)(189998001); DIR:OUT; SFP:1102; SCL:1; SRVR:BN1PR0101MB0772; H:cio-tnc-pf04.osuad.osu.edu;  FPR:; SPF:Pass; MLV:sfv; A:1; MX:1; LANG:en; 
X-Microsoft-Exchange-Diagnostics: 1; BY2NAM05FT037; 1:kI3Oj7FCcv/Tya4cXf6OB9AWWlOr7RLfPPF5mVKjITgCUIUaSF4KZ7my9Xs/WXgYP0WVg0Og91MHs5WRkXuhhRgN7IgdNd3RyiKfvjSzeOkG57cQ2HP2Cmy4vBiacrqnv5FhKDZ432mXaXGH1oq1X3y5zNVLV4/D+KgCXGIUzedff1pDUK1MlsPlRgsVYxd00lk6l4w6j02ZKiVHEutPFhmaadE9H92f5Ug/LieCaoN8UztFBn63PGRF9IGdKinNBdP5U+SCRbqr6Uq027RppDHZ5j4Lv0au+FLyfMWrCoIDEYmwq5n7h+qIdIaBrWS45rvQIyQoXQ3ZfY5dq07qmoa9PfaBqvKT55dObmReCev4Oz91cLfTe6wFx7sfMcCDrJhbtfs+F75uiOJOvN0cBXrINKphJ1irVce0bOil84HotvG441cJKb8y2B2K/Riik8iL61OY6zgaFeZ4okCPpYmWSvHIHjhF3BvU3gxQm9CucqSPF6K4JavHZ6cBPlAXBCsAbWvLR/KEPvY1bYKXLsTamHrL2SAwbevEjn7wvmdA2Hw89gFRW5QWQHx2fQ66VK7GaDMIMyM9qJoStXOs21/IQl1/PFxuLwn2vU82KqXrMTIKHI0C0Km0AEFq1ibM
X-MS-Office365-Filtering-Correlation-Id: f779ff05-0b5b-4a27-f7a0-08d47cf55828
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(8251501002)(2017030254075)(201703131423075)(201703031133081); SRVR:BN1PR0101MB0772; 
X-Microsoft-Exchange-Diagnostics: 1; BN1PR0101MB0772; 3:lIjOAqiNAlhDmIk0Z1e5PIBllNlXYNHeiS/bPfD0FO6+FeYfFD2SXQJmYkyfF6oRzHQ+59he1+zaCLlxDSoEybNbiCHgoeDqTOrN7lRgxfYm9UgW9hGt08HEWxK6cwqr3gUXLEPiaDAYngBHddewWZn8jG77QwY9uGbuIQ9nXFYv1/986dFGJAPH7mjym7v2rX99/rXR662Fr8kpGDGqFYGYXDAT00n5DHUKjvK+K4ZHSwpuF+8fUqbFN7DEyFddgxxqTeXeyx3Fdfk5FAA3jD/YeY2ae847YmnzoQIk/knQFZr1EA1zZmDT/ssGcVNE2bAag6Qe5Z11Rf9ujV0Nm9JKzYE7R+r1BMzKULAMIzokIr3rM8mdugQ0HUOOOAQNQmlhh7lSQilXHs61G19WxAxvAN+gVzy+c+epBIDZ+x5VPw5dFt84gBxYthbT5OtdF0Xquy0dWRSal10w3kcdRkLWq90fuWj1oyDeBA7zha2fIyNVeTI8JcB13KNxnbLU
X-Microsoft-Exchange-Diagnostics: 1; BN1PR0101MB0772; 25:/czYkrkArAyy4i/bppDSHU4Mj0rO3Sp1ekiNpNsgyc/w0pruwJwOU7X8WfjBUX82JZCEkjdGOYEUnWs6ZMfu3wEwyxO6VJIEB6+HYaMqjwDDBp1Q+PRJSVg/EMEdotdUKWc7rptICGMn7zHb+/Bm6Y0uQJg3QCDbU11z6fMtddP70CKSDp9Ow3cCfSgubqdQkFBjAje9W7dnxCzghJHJaiwdAdtnVYpWAIIYyIvReELzlyifCi2clIKeCB+Uupm5gWq6LN0E5U8iCLDAMp4mZjSLImVkLc7uIPka+zpQ3Ks/KZEuyJIOWY5g5qEKO+5CsQyoS/Q0ZWdE5imnUFv3iKiHS8VyFNOxMcHcTKyLoiYefrMyGUYd0CNrRBPyW8RDQ/DkKhIEMw0w+TIvHQkvc6ZZUFKib3z2J/sSTRNpOilDAYpJhFAaVs3uu0NTRYnMQvKJnmHVyDIHr/EHaawFmA==; 31:3eX3bRhnkR7FzV5OIH+gkJNFkhyAUjioaJT3Kd/rI4KftqqBVCTKlhWIphaNtqzhlQNCBbbZeyGoLd4PSYMYrt4CdsGa7Ig1KETAG/VSyKcqSJ1VVlVEY4xAkGt3PJcpyy5SsusO/PeRg7w8WkFrIBRwrjAXoLfFSaWxvPBtZ/UpBwf8xEDTB8NVOKA7PhyQU/XwttjtQFSQd4jP6ZZZTKnS6MNjzouwbr1ThhexKB+KnwRkZyKAlQzZCIU7k+Lc86MkeGftQu/mA1t1W6GUsQ==
X-Microsoft-Exchange-Diagnostics: 1; BN1PR0101MB0772; 20:sdaCO9RQWOimvmgq6cnafYvXkNNO5HOdKpG/0QJ85P71FkJcVs5FT/l3oWTpTn0VyJPxAhTqMCXX9n1fxfQSZjOzKGkFZOvPDyF0gZeel97Ut1FSQEHy3eqb0ZXkdP17df47noyip/fBWNvTXT79BXTza5Z3aBD0g5JPnChDIZ7GT9pkv9zxJZsE/ohJ2dbbMaHimgtMQ9bk9Ec0N464YH1i17BEzeZH10eSexW/I4vapCF5OecMwWPCRYPw6RhXey+01uE4EMZhYlVdwiYuwT4DykzfH5N0ETd81V9Q5Tz4IJFCyw1/4ITcsrwgJCxyn5ROs3wFwkSN5tMsZBYAotgNj5oQ0MOJpxnyoA8nUYmhG4Zcw7mCZOMc9cjLvNAHPpd/+atIWwYONWIcA2J+vOTAYs49dss3xTuibAnuYkDgAFxCTMWdIaFHre8vLo34SHZx/JePAygacYt6PBQRj6ks5wvVpoynxaGjGpaTnVpkIudybIxnT5bH9/OFrL3T
X-Microsoft-Antispam-PRVS: <BN1PR0101MB07723AF0A38F93925E51779AD00D0@BN1PR0101MB0772.prod.exchangelabs.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040450)(2401047)(8121501046)(13015025)(5005006)(13017025)(13018025)(13024025)(13023025)(93006095)(93004095)(10201501046)(3002001)(6041248)(20161123564025)(20161123560025)(20161123555025)(20161123562025)(201703131423075)(201702281529075)(201702281528075)(201703061421075)(6072148); SRVR:BN1PR0101MB0772; BCL:0; PCL:0; RULEID:; SRVR:BN1PR0101MB0772; 
X-Microsoft-Exchange-Diagnostics: 1; BN1PR0101MB0772; 4:Ga7wRc309uR1txwT0SBqyKtDoC3NB6BSwtsP3l+Qn/U2YQOoMAmXhfAg8BIP67T0ukZizw1fChtr76zHTdE7pI3GaAcgPExEOW6XhMw97hsbcj9TNwgrCPrCe0NRbbcUQw+y+dW7e1/yIwQlUVssNuOg+MVPm+e62Krl9hxwH1Lt6w8KS3MPcthsBtr+ffa7N6DKg2QvIpEXioMp4BnfPAnrH+QRFhetIqAjriB8umPA3BCv1ijZuivnRyqzqq+1HMLKdteDmshi1Ym2YwagKWE+3rjbLRF6R2UQ6ysHwGwwsospo70SLL7oQ4DSkHVHBi1tCXpqpMAhUYrmB7SAAax6UtEv1gExldXRYGy5wKUbUEpvZSEKI/igG+2B0HhCIxfncZYPu7m78ZxYiciWSm7br8U96X+PCJC8MIud5Bedr7t5tWF+TBnFM6ymj7ZPxeTdCzG8bwCN1LYOv04eI4P8MbLyS7oS1a8h3EKa6N+MWL7azui2rcIOteNkifIMKXF9LWE/9D+LV+GOWP8PiQce7WaEjCkkszKbcMHnShbEmZiVcuuX/khQhTVzDxq0ikHReH0R5HY172qiqLGi1CDdwTdpW33OmwrfVN5Uk0RMZ1+V+KWlgOstwnCqrkMHfrAn7nBWiw0mIphrCBTFOL2MqYfwCe3y4DpSYZYN9VEmGuMZophrFpCs+46cV0tCN0Z2boMjRfzyM/QaHYJ7opW40SiApHSJPUhgcOM9csZqsNV09H4X+MEpkOcmYYiu2+Qvg4STG2q85J22xHTVtlCbzu4tbbNmpsB3oWUnTVqTkgaFWDXH907+VRvJ+kC9RHJG/6HL9yNKQ1OdhFTkBw==
X-Forefront-PRVS: 02698DF457
X-Microsoft-Exchange-Diagnostics: =?us-ascii?Q?1; BN1PR0101MB0772; 23:Hl/WYGQx+py+XMQH/xHnhvqExwVzqWMOUNx8e9k?= =?us-ascii?Q?jxIkky19rCKKUwnnVaAfsZt4cT1nlRicklY85gtzljKwESjUZ062A6cvt9GC?= =?us-ascii?Q?Y95h+QMqb8E6IcQdSNyl1fRxiUYi9zFmbncbS+axtCdQ+bdqP6DphbGAAXmt?= =?us-ascii?Q?Nkd95/LRJWjyjwx5VneIVqSkJopiZfekIEtTGMUdPxCVTA4HlAIuF40j7O1A?= =?us-ascii?Q?wl1eYM/o+uhqDwCGp7E1shSaZtJAQeuGYubTZjZLQYuvOvb8bClCkHQ2Aoy2?= =?us-ascii?Q?Fn9noYUWClaNrYxV1xqIuxFNtku5QnEQFnCzgpjx4nP/lKZDEGxEJckwhFdg?= =?us-ascii?Q?tKrS8CG2zshBpDaRLA8fMQ3RbqHFLo3PaoYGIef/lhPBx+Fwc3BVzN14xinG?= =?us-ascii?Q?cSXrqdcOZb6BaEoZwcj3CPaz0TbyFRgyZzxqADYDLaI8n0KaqmHEr63b7vJj?= =?us-ascii?Q?oHqxv2bNq55Qcd7lTwNVGrQwGO8HJGOrqv94VVdmDJ7y+xtWOsddtVHGtdUn?= =?us-ascii?Q?rsbBBb0FptY2/oIyE/j4VNXs0pvKQP0aed5KONKGrzCvMM7ocyytthVvZVve?= =?us-ascii?Q?C7BrVl741AHqXDhr+FCI3pFPPrx6xehG3Oak5ITBbI7Vx4eerlBOOBFGLwN5?= =?us-ascii?Q?QDMA5tAydyqHElzSGHh4ERvWbPPsgSuFKgFfjSdckWPVMByLGac3YJuPv5cq?= =?us-ascii?Q?uHuS/tPLiA+bdsfqCF2pZqdKiIpMjQ9wXSq1QLmLpUwbBH5CmGAsq+I+qHzs?= =?us-ascii?Q?rxkIXlG6xHZwHs75j75Q4NtrciKSv7IbJKsXiA2FMvk9XE4nuExssMxHn5Wp?= =?us-ascii?Q?Nr9MQQd8HK6eAnncJ6G2R8/amtA5Ck/vYffYHUZxj/1N18gz6cCB2Dx5tGoM?= =?us-ascii?Q?M7HfzX32VnTfvtJ+Q0Wj/sQa9tuBwsCz/gxvjeeRp0kIbCTU0W2FioG5W85B?= =?us-ascii?Q?x/Z0SF7JcoQCWVvvQpKdulTMZgMghUwPrRafQlqttRXDwJa1NKJ0kgCQBt0O?= =?us-ascii?Q?e95HO3jvdA7LvT5JyxqRZr6WIZCP7beZifZVIEW8Sk/664tKsZLCLIVa56Q7?= =?us-ascii?Q?c6jqtin31HzlJ1Xs9QAUMYKdnK0R5NbrIwFWCdy9yxxLg6s/adDXZleM9PEW?= =?us-ascii?Q?klgNKpb0BU8K1rJaAdYkxJrFJm4gJZIp2fkzPeisH13qs4na9bhO4+9WeGGM?= =?us-ascii?Q?UmHPVWGuzdQVxxe76lNs+3XVqe6Tf71TFSk5opFe0VkIb/UbVozLY+f7bBZG?= =?us-ascii?Q?BDYxgsBNQwOJy7gIh/hU=3D?=
X-Microsoft-Exchange-Diagnostics: 1; BN1PR0101MB0772; 6:5PvPjgHOWLaexJAfoJrFliP4X/LD1ULKGAmWSUeT9t4yLcgXAf4m5nIL8I+yO9Ys1n3HEab9e4lXjwa3sDHAsbavNIGrxMG/McHyfemU4tH1yO4xr8PCtgxJUlWEHZhG3RJdETzD1WdhrbgpbPwaoshBOCsKRqISoWSpr4Ey7WB5srQ17cjQ1I/5xfH1aUKkOn9XPm8LT7qMQtsconAjmA6okhYYBVO+2qmapZSa8FCqXHl42q1Y0FZE6jH8/9SrWRrvWbMKXUwzT7Ip7ZIuACq9uUrt4JaVb6gdD5Gbp+QvFa82wl4inu9xbcv6eAFfa9jMOKDreSYkVnW9jIt7aeudm5rGVTRm+iwFxRu9dfqYtqYZ1ryLZKqZy/IWaYN4yufn79/sUJxzpEza9uiyPg==; 5:XoWeqvmOAWw1469v/fH8P0S7i7lAfcx5T9S0uDFQzHjveqZHDICDjwX/MeuUHlXIG6+/1CQfkcxr2332BKy7NEFsVaf+YUSBOszlPkGTiBndBaM7E8bWJsDXlPNP0QB1H5vbxsyVauib+JSzh76gOg==; 24:1gegWlhZ/PjViCI90hr3BPEijnR7G/sQPZZA76++dSKd9GUXiRKwE64jELo5ghI8EJfOeoqLXYnfCsj+3E7rdLuWUqX1FypSmDbK5AbnE+Y=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; BN1PR0101MB0772; 7:RVgYprHmPudQj23p2FPh3DeOEKfaWTceNUY5oJPPVZKI60QgKACTPb+rEkQSI5w5yBgFgYPcvv6ul3nwQKFXzr35gONpDWlUGt7zNf1IoR8mBtflQAQ7acxpr5ogNFnbvRQkJlBLnnkEeYAy2CNKSq8ebMPzBZQY+CZq8HyCRu4LQus7ARB1gSZG9LInXEK7MStC5EhC1DrlwYXHg/vT27OSb2CGvfq36UYZzfMYjdxkwJsCO8DRXDuogmw3qODIoc3lPJE7PgbwqO3P2/cp+i24A3kpsDLtFOUCrJ1zM5A/kKUYh3+x/rDLytiWr6Nwu43ESb/tlihFzjrc0AMIzw==; 20:6ANCYv9B9dnvw23mHg8yMp69VhGr/iTDn7Y3+d9m1RXxg3Tx6SrJtOIQZI2VwS6C5Nqcb2MmXs8LFCd8toYFT8QoAGDERNBB5jGavI1xMwC3IkK1xTXhQnjhTqUv7GBRTUGnmqJcTnI3ykYNBS4iAxe1X9wAkhdBUVPIWkanNcw=
X-OriginatorOrg: osu.edu
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 06 Apr 2017 14:00:55.2292 (UTC)
X-MS-Exchange-CrossTenant-Id: eb095636-1052-4895-952b-1ff9df1d1121
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=eb095636-1052-4895-952b-1ff9df1d1121; Ip=[164.107.81.218];  Helo=[cio-tnc-pf04.osuad.osu.edu]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN1PR0101MB0772
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/Pg8yhfpfC1nxjKy7cGMlc0I1wLY>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Apr 2017 14:01:02 -0000

