
From ben@nostrum.com  Mon Jul  1 11:57:26 2013
Return-Path: <ben@nostrum.com>
X-Original-To: xmpp@ietfa.amsl.com
Delivered-To: xmpp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 55FA511E823A for <xmpp@ietfa.amsl.com>; Mon,  1 Jul 2013 11:57:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.6
X-Spam-Level: 
X-Spam-Status: No, score=-102.6 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, SPF_PASS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5u0LBZnFUCRa for <xmpp@ietfa.amsl.com>; Mon,  1 Jul 2013 11:57:25 -0700 (PDT)
Received: from shaman.nostrum.com (nostrum-pt.tunnel.tserv2.fmt.ipv6.he.net [IPv6:2001:470:1f03:267::2]) by ietfa.amsl.com (Postfix) with ESMTP id 2D48911E822F for <xmpp@ietf.org>; Mon,  1 Jul 2013 11:57:25 -0700 (PDT)
Received: from [172.20.10.7] (mobile-166-147-071-202.mycingular.net [166.147.71.202]) (authenticated bits=0) by shaman.nostrum.com (8.14.3/8.14.3) with ESMTP id r61IvNEj072221 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO) for <xmpp@ietf.org>; Mon, 1 Jul 2013 13:57:24 -0500 (CDT) (envelope-from ben@nostrum.com)
From: Ben Campbell <ben@nostrum.com>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Message-Id: <18F7FEFD-51EA-4898-B71D-AA45429EEE4A@nostrum.com>
Date: Mon, 1 Jul 2013 13:57:18 -0500
To: XMPP Group <xmpp@ietf.org>
Mime-Version: 1.0 (Mac OS X Mail 6.5 \(1508\))
X-Mailer: Apple Mail (2.1508)
Received-SPF: pass (shaman.nostrum.com: 166.147.71.202 is authenticated by a trusted mechanism)
Subject: [xmpp] No XMPP Meeting in Berlin
X-BeenThere: xmpp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: XMPP Working Group <xmpp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/xmpp>, <mailto:xmpp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/xmpp>
List-Post: <mailto:xmpp@ietf.org>
List-Help: <mailto:xmpp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Jul 2013 18:57:26 -0000

Hi Everyone,

After consulting with the editors of the XMPP chartered work items, the =
chairs have decided to cancel the XMPP meeting for Berlin. We apologize =
for any inconvenience caused by the change.

However, we strongly encourage any members of the XMPP community present =
to attend the PKIX over Secure HTTP (POSH) BoF, since this is likely to =
be important for our Server Connection Sharing/Domain Name Assertion =
work in XMPP.

Thanks!