Re: saml-ec

> I will take an action item to post a new no-change revision to
> un-expire it and return it to the WG dashboard, since you have
> expressed interest in it.

Or I can, I'm still around. I just don't have reviewers I can offer up. I c=
an make time to address issues if they're raised by any reviews. I have no =
outstanding edits that I'm aware of.

-- Scott


From nobody Thu Apr  6 08:25:02 2017
Return-Path: <mrogers@redhat.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 39133129529 for <kitten@ietfa.amsl.com>; Thu,  6 Apr 2017 08:25:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.109
X-Spam-Level: 
X-Spam-Status: No, score=-2.109 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, T_SPF_PERMERROR=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fHS3l0R_9wY4 for <kitten@ietfa.amsl.com>; Thu,  6 Apr 2017 08:24:59 -0700 (PDT)
Received: from mail-qt0-f182.google.com (mail-qt0-f182.google.com [209.85.216.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 58802129531 for <kitten@ietf.org>; Thu,  6 Apr 2017 08:24:55 -0700 (PDT)
Received: by mail-qt0-f182.google.com with SMTP id x35so38907031qtc.2 for <kitten@ietf.org>; Thu, 06 Apr 2017 08:24:55 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=swpKTrZT1+O61hPSgKs7ue1s4OBzHEREoJ76j315+Y4=; b=AwemGOE0r1cHHNCuoStH+qn9JAYyb3ArPb5Gz04HJVW//4XNwf/Y0kdrhBt/xcslLq lIe1bKuFL3yfOgVDJKjuh4a5uWa4n5njb4LXiVDtOmPm8V4ch/bWWd5czLjg2bu0DP9I 5KpSCPMjNLrfVA+eU5328UDREuUhg9d40y40ccA/zcuvPK7KESXZqUyWlIZGE4/D26bo UgkHpclmzZwUpZzm22kEiHUw4zwKIPNBJ2fHd4VwLKY228mdPnrfxXVR9q1S4IDvpfY+ 2HmglWl65KdLUoFl7mGb+JimFDY210D4MJuiUJVBZj/aRTjNIHXos66fz4g0eGUI1XGU S/JA==
X-Gm-Message-State: AFeK/H23IeAbNQI742ecSiXrtWKDfK1HQrder7DRj7WcYoMf4XlGXfgFmCVyJcxB+hKk0kQ2sL04h7nm9Yns5vDG
X-Received: by 10.200.3.46 with SMTP id q46mr37553150qtg.243.1491492294391; Thu, 06 Apr 2017 08:24:54 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.12.175.181 with HTTP; Thu, 6 Apr 2017 08:24:23 -0700 (PDT)
In-Reply-To: <jlglgrdbsol.fsf@thriss.redhat.com>
References: <20170405045550.GJ30306@kduck.kaduk.org> <20170405191034.GF4004@localhost> <jlglgrdbsol.fsf@thriss.redhat.com>
From: Matt Rogers <mrogers@redhat.com>
Date: Thu, 6 Apr 2017 11:24:23 -0400
Message-ID: <CAAeFVfw4FEjGuhgOswXw6bsKs3j4L7AeEfuZ0kLj+3uYyCgcvA@mail.gmail.com>
To: Robbie Harwood <rharwood@redhat.com>
Cc: Nico Williams <nico@cryptonector.com>, Benjamin Kaduk <kaduk@mit.edu>, kitten@ietf.org
Content-Type: text/plain; charset=UTF-8
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/WY93AAcju1JMtwSytHNMrcNEHuI>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Apr 2017 15:25:01 -0000

On Thu, Apr 6, 2017 at 8:56 AM, Robbie Harwood <rharwood@redhat.com> wrote:
> Nico Williams <nico@cryptonector.com> writes:
>
>> On Tue, Apr 04, 2017 at 11:55:50PM -0500, Benjamin Kaduk wrote:
>>
>>> What do people currently feel are the top one or two highest
>>> priority items for the WG to consider?
>>
>>  - SPAKE
>
> Biased of course, but this is my highest.
>
>>  - Channel bound flag...
>
> This is my second.
>
>>  - TLS-1.3-based GSS mechanism
>
> Also consider this one important.
>

I agree with this list as well.


From nobody Fri Apr  7 09:36:52 2017
Return-Path: <daedulus@btconnect.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C7D67129540 for <kitten@ietfa.amsl.com>; Fri,  7 Apr 2017 09:36:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.697
X-Spam-Level: 
X-Spam-Status: No, score=-4.697 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.796, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=btconnect.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RkEgLmynPqQc for <kitten@ietfa.amsl.com>; Fri,  7 Apr 2017 09:36:46 -0700 (PDT)
Received: from EUR02-HE1-obe.outbound.protection.outlook.com (mail-eopbgr10091.outbound.protection.outlook.com [40.107.1.91]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 85426129519 for <kitten@ietf.org>; Fri,  7 Apr 2017 09:36:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=btconnect.onmicrosoft.com; s=selector1-btconnect-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=GhSEqKLPExWLZrHQPYy2WLlg2WgAAsuAqSFMQMPOb3Q=; b=KnQ9A2X17SLFbvMql2y9sPdNNV7puAQUZpxGg2+qhp96PUvXAClMLIoNJOaCK6rd988qRQIKbL64NyspIeHYyMD/185C1M7tiy4d947jsep1mDAnMyOKgyhaB00YZJZwwRN9MKKXi7lf/Bjl5p7RW91EmyNB9dtA83+J9wWxNvU=
Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=daedulus@btconnect.com; 
Received: from pc6 (86.169.157.161) by DB5PR07MB1560.eurprd07.prod.outlook.com (2a01:111:e400:5bc7::10) with Microsoft SMTP Server (version=TLS1_2,  cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1019.8; Fri, 7 Apr 2017 16:36:30 +0000
Message-ID: <005301d2afbc$d6124640$4001a8c0@gateway.2wire.net>
From: tom p. <daedulus@btconnect.com>
To: Benjamin Kaduk <kaduk@mit.edu>
CC: <kitten@ietf.org>
References: <149089878562.15595.17069295528887995710@ietfa.amsl.com> <00f701d2ae23$6d83ac80$4001a8c0@gateway.2wire.net> <20170405155316.GN30306@kduck.kaduk.org>
Date: Fri, 7 Apr 2017 17:31:48 +0100
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
X-Originating-IP: [86.169.157.161]
X-ClientProxiedBy: DB6PR0301CA0021.eurprd03.prod.outlook.com (2603:10a6:4:3e::31) To DB5PR07MB1560.eurprd07.prod.outlook.com (2a01:111:e400:5bc7::10)
X-MS-Office365-Filtering-Correlation-Id: d1142920-e05a-40a3-5b71-08d47dd43ea7
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(201703131423075)(201703031133081); SRVR:DB5PR07MB1560; 
X-Microsoft-Exchange-Diagnostics: 1; DB5PR07MB1560; 3:BZKV/AbyFakUCcoTa+CyJICDBUhChB1iSfF3tuuqCsgRlxS3u/85vVdEs876AkzEKjVJ9pQiYzFLGqv4kabSXf1Iie9hStHhQHuFTjQ8//2PAHs5abEiBAMO9FCBweu4RXYrYri2ehXSBvPtKbJwB31LPJc061no+lhXwrz3L6T8cYuAO/Bpi61ELB8H0M4B+4fIaFMTDblDIOraqYLdInuas2ASa+U6Gl6pN3WZX+9t5+QpgbJSSOYWUW+T73snAeYu/sl29j1eH8j/A8LQW6t182v8kGn9RDSSUalYKp8oX5pBQvQdce7DrH81gtjbKBMEDb70MZ7PPpYyeMoD+w==; 25:qMfPERzUEi2Xj4VkfOERr7iSbEDOdxH3RTpWn1JxGB5j7QvP4HIXnBW5RdBvq4JHTEUR4yEy4SKqbHZdaIm54/UDP5jr8rqv5M1VIe7S5mnGqOtLIpJYVHgxr4PbZ9m8MyVlg+hNGOgw/jFHwN7iC9Y7H25LfKntlkAuKGHChGOWpULLGtj6yv+oHDhNjBmhoEtpsjgbH1q5EjI0/03piMyB1vS2uGTIO6Xeu65mu+QYtliWHIjSDH7YYD64ldGZj6ZNSAJzVQsX8xR/m4EivQuUFRpCwy/cU9JA3FVn0UISIURgJ9jNBBq7f7f5yxQ2B8hPRicCFV+yAp+rFfp/H5FIN+GImSo/USbryNbxGhRS0MG+5dgoZthyMy4qwt4co55Y7Ipwmr9kdrxrEUNBocojv7z/XjZJgkQgNZnzvla75Fl9Mmi0cl8qfKIPUF4Od2YENqnHSD0LQYWOaA5v2g==
X-Microsoft-Exchange-Diagnostics: 1; DB5PR07MB1560; 31:nwINIaXKDRg6y4KMzLHmtI/LPCsvpIkVPlsiGJDLYMkU2Huui+2nsoEgZqEa3q9lr3VYUOXD7Y0WUWVxHMZYXnlK4W1Ipk6y9PyARPhd1CoCa+711jCl5AEpRmOMXveNpB+ajpUqjb3aVOCBriQpJVFJzcfBm19Pj7krVl52oANNk3fnkziAS/gkT15+XocAUjUCPH3y9Y0Bv62GcY7ksLlu2it1qJ02jkgm3s0I0Ef4ua3DtJakFTf8VbtoOp1a8ts8+AcDlwU1u79dtkYKz6GWh/+tUH0BF/yXbBkIRk4=
X-Microsoft-Antispam-PRVS: <DB5PR07MB1560B693DE3B952693383203C60C0@DB5PR07MB1560.eurprd07.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(178726229863574)(100405760836317);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040450)(601004)(2401047)(8121501046)(5005006)(3002001)(93006095)(93001095)(10201501046)(6041248)(201703131423075)(201702281528075)(201703061421075)(20161123562025)(20161123555025)(20161123560025)(20161123564025)(6072148); SRVR:DB5PR07MB1560; BCL:0; PCL:0; RULEID:; SRVR:DB5PR07MB1560; 
X-Microsoft-Exchange-Diagnostics: 1; DB5PR07MB1560; 4:xUplWhAUi4GyvSTFe3rZp8ggd6k6Z2Z4+Ly179jkwgE8aHMprKazFjNVvcWWeXoN3+GtURXu+rJieGW5id2yVfbnGF1qMBt6bzraMaPY4AVl0W8WVO5d7qMQF5W6ai59sx4q8tjvqdwovuXJipUEFRdOocrO85/ic+GO/UfgophmZ36+e29VJmAQgLCWWi9b2HXOLSQxmWd57HjRUeNnTEMPouOrNX4qt98KTQMCr/IOI6FuzpdJWCCEjhArG0wgVR/CkNS+USz2vVLtxcpJYUMHalrtLlaiA9xE+WsWbIPzVBfsIuBfCfcMdBiq5uwzJ+HSYIehrgpMnq+Dksl8vrOgnfJrhhXOyi+YAoqjmZqgDxJfCMDGEY0qjUboPwx5OWdHsSbBI/a6x6g9qI125FnkXOSjc+XY/L9Z+JeJ8jmmuuO1zWQoSWjGAb+vMRmyTqD0/kC3rLWvCZxO6QUce2mB5rOKUJSN3oNzGEd5BTrWIYdHM35SpvIObO6ZwRn1qTjWx2FSeUNIc9NJRh66/98kfacmZzt2c6pGDNIP9zjuQeRv+7EZ4UQmGg876ZbX3M1GBh3KoX27h8Cb9uCS+AUmnHrerGjWwbFDF+VQgvV81O2blKO8o3ifSrplDZMMUYSde8g6WXoBvbQtjAE5c91NtzF3RVnp6lu+ja0uDmZ+IUapM9uweX9phMnqytVaKvBLXIkerCyNfBB37+C7x3tWbBBXZ+BGVBnvu5XgIiNGcPkaG+D2ie0+SUrOf9CzNaQ3AjFJ6Y2SeOMWw8DfN7Vx6cdsiPWi7Kpaw5UPsJY=