Ben.=20



From mamille2@cisco.com  Thu Jul 11 06:09:53 2013
Return-Path: <mamille2@cisco.com>
X-Original-To: xmpp@ietfa.amsl.com
Delivered-To: xmpp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4FC0211E812E for <xmpp@ietfa.amsl.com>; Thu, 11 Jul 2013 06:09:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.599
X-Spam-Level: 
X-Spam-Status: No, score=-10.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id R6znODCl8BBN for <xmpp@ietfa.amsl.com>; Thu, 11 Jul 2013 06:09:49 -0700 (PDT)
Received: from rcdn-iport-3.cisco.com (rcdn-iport-3.cisco.com [173.37.86.74]) by ietfa.amsl.com (Postfix) with ESMTP id B586321F9F20 for <xmpp@ietf.org>; Thu, 11 Jul 2013 06:09:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=9900; q=dns/txt; s=iport; t=1373548188; x=1374757788; h=from:to:cc:subject:date:message-id:references: mime-version; bh=uvOLkU6cEvuNoqSvhLeYTVxM8jzFcvHsVkU2cO7hBQw=; b=HvIVd6R1wXI6AV5QON32IOhS6v0qMUC9+R+MW2BuVBbGVDDTu76jjvQI CatwsmEPoVR1rLAISvzX9vpC4xri7ZgZNbBrqUqlMrpRPD0hz5vn9tJ7r Lemk0GLyJdZaJX1OKxbrdBr55dYZIx/xb6MSdbaSeBcUJR4MuaLnX9VCA Y=;
X-Files: smime.p7s : 4136
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: Ag0FAJid3lGtJV2d/2dsb2JhbABRCYMJMk3BUIEGFnSCIwEBAQMBSSoGBQcEAgEZAwEBAQEKHQcCMBQJCAIECgQFCAaHewYMtzSOJoEKBhAKEQsCA4MAbAOQDoEth0iQIYFYgTmCKA
X-IronPort-AV: E=Sophos;i="4.87,1043,1363132800";  d="p7s'?scan'208";a="233573517"
Received: from rcdn-core-6.cisco.com ([173.37.93.157]) by rcdn-iport-3.cisco.com with ESMTP; 11 Jul 2013 13:09:47 +0000
Received: from xhc-aln-x08.cisco.com (xhc-aln-x08.cisco.com [173.36.12.82]) by rcdn-core-6.cisco.com (8.14.5/8.14.5) with ESMTP id r6BD9lAF016141 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Thu, 11 Jul 2013 13:09:47 GMT
Received: from xmb-aln-x11.cisco.com ([169.254.6.51]) by xhc-aln-x08.cisco.com ([173.36.12.82]) with mapi id 14.02.0318.004; Thu, 11 Jul 2013 08:09:47 -0500
From: "Matt Miller (mamille2)" <mamille2@cisco.com>
To: "<xmpp@ietf.org> Group" <xmpp@ietf.org>
Thread-Topic: Problems with draft-miller-xmpp-e2e [WAS: [Standards] Updated Yabasta Protocol (E2E-related)]
Thread-Index: AQHOfjfqBUeXs7ErtE2yPaxw8EVu4g==
Date: Thu, 11 Jul 2013 13:09:46 +0000
Message-ID: <BF7E36B9C495A6468E8EC573603ED941152B1B4F@xmb-aln-x11.cisco.com>
References: <1693EFE1FD641C42A0D542FCBC732DE6BDE5BA3C@EX3.YODA.UTOPIA.LOCAL>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [10.129.24.90]
Content-Type: multipart/signed; boundary="Apple-Mail=_C49A6B86-81DB-4BCC-B8B9-5D73576ECDBB"; protocol="application/pkcs7-signature"; micalg=sha1
MIME-Version: 1.0
Cc: Peter Waher <Peter.Waher@clayster.com>
Subject: [xmpp] Problems with draft-miller-xmpp-e2e [WAS: [Standards] Updated Yabasta Protocol (E2E-related)]
X-BeenThere: xmpp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: XMPP Working Group <xmpp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/xmpp>, <mailto:xmpp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/xmpp>
List-Post: <mailto:xmpp@ietf.org>
List-Help: <mailto:xmpp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Jul 2013 13:09:53 -0000

--Apple-Mail=_C49A6B86-81DB-4BCC-B8B9-5D73576ECDBB
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

Forwarding to the proper discussion venue...

Begin forwarded message:

> From: Peter Waher <Peter.Waher@clayster.com>
> Subject: FW: [Standards] Updated Yabasta Protocol (E2E-related)
> Date: June 27, 2013 1:59:40 PM MDT
> To: "Matt Miller (mamille2@cisco.com)" <mamille2@cisco.com>
>=20
> Hello Matt
>=20
> Anything you would like to comment on, on the standards list?
>=20
> Sincerely,
> Peter Waher
>=20
> -----Original Message-----
> From: Jon Kristensen [mailto:info@jonkri.com]=20
> Sent: den 27 juni 2013 15:30
> To: Peter Waher
> Cc: XMPP Standards
> Subject: Re: [Standards] Updated Yabasta Protocol (E2E-related)
>=20
> Hi Peter, and thank you for your response!
>=20
> These are the problems of the draft as I understand it.
>=20
> It does not offer perfect forward secrecy, as the compromise of a =
private key would unlock all of the session keys protected by the =
corresponding public key.
>=20
> It also does not allow for anonymity (neither weak or strong), as the =
public key is being sent in the clear.
>=20
> A Diffie-Hellman key exchange request model could be used to tackle =
these problems, provided that two levels of <keyreq /> requests can be =
used. I don't know if this is part of the indended usage of the draft, =
or whether or not it would actually work. It would be great to see, =
though! Has any work been done to accommodate this feature?
>=20
> I'm also a little concerned about the fact that the public keys is =
used to protect the session keys from a deniability perspective, but I =
haven't really thought that through enough yet. Maybe it's nothing...
>=20
> Thanks again!
>=20
> Jon
>=20
> On Thu, 2013-06-27 at 17:25 +0000, Peter Waher wrote:
>> Hello Jon
>>=20
>> Have you considered using the proposed draft for end-to-end =
encryption available at IETF?
>> http://tools.ietf.org/html/draft-miller-xmpp-e2e-06
>>=20
>> Sincerely,
>> Peter Waher
>>=20
>> -----Original Message-----
>> From: Jon Kristensen [mailto:info@jonkri.com]
>> Sent: den 26 juni 2013 14:16
>> To: standards@xmpp.org
>> Subject: [Standards] Updated Yabasta Protocol (E2E-related)
>>=20
>> Hello everyone!
>>=20
>> The OTR-inspired and end-to-end secure Yabasta protocol has received =
a significant update today. You can see the updated protocol at =
<https://github.com/jonkri/yabasta-protocol/>.
>>=20
>> The protocol now supports a higher degree of anonymity than it did=20
>> before. The public key is no longer automatically transferred in the=20=

>> authenticated key exchange (as is the case with the Off-the-Record=20
>> protocol). Instead, the key exchange only exposes a signature. Users=20=

>> can then perform various identity verification actions (such as
>> "challenges") to increase their trust in the remote peer before they =
reveal their public key. This is done so that clients can choose to =
consider their public keys a secret credential, and not automatically =
reveal their public keys to an active man-in-the-middle attacker.
>>=20
>> The protocol has also been made more flexible. Clients can now =
configure things like what prime numbers to use for the Diffie-Hellman =
calculations, as well as what cryptographic and signing algorithms to =
use. Other updates include a separation between the abstract method and =
the actual protocol implementation, various clean-ups, and additional =
explanations to make the document easier to understand.
>>=20
>> Feedback is more than welcome! :-)
>>=20
>> Thanks!
>>=20
>> Jon Kristensen
>>=20
>>=20
>=20
>=20
>=20
> -----
> No virus found in this message.
> Checked by AVG - www.avg.com
> Version: 2013.0.3345 / Virus Database: 3204/6445 - Release Date: =
06/27/13

- m&m

Matt Miller < mamille2@cisco.com >
Cisco Systems, Inc.