X-Forefront-PRVS: 0270ED2845
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(4630300001)(6009001)(39860400002)(39450400003)(39410400002)(39400400002)(39850400002)(39840400002)(189002)(13464003)(377454003)(24454002)(199003)(51444003)(6666003)(4720700003)(110136004)(23756003)(5660300001)(6916009)(38730400002)(42186005)(50466002)(1456003)(14496001)(61296003)(84392002)(4326008)(2906002)(6246003)(305945005)(7736002)(6496005)(1556002)(86362001)(2171002)(33646002)(3846002)(66066001)(6116002)(189998001)(81686999)(81816999)(50986999)(76176999)(47776003)(6486002)(230700001)(44736005)(53936002)(50226002)(8676002)(81166006)(229853002)(62236002)(230783001)(44716002)(9686003)(116806002)(25786009)(74416001)(7726001); DIR:OUT; SFP:1102; SCL:1; SRVR:DB5PR07MB1560; H:pc6; FPR:; SPF:None; MLV:nov;  PTR:InfoNoRecords; MX:1; A:0; LANG:en; 
Received-SPF: None (protection.outlook.com: btconnect.com does not designate permitted sender hosts)
X-Microsoft-Exchange-Diagnostics: =?iso-8859-1?Q?1; DB5PR07MB1560; 23:rXaej0bxpSpJHm0/nDf0GNV0AnnVWdzUfclJqmG?= =?iso-8859-1?Q?bRqVxrpT0wG16DNuqFlKURNWjI19Bk+r7zY/teqfgm6+qa/6db8BRj6RXS?= =?iso-8859-1?Q?v8HVXp9qDbeXStkz4SvdyKwfA8OzMZdjYONJ+dc3gQ5tiHCooZ6eoMjF8o?= =?iso-8859-1?Q?/Vb393RK6xl6z/rpHNqq4cxNYzaGTtDexOE6zLQN3RuVx4QM5Vw+JICKN1?= =?iso-8859-1?Q?Qr4bLpcKpOn1aZ0MQGtS0rfaw20YfZfvdGtM7AVL1LGdEdckOuITQvFH0I?= =?iso-8859-1?Q?FVFH+yHYwyZvkSiESS27NFixmcpXhj67SlUFwqTWM1rx9sbqDtbLaPUS7v?= =?iso-8859-1?Q?gHWU6qu4RdNyMd8TFwWY28uPQ7GjLB6Wfnr77G7ujZHN+xRZKSYKC90J1V?= =?iso-8859-1?Q?iCpXeJOtzR60NE7MHPTgj9uQj/IZ3y5zBj99VAxR7ubVCecATTJxB79x3a?= =?iso-8859-1?Q?+UrboVY01Keh7e0oiCRXhOSrML5UDOStlQJnUnrjD7YzF5mcgANBHXuO1q?= =?iso-8859-1?Q?PySWgTnbGfbWJy/eJv5N/blsdFZtZRKXJm9LUuIU1vtjONsG4hiy0SA+lK?= =?iso-8859-1?Q?3bI7ItMYVKFew74e3ALNkhblGWrZnXu0dVgtJikZZGtEFZnW8hNMDLPMdG?= =?iso-8859-1?Q?pH2Kvl0/aBNGk1JUNjEK/8zgNvknSEcdCkG0UL66hAzk2x5i0INgfxBqG5?= =?iso-8859-1?Q?igG68jCnZGYcDT6iQMw67HQxk90PRvjwDLocKllxnDPnbrxLKPq8uIuZ37?= =?iso-8859-1?Q?cxMRuDa9hl2PFRvA3Q00mjVSybG6wGt0n5tDusem4IQ/CKnTc8AgxLokqr?= =?iso-8859-1?Q?di1RJRoKD6C8AyDAKC5A60SRhndiGggLO5G4kE0s9791ZixMyshyohO1sm?= =?iso-8859-1?Q?TnCfN5wv4mqCTztaG2FHCQX/ZpOfzWFAnpvOLNg8x6zwlxmH5fx2BXFxWw?= =?iso-8859-1?Q?7xVAt06aqnsyzBCeKubcB8bYC921sjFcOo9cO+AMleAU9QAKLkYJ7WPjWX?= =?iso-8859-1?Q?8ryhPATfVYoo1P+dBFIZ5er58/ZNETYgq+psRJxeTMB65peRvQqvG+b+j0?= =?iso-8859-1?Q?Fu6m9pX9MhGzGUdJGHLtPSdqBnv0vNAk8T56Wi7/sVRyrp3SlmQwisxqi+?= =?iso-8859-1?Q?f6Ot+p25BGCt4PO4aYBqBY13CZiE/gsW1ESbC7ud8IyB4NRIgSZKy8oCVK?= =?iso-8859-1?Q?KhHfhe4hmYtahOIVfC/8kPSCK9NcDTezNPUtoam6aGhJDDAjhinQNwD9dY?= =?iso-8859-1?Q?+SKWoL+VkTv6pmVOcKzTTtMu4pCvTAPMsQ4+YB4ykGfV4HwZCl1TR9PDTg?= =?iso-8859-1?Q?pHMFA3Ju/8jOsnB/7R0Y3DBGAQCfPwUOYBN78OvLLC3HlH0wrZ4srrp/5E?= =?iso-8859-1?Q?6qmi2r20sG4JoicN+0MTLnb6ukiAYbQbspUpZoFI15X7PVpn47EJw6X29p?= =?iso-8859-1?Q?fYz/uHZ5AEOapLC13iV+/BoOIRFi3qoPlTCurNzIGwJZDpe697dD6HTla5?= =?iso-8859-1?Q?izC8SN5pUsrsYF8LyRNu9e6fhPoJuEGmS8nwB6sHD?=
X-Microsoft-Exchange-Diagnostics: 1; DB5PR07MB1560; 6:s1FQqL8tNgkM0Q6gyweY7tLk8/zXffFH42lxh8kv3ejLGNINXSCR51HGgXhrKsMjrpGU4WJjy4LYf4JKEiZzleQJOQnviSsVDzl8tqVakxbKTC4/OyXRKu0J5h7tK7fmiqRoxQ6yFaOF5KbWYzyfgvAMSYErAHP8q3DDVGDbylRgnxtOUenGzsbmTWeNoQ4VNNOAi8bofb5XZTVH6YvwHnFlaWgMTAjgFgDUGMqBEI5TxZED2zU7XRRlS6Q5uNjopCcz/aKVSU0oetaG88k7K6IdU3uvXhxCNSrIgzytnWnJ0sAoJAjgWmTP7OSgSE8xDpbHvL4CnH+mMdv+0kBjeYagyjDsCSwudoTeyliCDSp+rHYojz773Vt8OIK6ljWsgZOYVUuz6lkIN6Ufy1rOcJW4XyJ4C8W0UXnbZYLiHvPuDnssg5nkiF/Mwp5aWnHPx1BYjcGqN+KB8AIxXs0FXg==; 5:tJpOSnW6E4FHTZiDgclqzjGCrSehDbHO0KS2rhSnyzSFxa3THsp0iSWQXcQZkuW2AYhI4AP4XNWf+4ndht6JVd73DUs1LXfwJkMCuUeBpnCalpzF/3XKz/p7a8K0+9n+28wqWUDlZUbSbmJho+12dQ==; 24:xiXoS/aZ330pgCfZ4VMluov4LszbR6+qvMyF6cUEaFq7il+btRgQthZBtZFei5dHmVHz4sfZjN/NIbsu8sGFchs9B5Z+nu4glw9Zl94HIE4=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; DB5PR07MB1560; 7:3ZDvca0goS/1lOue0UPcv6jIEotTCnGKoJkYEBdObnnZalEnZIOj/jN5EiC7jme6ngpwTY5rDnLcoL3n4iRke3C8yMuqX1Y+UDJ7vOYks+f68f9T2gnpnW2u+Qrj5r53QsJIJnxw+yfmXzio0pTVDJHuToMQmXuY7RazULg1eNh8Pybnoql70Jz1ulfVvNWNA0yJ1DHzf2FpQH6KzsN7f47rO4qHKBEp+ftV1Awr4+/ED9vcl9MsrvjlXVcesHcITxL4KkxBF64z/Sxxj+TmZETRZ5AX1jnchuOV/J5hJ+GPilq5le6wx2G/en+/QgNke5Nj7q4TVtevzVX2Q5yxZA==
X-OriginatorOrg: btconnect.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 07 Apr 2017 16:36:30.1564 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB5PR07MB1560
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/ApTBigNDyFxwuY8NmA3Dyv9The0>
Subject: Re: [kitten] draft-kaduk-kitten-des-des-des-die-die-die-01.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 07 Apr 2017 16:36:49 -0000

----- Original Message -----
From: "Benjamin Kaduk" <kaduk@mit.edu>
To: "tom p." <daedulus@btconnect.com>
Cc: <kitten@ietf.org>
Sent: Wednesday, April 05, 2017 4:53 PM
> On Wed, Apr 05, 2017 at 04:43:46PM +0100, tom p. wrote:
> > From the title, I was expecting an equivalent to RFC7465 but that is
not
> > what this is; I think it should be.  Which WG is best placed to do
this,
> > I am easy about.
>
> I'm not sure I understand the question.  You are interested in
> prohibiting triple-DES cipher suites from use in TLS?  That would
> best be done in the TLS WG.
>
> This draft was given its name as a homage to RFC 6649, which AFAIK
> was the first document to use that construction.

Ah, I am not as well informed as you.  I first came across the name of
that form with RFC7465 and assumed that that was the one you were
following.

Having read RFC6649, I still think that RFC7465 is the way to do it.
The Abstract of that RFC gives me very clear guidance as to what to do.
This I-D I find less clear
"The 3DES and RC4 encryption types are steadily weakening in
   cryptographic strength ..."
leaves me wondering; would a dose of iron or vitamins restore their
strength?  Well, no:-) but I want clear guidance, not the evidence from
which I have to work out my own conclusions.

RFC7465 - wisely - avoids the word 'deprecate'; it tells users what to
do, what the advice of those more expert in the field is.  I have seen
discussions on several lists as to what the word 'deprecate' means, with
no consensus, no definition.  We do now have a definition in
leiba-cotton- -5226bis and since you are proposing to update IANA, then
that is the definition you are going to get, like it or lump it, so if
that is what you mean, you should have that as a Normative Reference; if
not, then I think that you should avoid the word 'deprecate' as RFC7465
does.

Tom Petch

> -Ben


From nobody Mon Apr 10 11:14:02 2017
Return-Path: <mrogers@redhat.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5358C1270A0 for <kitten@ietfa.amsl.com>; Mon, 10 Apr 2017 11:14:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.41
X-Spam-Level: 
X-Spam-Status: No, score=-1.41 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, T_SPF_PERMERROR=0.01] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zwEbAl8Aswik for <kitten@ietfa.amsl.com>; Mon, 10 Apr 2017 11:13:59 -0700 (PDT)
Received: from mail-qt0-f175.google.com (mail-qt0-f175.google.com [209.85.216.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EB424129A8F for <kitten@ietf.org>; Mon, 10 Apr 2017 11:13:58 -0700 (PDT)
Received: by mail-qt0-f175.google.com with SMTP id c45so70822494qtb.1 for <kitten@ietf.org>; Mon, 10 Apr 2017 11:13:58 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=oinQfFm1WZkEauNhj9Wcn1H4RQBwZR1jSQ5sa3fibXw=; b=EPc9/Ma4uCYl2WOOamUZ39k4g270gXM+Y2bETrNgOboHqgIgdGlRgTYyPejpTSzAvq Q3yvTEoWk51EzyBRk9oi6HnIQTPujdXyz1OlibXIJ1E6+ZXzcPSuWtEci478SFsDQoM3 myiXu8k/XyPIa1IGOtfJELE0IjIzfQVwjZtBULOY6n+v+ULi5W8Q5Qzp75xrvUYpe//7 OzVHgdFOvA4PnAUL/iIDPvk+jmiRFgwWYH3QAfi2WOw2wcxQ0k87Jl3V0+OTBeX2va3T 6a3xKNfx/ZbJzdbDKKj5FJmA4j7NvA6M8IKxFsJS+wSqnlYK8TZzCZVacD8roGdaRHB/ b7Tw==
X-Gm-Message-State: AFeK/H1wuq9Cc5eaed+MPXjW57O+K6Gm9TI5k0wjNo7bbrVRQOgJeDgi9L741PK9ENEzwJ3jJMUCVO3E4e5JwvFq
X-Received: by 10.200.3.46 with SMTP id q46mr58300679qtg.243.1491848038095; Mon, 10 Apr 2017 11:13:58 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.12.175.181 with HTTP; Mon, 10 Apr 2017 11:13:27 -0700 (PDT)
In-Reply-To: <2ccb915d-4a10-1ced-d8c8-298e1aec6373@mit.edu>
References: <x7dzige39sj.fsf@equal-rites.mit.edu> <CAAeFVfwexk8THERJZ5Qm+sTB+FVMWsRSOXninGFmMWehzwiz-A@mail.gmail.com> <2ccb915d-4a10-1ced-d8c8-298e1aec6373@mit.edu>
From: Matt Rogers <mrogers@redhat.com>
Date: Mon, 10 Apr 2017 14:13:27 -0400
Message-ID: <CAAeFVfwY2T3XndS3=bJ3qBqiv4=_pSM-UkOtGPG6gCq+1yM2mw@mail.gmail.com>
To: Greg Hudson <ghudson@mit.edu>
Cc: kitten@ietf.org, Benjamin Kaduk <kaduk@mit.edu>
Content-Type: text/plain; charset=UTF-8
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/yrjoc9Y5xaWBvYNvk9J1FkVmF0g>
Subject: Re: [kitten] Review of draft-ietf-kitten-krb-service-discovery-00
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Apr 2017 18:14:00 -0000

On Mon, Apr 3, 2017 at 12:32 PM, Greg Hudson <ghudson@mit.edu> wrote:
>
>   The URI RR has service information encoded in its ownername.  In
>   order to encode the service for a specific owner name one uses
>   service parameters.  Valid service parameters used are either
>   Enumservice Registrations registered by IANA, or prefixes used
>   for the SRV resource record.
>
> which seems like a slightly more restrictive statement than the one in
> RFC 7553.  We may need some guidance from the chairs or ADs on the
> mechanics of moving forward here.  Simply making the reference
> informative doesn't seem sufficient, as the URI RR type is fundamental
> to this standard.
>
> (To be clear, I think what we're doing ought to be fine, and that it's
> generally pointless to include a transport label in a URI record owner
> name like one would in a SRV owner name.  The question is one of
> conformance with the pre-existing standard, not practicality.)
>

I'll leave this as normative at the moment, but perhaps it warrants
some text to explain the difference between our use of the owner name
and the RFC 7553 guidelines.