--Apple-Mail=_C49A6B86-81DB-4BCC-B8B9-5D73576ECDBB
Content-Disposition: attachment; filename="smime.p7s"
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMezCCBjQw
ggQcoAMCAQICAR4wDQYJKoZIhvcNAQEFBQAwfTELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0
Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxKTAn
BgNVBAMTIFN0YXJ0Q29tIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MB4XDTA3MTAyNDIxMDE1NVoX
DTE3MTAyNDIxMDE1NVowgYwxCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSsw
KQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFy
dENvbSBDbGFzcyAxIFByaW1hcnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQTCCASIwDQYJKoZIhvcN
AQEBBQADggEPADCCAQoCggEBAMcJg8zOLdgasSmkLhOrlr6KMoOMpohBllVHrdRvEg/q6r8jR+EK
75xCGhR8ToREoqe7zM9/UnC6TS2y9UKTpT1v7RSMzR0t6ndl0TWBuUr/UXBhPk+Kmy7bI4yW4urC
+y7P3/1/X7U8ocb8VpH/Clt+4iq7nirMcNh6qJR+xjOhV+VHzQMALuGYn5KZmc1NbJQYclsGkDxD
z2UbFqE2+6vIZoL+jb9x4Pa5gNf1TwSDkOkikZB1xtB4ZqtXThaABSONdfmv/Z1pua3FYxnCFmdr
/+N2JLKutIxMYqQOJebr/f/h5t95m4JgrM3Y/w7YX9d7YAL9jvN4SydHsU6n65cCAwEAAaOCAa0w
ggGpMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMB0GA1UdDgQWBBRTcu2SnODaywFc
fH6WNU7y1LhRgjAfBgNVHSMEGDAWgBROC+8apEBbpRdphzDKNGhD0EGu8jBmBggrBgEFBQcBAQRa
MFgwJwYIKwYBBQUHMAGGG2h0dHA6Ly9vY3NwLnN0YXJ0c3NsLmNvbS9jYTAtBggrBgEFBQcwAoYh
aHR0cDovL3d3dy5zdGFydHNzbC5jb20vc2ZzY2EuY3J0MFsGA1UdHwRUMFIwJ6AloCOGIWh0dHA6
Ly93d3cuc3RhcnRzc2wuY29tL3Nmc2NhLmNybDAnoCWgI4YhaHR0cDovL2NybC5zdGFydHNzbC5j
b20vc2ZzY2EuY3JsMIGABgNVHSAEeTB3MHUGCysGAQQBgbU3AQIBMGYwLgYIKwYBBQUHAgEWImh0
dHA6Ly93d3cuc3RhcnRzc2wuY29tL3BvbGljeS5wZGYwNAYIKwYBBQUHAgEWKGh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL2ludGVybWVkaWF0ZS5wZGYwDQYJKoZIhvcNAQEFBQADggIBAAqDCH14qywG
XLhjjF6uHLkjd02hcdh9hrw+VUsv+q1eeQWB21jWj3kJ96AUlPCoEGZ/ynJNScWy6QMVQjbbMXlt
UfO4n4bGGdKo3awPWp61tjAFgraLJgDk+DsSvUD6EowjMTNx25GQgyYJ5RPIzKKR9tQW8gGK+2+R
HxkUCTbYFnL6kl8Ch507rUdPPipJ9CgJFws3kDS3gOS5WFMxcjO5DwKfKSETEPrHh7p5shuuNktv
sv6hxHTLhiMKX893gxdT3XLS9OKmCv87vkINQcNEcIIoFWbP9HORz9v3vQwR4e3ksLc2JZOAFK+s
sS5XMEoznzpihEP0PLc4dCBYjbvSD7kxgDwZ+Aj8Q9PkbvE9sIPP7ON0fz095HdThKjiVJe6vofq
+n6b1NBc8XdrQvBmunwxD5nvtTW4vtN6VY7mUCmxsCieuoBJ9OlqmsVWQvifIYf40dJPZkk9YgGT
zWLpXDSfLSplbY2LL9C9U0ptvjcDjefLTvqSFc7tw1sEhF0n/qpA2r0GpvkLRDmcSwVyPvmjFBGq
Up/pNy8ZuPGQmHwFi2/14+xeSUDG2bwnsYJQG2EdJCB6luQ57GEnTA/yKZSTKI8dDQa8Sd3zfXb1
9mOgSF0bBdXbuKhEpuP9wirslFe6fQ1t5j5R0xi72MZ8ikMu1RQZKCyDbMwazlHiMIIGPzCCBSeg
AwIBAgIDBoRIMA0GCSqGSIb3DQEBBQUAMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRD
b20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzE4MDYG
A1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGllbnQgQ0EwHhcN
MTMwNDMwMjE1NDQyWhcNMTQwNTAyMDUzOTA0WjBbMRkwFwYDVQQNExBiN2F6NndOY0t0R3JtMEpF
MRswGQYDVQQDDBJtYW1pbGxlMkBjaXNjby5jb20xITAfBgkqhkiG9w0BCQEWEm1hbWlsbGUyQGNp
c2NvLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJbKBMsG+9UFTx9uq/bhhXgu