From nobody Mon Apr 10 21:53:10 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DB25F1289C3 for <kitten@ietfa.amsl.com>; Mon, 10 Apr 2017 21:53:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.221
X-Spam-Level: 
X-Spam-Status: No, score=-4.221 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bnxE7DM2TXsf for <kitten@ietfa.amsl.com>; Mon, 10 Apr 2017 21:53:05 -0700 (PDT)
Received: from dmz-mailsec-scanner-7.mit.edu (dmz-mailsec-scanner-7.mit.edu [18.7.68.36]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AC059124234 for <kitten@ietf.org>; Mon, 10 Apr 2017 21:53:05 -0700 (PDT)
X-AuditID: 12074424-733ff700000015d3-b7-58ec612fd865
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id 6B.46.05587.F216CE85; Tue, 11 Apr 2017 00:53:03 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id v3B4r22i028401; Tue, 11 Apr 2017 00:53:02 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v3B4qvZD017166 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Tue, 11 Apr 2017 00:53:00 -0400
Date: Mon, 10 Apr 2017 23:52:57 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: Greg Hudson <ghudson@mit.edu>
Cc: Matt Rogers <mrogers@redhat.com>, kitten@ietf.org
Message-ID: <20170411045257.GY30306@kduck.kaduk.org>
References: <x7dzige39sj.fsf@equal-rites.mit.edu> <CAAeFVfwexk8THERJZ5Qm+sTB+FVMWsRSOXninGFmMWehzwiz-A@mail.gmail.com> <2ccb915d-4a10-1ced-d8c8-298e1aec6373@mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <2ccb915d-4a10-1ced-d8c8-298e1aec6373@mit.edu>
User-Agent: Mutt/1.6.1 (2016-04-27)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrEIsWRmVeSWpSXmKPExsUixG6nrquf+CbCYOZZWYujm1exWNyfGOfA 5LFkyU8mj/f7rrIFMEVx2aSk5mSWpRbp2yVwZRyYq1XwVq1i0cILbA2Ml+W6GDk4JARMJFrf WnUxcnEICbQxSTT8PM3UxcgJ5GxklPjw2AYicZVJ4tvGVYwgCRYBVYmTO8+zgdhsAioSDd2X mUFsEQFFiWer5rKA2MwCphIfPt4DqxEW8JJ4PGUpC8gyXqBlM1YJQsxcySixYdY0sBpeAUGJ kzOfQPVqSdz495IJpJ5ZQFpi+T8OEJNTwFpixe1okApRAWWJhhkPmCcwCsxC0jwLSfMshOYF jMyrGGVTcqt0cxMzc4pTk3WLkxPz8lKLdM31cjNL9FJTSjcxgoPTRWUHY3eP9yFGAQ5GJR5e ibLXEUKsiWXFlbmHGCU5mJREeQNmAoX4kvJTKjMSizPii0pzUosPMUpwMCuJ8DpEv4kQ4k1J rKxKLcqHSUlzsCiJ84prNEYICaQnlqRmp6YWpBbBZGU4OJQkeKUSgBoFi1LTUyvSMnNKENJM HJwgw3mAhs+IBxleXJCYW5yZDpE/xajL8W7ph/dMQix5+XmpUuK8XiBFAiBFGaV5cHNASUUi e3/NK0ZxoLeEeQ+CrOMBJiS4Sa+AljABLTmz6yXIkpJEhJRUA+N8J9cDnJPVbJlVD2RwbD32 9N2rL6eSJr9OjTjUtL39xnTXc0tWXFnTvXt9wJVamdw7u/5nPNxxUK/332G2nZwLp3Qa2Bl1 ZgsteC7F7Zmwc2IP294H7rHf5671UrwX2VBh8iLh1CMFp8u97S/3NO3zn2bm3/rNxIbhZ9q6 V3vuZyZs61nqzXBEiaU4I9FQi7moOBEAQQ+syQUDAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/EoNXketHYIfOF_6HKTBg1OSdofU>
Subject: Re: [kitten] Review of draft-ietf-kitten-krb-service-discovery-00
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Apr 2017 04:53:08 -0000

On Mon, Apr 03, 2017 at 12:32:55PM -0400, Greg Hudson wrote:
> On 03/30/2017 02:51 PM, Matt Rogers wrote:
> >> * RFC 7553 is informational and this document is standards track, which
> >>   is a down reference (see RFC 3967).  Also, RFC 7553 contains ambiguous
> >>   guidance about URI records labels which some readers have interpreted
> >>   as being incompatible with our use of labels.  I think at one point we
> >>   received advice to reference the IANA registration of the URI record
> >>   type instead of RFC; unfortunately I do not know the mechanics of that
> >>   kind of reference.
> 
> > The IANA registration entry refers to RFC 7553:
> > https://www.iana.org/assignments/dns-parameters/dns-parameters.xhtml
> > Perhaps it should just be an informative reference instead.
> 
> There is also a "completed template" in the IANA assignment:
> 
> https://www.iana.org/assignments/dns-parameters/URI/uri-completed-template
> 
> I hadn't read this before.  It says (in section E):
> 
>   The URI RR has service information encoded in its ownername.  In
>   order to encode the service for a specific owner name one uses
>   service parameters.  Valid service parameters used are either
>   Enumservice Registrations registered by IANA, or prefixes used
>   for the SRV resource record.

It's not entirely clear just how binding this is on consumers,
though I do think IANA consults this sort of thing sometimes.

> which seems like a slightly more restrictive statement than the one in
> RFC 7553.  We may need some guidance from the chairs or ADs on the

Given how similar it is to the text in the RFC, I think we are
forced to conclude that the RFC takes precedence, possibly due to
last-minute changes.  (That is, that someone got sloppy at some
point.  But the RFC text is what has IETF consensus, and is thus
preferred.)  The relevant text was added in draft-faltstrom-uri-11,
FWIW.

We can call this issue out in the shepherd writeup for IESG
attention, too.  Making a final call is "above our pay grade" :)

> mechanics of moving forward here.  Simply making the reference
> informative doesn't seem sufficient, as the URI RR type is fundamental
> to this standard.
> 
> (To be clear, I think what we're doing ought to be fine, and that it's
> generally pointless to include a transport label in a URI record owner
> name like one would in a SRV owner name.  The question is one of
> conformance with the pre-existing standard, not practicality.)

It is correct to leave the reference as normative; the downref can
be called out during IETF last call (though, IIRC, some recent-ish
changes in policy do not mandate it quite as strongly as it used to
be).

> >> * Similarly, MS-KKDCP is in the normative references section, and is not
> >>   a standards-track IETF document.  It is only used as the reference in
> >>   the initial contents of the transport registry, so perhaps it can just
> >>   be an informative reference.
> >>
> > I'll make this an informative reference.
> 
> The MS-KKDCP reference is obvious controlling when using the kkdcp
> transport.  Since this is just an initial transport registration, it may
> be okay to use an informative reference.

I believe an informative reference is fine for this document, as
that spec is not needed in order to use the discovery protocol
itself.  (It's needed to use the results of discovery, but that's
out of scope.)

> >> * The wording here seems too general.  I think we want to specifically
> >>   say that URI records should be preferred over SRV records.
> 
> > How about: "Clients that support service discovery through both URI
> > and SRV records SHOULD perform the URI discovery first. If no URI
> > record is found, the client MAY then attempt SRV discovery."
> 
> Sure.
> 
> There is an argument for a MUST here.  DNS administrators will commonly
> want to set up both URI and SRV records for a realm, and the behavior of
> trying URI first may be important (e.g. if the URI record includes a
> kkdcp entry).

Note that the MUST only applies for implementations that claim to
comply with <RFC-to-be>, so it is not as strong a requirement as it
might seem at first.

> >> * The reference here is "TBD".  Is there a plan?  Is the reference
> >>   supposed to be to this RFC once a number is assigned?
> >>
> > 
> > It should be changed to the assigned number, yes. It was suggested
> > that instead of TBD we use [This Document], which I think is the
> > convention for this kind of reference.
> 
> That seems okay.  There might also need to be an RFC editor guidance
> section pointing out the need for a substitution there.  For instance,
> in https://tools.ietf.org/html/draft-ietf-krb-wg-crypto-07 see the
> "Notes to RFC Editor" section at the end.

Yes, "[this document]" is an accepted form.  I don't expect a
specific RFC Editor note is needed for this sort of usage.

-Ben


From nobody Tue Apr 11 08:05:30 2017
Return-Path: <mrogers@redhat.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1570712EAB4 for <kitten@ietfa.amsl.com>; Tue, 11 Apr 2017 08:05:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.421
X-Spam-Level: 
X-Spam-Status: No, score=-1.421 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nXI44KqhRXGi for <kitten@ietfa.amsl.com>; Tue, 11 Apr 2017 08:05:21 -0700 (PDT)
Received: from mail-qt0-f170.google.com (mail-qt0-f170.google.com [209.85.216.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3BF3312EAB8 for <kitten@ietf.org>; Tue, 11 Apr 2017 08:05:06 -0700 (PDT)
Received: by mail-qt0-f170.google.com with SMTP id n46so58270820qta.2 for <kitten@ietf.org>; Tue, 11 Apr 2017 08:05:06 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to :content-transfer-encoding; bh=e7eJ02idGih2kxc5pZloiURkAYbkrL06z/4his4gDL8=; b=AvDkVTsXsppy+ql2DRtAt+u3r2Ywr6I1IMvLnQBgOX/f7kxcqeIyQEf5J99Rl+jbwc zB/6JqZM454fXB2UQ8xAzBLRiVh97o0U2w2l/XOYqmdXwdnGUASWTZEvmfQTzOcMzPke znExJsXMwsNVpyylt5SITBPIDnlb96z8im4nxnCod7cTuSqJiAb2aPRdMFyeLYIk7IXU Pv0xgU+h86A25xp26PkBZm1aFzuw4qigIYhjUQWrOx7OxkAJ4mVUuSQ6DaT3NcDUb2kX izZ9tvQSowidiJF8fv9CXmltjbzYGXaKnGHnfygZl/djy1dyG/5gC6zuUit7wW4BdYPf pkZA==
X-Gm-Message-State: AN3rC/74j6BSw0zabkTAZsbTQHRdfTg9wrbKC94yWcea+rtwbG9aqLq2TpAFG9fr1JOzGPLKmvirX6DWoE6ulmMF
X-Received: by 10.237.37.24 with SMTP id v24mr6299634qtc.290.1491923105280; Tue, 11 Apr 2017 08:05:05 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.12.175.145 with HTTP; Tue, 11 Apr 2017 08:04:34 -0700 (PDT)
From: Matt Rogers <mrogers@redhat.com>
Date: Tue, 11 Apr 2017 11:04:34 -0400
Message-ID: <CAAeFVfz8XqKn6YLzV_=khrxniPsGAR+=7AzEwLv2dHQEwR5guw@mail.gmail.com>
To: iesg-secretary@ietf.org, ekr@rtfm.com, kitten@ietf.org
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/0RPCmxZAbq_pqSokqD06LsCCNt0>
Subject: [kitten] Document Shepherd Write-Up for draft-ietf-kitten-rfc5653bis
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Apr 2017 15:05:22 -0000

Summary:
Matt Rogers is the Document Shepherd. Eric Rescorla is the Responsible
Area Director.

This document is a Proposed Standard to update RFC 5653  (Generic
Security Service API Version 2 : Java Bindings Update). This document
addresses a flaw in RFC 5653 by extending the GSSException class with
an error token, as well as removing the specification of stream-based
GSSContext methods.

Review and Consensus:
There is consensus among the WG for this document, and it saw active
discussion and review by WG members. As a =E2=80=98bis=E2=80=99 document, a=
ll errata
have been considered. Concerns about the design of the stream-based
GSSContext methods were brought up and addressed during the WG Last
Call process and there was agreement on their removal from the
document.

Intellectual Property:
There are no intellectual property disclosures against this document,
and all authors have confirmed compliance with BCPs 78 and 79.

Note:
The idnits check mentions an obsoleted normative reference to RFC
2853, which is the predecessor to RFC 5653. The references are used
only during explanation of the differences since RFC 2853.


From nobody Tue Apr 11 19:39:30 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 58A74126CD8 for <kitten@ietfa.amsl.com>; Tue, 11 Apr 2017 19:39:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.802
X-Spam-Level: 
X-Spam-Status: No, score=-2.802 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2k9PSHU1BVOW for <kitten@ietfa.amsl.com>; Tue, 11 Apr 2017 19:39:27 -0700 (PDT)
Received: from dmz-mailsec-scanner-3.mit.edu (dmz-mailsec-scanner-3.mit.edu [18.9.25.14]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2284C126C7A for <kitten@ietf.org>; Tue, 11 Apr 2017 19:39:27 -0700 (PDT)
X-AuditID: 1209190e-b17ff70000003afa-59-58ed935d22cc
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id EF.7E.15098.D539DE85; Tue, 11 Apr 2017 22:39:26 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id v3C2dOsZ008890 for <kitten@ietf.org>; Tue, 11 Apr 2017 22:39:25 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v3C2dKsv018394 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Tue, 11 Apr 2017 22:39:24 -0400
Date: Tue, 11 Apr 2017 21:39:20 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: kitten@ietf.org
Message-ID: <20170412023920.GB30306@kduck.kaduk.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.6.1 (2016-04-27)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrDIsWRmVeSWpSXmKPExsUixG6nohs3+W2EwdW7jBZHN69icWD0WLLk J1MAYxSXTUpqTmZZapG+XQJXxqVl0gWreSqu7Z3N0sD4h7OLkZNDQsBE4tK/NexdjFwcQgJt TBJnD39ghHCOM0p8f9/HCuG8ZpJYtPYZE0gLi4CqRPf2d6wgNpuAikRD92VmEFtEQFhi99Z3 YLawgK3ErFl3wWp4gVZ8+f+DEcIWlDg58wkLiM0soCVx499LoJkcQLa0xPJ/HCBhUQFliYYZ D5gnMPLOQtIxC0nHLISOBYzMqxhlU3KrdHMTM3OKU5N1i5MT8/JSi3SN9XIzS/RSU0o3MYIC iVOSbwfjpAbvQ4wCHIxKPLweZ95ECLEmlhVX5h5ilORgUhLlvazwNkKILyk/pTIjsTgjvqg0 J7X4EKMEB7OSCG+LC1CONyWxsiq1KB8mJc3BoiTOK67RGCEkkJ5YkpqdmlqQWgSTleHgUJLg /ToRqFGwKDU9tSItM6cEIc3EwQkynAdouPskkOHFBYm5xZnpEPlTjIpS4rxBIAkBkERGaR5c LyjSJbL317xiFAd6RZh3PkgVDzBJwHW/AhrMBDT4zK6XIINLEhFSUg2MbB/5pFa7rn/o1rFL 4NbMKa1urydMvNtTI9u54qGaaF9vfq2uEVf0m/379HWPeXlcq02yrfu+yGT9/KrXLTZK35T3 v4v2KM15uts36ciZgFs6fCe/fTN5E214KprbdMtLhZnrHtmI/E9YM+luhdmF+ZuMjxmJn5R+ fsKJ97TvZbW4r6oX8tROKLEUZyQaajEXFScCAKXTl1PPAgAA
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/IbV_Tqg7T9TsPzDiMLeWlxfdLZw>
Subject: [kitten] Review of draft-ietf-kitten-krb-service-discovery-00
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 12 Apr 2017 02:39:28 -0000

In addition to the other thread, I have a few comments from my
read-through, in addition to the issues already raised by others.

I'm inclined to agree with Greg that specifying a discovery scheme
for a protocol that is not well-specified/interoperable is probably
not worth doing; there was some IESG pushback recently as OAuth was
trying to get an "amr" registry created (similar to our
authentication indicator, in a rough sense), which listed some
schemes like "hotp" without any explanation of how they would work.

We very informally bring in the concept of a "master server" in
section 4.2.1; this is not a term that commonly appears in kerberos
RFCs, so it may be worth indicating that it is a term being newly
defined (or avoiding it altogether).

Listing kitten@ietf.org as a Designated Expert is unwise; the
expert(s) should be named individuals selected by the IESG.  The
document creating the registry ought to give the IESG some guidance
as to who is qualified to be such an expert, though.  The
instructions to the expert can certainly include a three-week period
of public review on the kitten list, though.

It's sometimes odd to have the IANA considerations be the first
place that certain concepts come up in the document.  It may be
clearer to have a table for them in the main body of the text, and
the IANA considerations refer back to that table as being the
initial registry contents.

Something of a nit, but I thought that "MS-KKDCPP" was the
established abbreviation for that specifciation (i.e., with two
'P's).

-Ben


From nobody Thu Apr 13 12:30:17 2017
Return-Path: <mrogers@redhat.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 21EAD128D69 for <kitten@ietfa.amsl.com>; Thu, 13 Apr 2017 12:30:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.12
X-Spam-Level: 
X-Spam-Status: No, score=-2.12 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EKzp406YcxsP for <kitten@ietfa.amsl.com>; Thu, 13 Apr 2017 12:30:14 -0700 (PDT)
Received: from mail-qt0-f179.google.com (mail-qt0-f179.google.com [209.85.216.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9906313160F for <kitten@ietf.org>; Thu, 13 Apr 2017 12:30:13 -0700 (PDT)
Received: by mail-qt0-f179.google.com with SMTP id c45so53392368qtb.1 for <kitten@ietf.org>; Thu, 13 Apr 2017 12:30:13 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=gan/KGx+JdX7SjDt3Joo+u8SQmFgZlXMaCPfUR/pWYQ=; b=Lov9vTBhGcRlDxKoGsYjOM5a/xGt69xmIkchErtwEHa+JojKrCgbVpLq2ORtHPuxWa dtSCj46agSzjSczOEPSzb2W/1R1oAiIi/QF1R+9i4HKx47dltWmQBa5AE0nKWnYG9WPD dqsikbNwdUEdFXakIj8+2cpIdrIx+fnbF3bR0nLq8s621GgMEYLBsLAgysCnzClWYB35 rJyep5s0qsTWkGGGbvnPjGIyQjGTIQeCj6FmNPoBJjRg8OsH/PYm6gY0Pt0mbItNDx/X DhU3QTGN/pBGyPFEQJXnPaad/pIkb+4/oKFpwr9/aeTT8qPA1s4iCOGGbsqFBxQVaHvl Qb1w==
X-Gm-Message-State: AN3rC/5BkYoYkrnPw5hgF3BtUTkEArZeIxBDgf0O8x9qu6PskceA7qjh FrnhXgZTnYSf7a8kPeaMSuNwpdTNWHecxW8=
X-Received: by 10.200.52.232 with SMTP id x37mr3979735qtb.34.1492111812656; Thu, 13 Apr 2017 12:30:12 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.12.175.145 with HTTP; Thu, 13 Apr 2017 12:29:42 -0700 (PDT)
In-Reply-To: <20170412023920.GB30306@kduck.kaduk.org>
References: <20170412023920.GB30306@kduck.kaduk.org>
From: Matt Rogers <mrogers@redhat.com>
Date: Thu, 13 Apr 2017 15:29:42 -0400
Message-ID: <CAAeFVfyG5Aifpzry9Ha-Ddqbt93s7mJanWYar__kj2OJWa8BXg@mail.gmail.com>
To: Benjamin Kaduk <kaduk@mit.edu>
Cc: kitten@ietf.org
Content-Type: text/plain; charset=UTF-8
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/M9SFlktUjPnTBR7XvO9eWBJBPmo>
Subject: Re: [kitten] Review of draft-ietf-kitten-krb-service-discovery-00
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 13 Apr 2017 19:30:16 -0000

On Tue, Apr 11, 2017 at 10:39 PM, Benjamin Kaduk <kaduk@mit.edu> wrote:
> In addition to the other thread, I have a few comments from my
> read-through, in addition to the issues already raised by others.
>
> I'm inclined to agree with Greg that specifying a discovery scheme
> for a protocol that is not well-specified/interoperable is probably
> not worth doing; there was some IESG pushback recently as OAuth was
> trying to get an "amr" registry created (similar to our
> authentication indicator, in a rough sense), which listed some
> schemes like "hotp" without any explanation of how they would work.
>
Agreed, I am removing the text related to admin services.