vJvO8z7cwKaqqwZhVf5z/kHFyCNijtmTOE+YXjA8mWR4aoBwB5SvGypI/cJUofJ+AlBTC4g+RMx/
K0Ab4/jQqTQz9CDzMOB+Wm+rt8ZJ7A8ZzOJmNDAsf/VvB8l2A1SQz1UsAixgH16NTr8SlblAXEKk
4hwpCudUiNjjQokqJ0H686UBKVorcZSgXaza8XMqGtJF/8mNhR9GQYi7Xht1ky+9LFOrto2daZto
KJRwMeVusVdHUeKEQSu7jztw8HchH3KEb7Q+r5X+hhDZoddfKE8d5eyPuhiZdrzv7OlNZ0fSLdx7
3AE3nx9/R5YlXucCAwEAAaOCAtgwggLUMAkGA1UdEwQCMAAwCwYDVR0PBAQDAgSwMB0GA1UdJQQW
MBQGCCsGAQUFBwMCBggrBgEFBQcDBDAdBgNVHQ4EFgQUxGd+/qrdVudHrIKkw5xOMY7eaLUwHwYD
VR0jBBgwFoAUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHQYDVR0RBBYwFIESbWFtaWxsZTJAY2lzY28u
Y29tMIIBTAYDVR0gBIIBQzCCAT8wggE7BgsrBgEEAYG1NwECAzCCASowLgYIKwYBBQUHAgEWImh0
dHA6Ly93d3cuc3RhcnRzc2wuY29tL3BvbGljeS5wZGYwgfcGCCsGAQUFBwICMIHqMCcWIFN0YXJ0
Q29tIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MAMCAQEagb5UaGlzIGNlcnRpZmljYXRlIHdhcyBp
c3N1ZWQgYWNjb3JkaW5nIHRvIHRoZSBDbGFzcyAxIFZhbGlkYXRpb24gcmVxdWlyZW1lbnRzIG9m
IHRoZSBTdGFydENvbSBDQSBwb2xpY3ksIHJlbGlhbmNlIG9ubHkgZm9yIHRoZSBpbnRlbmRlZCBw
dXJwb3NlIGluIGNvbXBsaWFuY2Ugb2YgdGhlIHJlbHlpbmcgcGFydHkgb2JsaWdhdGlvbnMuMDYG
A1UdHwQvMC0wK6ApoCeGJWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL2NydHUxLWNybC5jcmwwgY4G
CCsGAQUFBwEBBIGBMH8wOQYIKwYBBQUHMAGGLWh0dHA6Ly9vY3NwLnN0YXJ0c3NsLmNvbS9zdWIv
Y2xhc3MxL2NsaWVudC9jYTBCBggrBgEFBQcwAoY2aHR0cDovL2FpYS5zdGFydHNzbC5jb20vY2Vy
dHMvc3ViLmNsYXNzMS5jbGllbnQuY2EuY3J0MCMGA1UdEgQcMBqGGGh0dHA6Ly93d3cuc3RhcnRz
c2wuY29tLzANBgkqhkiG9w0BAQUFAAOCAQEAlDhXbGEI7lbqUcu5r2JHZaMsbRZda/99ZqODzWGX
0llou9jGccsAWDPPwRRe2+ROpXfH4cuJZElTcLDeZSp/qpXKhjYieFSX8+Ml9sKEj5UOSqQLyoLk
PtrIJV12Jk3nuG2Jc0UeEnGwK/aqtzy7+bfEVI0ziyVM2gChHh0RH74KyiwYWknbOTRIkZcz/ulE
DVFQp63uj6wfmDNvAUHBAdhKVqA1S/rfP1KcDZpf1NfvwXJibiqTRA6K1EOxTJOP41n/XdvHqHXL
RWL2xrOUI9/URANr/ok3OrsuZEMFnAAGefS1bWS/hFtUGVkHGiKEBbyDW7da2ULXbuC7umrQnzGC
A28wggNrAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkG
A1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRD
b20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGllbnQgQ0ECAwaESDAJBgUrDgMCGgUA
oIIBrzAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzA3MTExMzA5
NDhaMCMGCSqGSIb3DQEJBDEWBBQFmhw2kbPlLkr1Q5oFDNsnZOostTCBpQYJKwYBBAGCNxAEMYGX
MIGUMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2Vj
dXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3Mg
MSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGllbnQgQ0ECAwaESDCBpwYLKoZIhvcNAQkQAgsxgZeg
gZQwgYwxCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1
cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAx
IFByaW1hcnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBoRIMA0GCSqGSIb3DQEBAQUABIIBADuu
FNRyBJAY287TwZb5bOFukjSmEULEP2ed0f0pvtexQ1DYc9NKDkc4hdRjfl1QssKp8xPHIg7GJb2c
WK6XGdY76l3jRI5BhtcQpu9Wt28hKVMc2Cxtl8P+Nyf1uNLiqEkyymqJwma5lrP8X5lAN4wXeZKs
YA6OzLEqye/UK2IIDQ8y82JOyz+oFKt7fhA1CEtCxZZOZd/Qpk/E5TFkhMWlekRO3jz5PXk+G2CN
EGNOf7x9bBePM2TJRx5D8m/HIlAQn1697YLh1N19G3l/inTEW9jSnu3gnLhJfhqa5wePdZ8n+Vu2
ZrKKMJ1TVG/Df4EA1Gr6/Bp2s/v64E6gsJgAAAAAAAA=