> We very informally bring in the concept of a "master server" in
> section 4.2.1; this is not a term that commonly appears in kerberos
> RFCs, so it may be worth indicating that it is a term being newly
> defined (or avoiding it altogether).
>
The updated text for the master flag description should help clarify
(see below).

> Listing kitten@ietf.org as a Designated Expert is unwise; the
> expert(s) should be named individuals selected by the IESG.  The
> document creating the registry ought to give the IESG some guidance
> as to who is qualified to be such an expert, though.  The
> instructions to the expert can certainly include a three-week period
> of public review on the kitten list, though.
>

Looking at some existing IANA Considerations examples, I might suggest
the following:

8.  IANA Considerations

   This document establishes two registries [to be] managed by IANA, in
   accordance with [RFC5226].

   For registration requests the responsible IESG area director should
   appoint a Designated Expert.  The intention is that any allocation
   will be accompanied by a published RFC.  The Designated Expert will
   post a request to the KITTEN WG mailing list (or a successor
   designated by the Area Director) for comment and review, including an
   Internet-Draft.  Before a period of three weeks has passed, the
   Designated Expert will either approve or deny the registration
   request, publish a notice of the decision to the KITTEN WG mailing
   list or its successor, and inform IANA of its decision.  A denial
   notice must be justified by an explanation and, in the cases where it
   is possible, concrete suggestions on how the request can be modified
   so as to become acceptable.

> It's sometimes odd to have the IANA considerations be the first
> place that certain concepts come up in the document.  It may be
> clearer to have a table for them in the main body of the text, and
> the IANA considerations refer back to that table as being the
> initial registry contents.
>

I'm expanding on the master flag separately from the registry contents
and try to clarify its intent;

6.2.  Flags
...
6.2.1.  Master Flag

   The "m" flag indicates that the server is a "master".  The client
   SHOULD consider this server as one that might possess more up-to-date
   long-term key material, and use it as a fallback for errors that
   might result from out-of-date keys.
....
8.1.2.  Initial Registry Contents

   o Value: m
   o Description: Master flag
   o Reference: [This Document]

> Something of a nit, but I thought that "MS-KKDCPP" was the
> established abbreviation for that specifciation (i.e., with two
> 'P's).
>

The Microsoft documentation and others only refer to it as "MS-KKDCP".
Thanks again for your comments,

Matt


From nobody Fri Apr 21 15:25:33 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2ABE9127A91 for <kitten@ietfa.amsl.com>; Fri, 21 Apr 2017 15:25:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.222
X-Spam-Level: 
X-Spam-Status: No, score=-4.222 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8yR6A45U2auI for <kitten@ietfa.amsl.com>; Fri, 21 Apr 2017 15:25:31 -0700 (PDT)
Received: from dmz-mailsec-scanner-5.mit.edu (dmz-mailsec-scanner-5.mit.edu [18.7.68.34]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CF3FE1243FE for <kitten@ietf.org>; Fri, 21 Apr 2017 15:25:30 -0700 (PDT)
X-AuditID: 12074422-6efff700000048a0-02-58fa86d888a2
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by  (Symantec Messaging Gateway) with SMTP id E6.E8.18592.8D68AF85; Fri, 21 Apr 2017 18:25:29 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id v3LMPSKR011444 for <kitten@ietf.org>; Fri, 21 Apr 2017 18:25:28 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v3LMPOBj029928 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <kitten@ietf.org>; Fri, 21 Apr 2017 18:25:27 -0400
Date: Fri, 21 Apr 2017 17:25:24 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: kitten@ietf.org
Message-ID: <20170421222524.GE30306@kduck.kaduk.org>
References: <20170405045550.GJ30306@kduck.kaduk.org> <20170406023433.GX30306@kduck.kaduk.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20170406023433.GX30306@kduck.kaduk.org>
User-Agent: Mutt/1.6.1 (2016-04-27)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrMIsWRmVeSWpSXmKPExsUixG6nrnuz7VeEwb4OE4ujm1exODB6LFny kymAMYrLJiU1J7MstUjfLoEro2/ee/aCE5wV/6d0MzUwPmHvYuTkkBAwkdj3/CYjiC0k0MYk 0bdPr4uRC8g+zijx9vUCVgjnNZPEngNLwapYBFQltvZPZgKx2QRUJBq6LzOD2CICwhK7t74D s4UFNCWaH28CquHg4AXa0NJkCrEgXuLf7o2sIDavgKDEyZlPWEBsZgEtiRv/XoKVMwtISyz/ xwES5hQwlXjw/isbiC0qoCzRMOMB8wRG/llIumch6Z6F0L2AkXkVo2xKbpVubmJmTnFqsm5x cmJeXmqRrqlebmaJXmpK6SZGcNi5KO1gnPjP6xCjAAejEg/vCpZfEUKsiWXFlbmHGCU5mJRE eUN+/4wQ4kvKT6nMSCzOiC8qzUktPsQowcGsJMKrVw9UzpuSWFmVWpQPk5LmYFES5xXXaIwQ EkhPLEnNTk0tSC2CycpwcChJ8D5pBWoULEpNT61Iy8wpQUgzcXCCDOcBGq7QBjK8uCAxtzgz HSJ/ilFRSpzXH6RZACSRUZoH1wtKCxLZ+2teMYoDvSLMWwpSxQNMKXDdr4AGMwENPuv3A2Rw SSJCSqqBceKCzlz1QKa5BSsvLvPeU7iB3XKzFeORNQm9ys25klwPmvOOSCQx7vCzvrfY3epR 8mRGtawN68JmLQuYn7DO1WEtd8sc8Zi3pXKPy9YUX20Pz5P90rxk2aSYfv3Nq2SVONMfKBtV eyQUBz6y03cwmuC57phqXYBV0vuEp8n/SuW2vZyvVWGtxFKckWioxVxUnAgATXvK1OYCAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/QRBSRJzaxRy9xkUXymbOsNtUruE>
Subject: Re: [kitten] taking on new work?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 21 Apr 2017 22:25:32 -0000

On Wed, Apr 05, 2017 at 09:34:33PM -0500, Benjamin Kaduk wrote:
> On Tue, Apr 04, 2017 at 11:55:50PM -0500, Benjamin Kaduk wrote:
> > 
> > What do people currently feel are the top one or two highest
> > priority items for the WG to consider?  (Such items need not be
> > limited to the above list, of course; note that, e.g.,
> > draft-schmaus-kitten-sasl-ht-00 has recently appeared on the list of
> > related internet-drafts.)
> 
> To sum up today's traffic, it looks like SPAKE (Greg/Me/Nico's
> second tier) and GSS AEAD (Jeffrey/Nico) are the leaders, though of
> course it would be good to get input from more people.

Now that the input has died down and the chairs have had a chance to
confer, it seems we have consensus to adopt
draft-mccallum-kitten-krb-spake-preauth and reinvigorate attention
on draft-ietf-kitten-channel-bound-flag.

Authors, please submit a new version of
draft-mccallum-kitten-krb-spake-preauth as
draft-ietf-kitten-krb-spake-preauth at your convenience.

Everyone is encouraged to (re)review these documents, and those
interested in a TLS 1.3-related GSS mechanism are encouraged to
formulate such thoughts in the form of a draft.

Thanks,

Ben
for the chairs


From nobody Tue Apr 25 06:05:22 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: kitten@ietf.org
Delivered-To: kitten@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id E447812ECF0; Tue, 25 Apr 2017 06:05:02 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
Cc: kitten@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.50.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <149312550282.31812.14201802352411571075@ietfa.amsl.com>
Date: Tue, 25 Apr 2017 06:05:02 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/tRh2mpebVnMUZg_YefLTOZU2pyY>
Subject: [kitten] I-D Action: draft-ietf-kitten-sasl-saml-ec-15.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Apr 2017 13:05:03 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Common Authentication Technology Next Generation of the IETF.

        Title           : SAML Enhanced Client SASL and GSS-API Mechanisms
        Authors         : Scott Cantor
                          Simon Josefsson
	Filename        : draft-ietf-kitten-sasl-saml-ec-15.txt
	Pages           : 34
	Date            : 2017-04-24

Abstract:
   Security Assertion Markup Language (SAML) 2.0 is a generalized
   framework for the exchange of security-related information between
   asserting and relying parties.  Simple Authentication and Security
   Layer (SASL) and the Generic Security Service Application Program
   Interface (GSS-API) are application frameworks to facilitate an
   extensible authentication model.  This document specifies a SASL and
   GSS-API mechanism for SAML 2.0 that leverages the capabilities of a
   SAML-aware "enhanced client" to address significant barriers to
   federated authentication in a manner that encourages reuse of
   existing SAML bindings and profiles designed for non-browser
   scenarios.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-kitten-sasl-saml-ec/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-kitten-sasl-saml-ec-15
https://datatracker.ietf.org/doc/html/draft-ietf-kitten-sasl-saml-ec-15

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-kitten-sasl-saml-ec-15


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