--Apple-Mail=_C49A6B86-81DB-4BCC-B8B9-5D73576ECDBB--

From mamille2@cisco.com  Thu Jul 11 06:20:59 2013
Return-Path: <mamille2@cisco.com>
X-Original-To: xmpp@ietfa.amsl.com
Delivered-To: xmpp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 35A1521F9C11 for <xmpp@ietfa.amsl.com>; Thu, 11 Jul 2013 06:20:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.599
X-Spam-Level: 
X-Spam-Status: No, score=-10.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y-bHrxiPHwt2 for <xmpp@ietfa.amsl.com>; Thu, 11 Jul 2013 06:20:53 -0700 (PDT)
Received: from rcdn-iport-5.cisco.com (rcdn-iport-5.cisco.com [173.37.86.76]) by ietfa.amsl.com (Postfix) with ESMTP id 2839D21F9C05 for <xmpp@ietf.org>; Thu, 11 Jul 2013 06:20:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=8348; q=dns/txt; s=iport; t=1373548852; x=1374758452; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=UVqliQ7R5jjy5k+wYZlRKvNwjTTCOh2gbQEnXAooK8E=; b=EbshjEy3nvqp1n+iFDq1FxFwSdbJhGjiY89Iz8Y0pemmoPRKJR933f9x pf6hhys/CGlFMBJ7S8hCbucMOV/I2fHT6gja9f7z8400dIOa5Z1O6GjUd 8vJ+lRDqINZA7RnFBUJyHZQ5ZQQ3TqXisJq7Srh6ysx0RwkryNhfmzSyA c=;
X-Files: smime.p7s : 4136
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AgsFAJid3lGtJV2Y/2dsb2JhbABagwl/wVCBBhZ0giMBAQEDAXkMBAIBCBEEAQELHQcCMBQJCAIEDgUIBod7BrdAjzAxBwaDA2wDkA6BLZdpgViBOYIo
X-IronPort-AV: E=Sophos;i="4.87,1043,1363132800";  d="p7s'?scan'208";a="233558377"
Received: from rcdn-core-1.cisco.com ([173.37.93.152]) by rcdn-iport-5.cisco.com with ESMTP; 11 Jul 2013 13:20:51 +0000
Received: from xhc-rcd-x09.cisco.com (xhc-rcd-x09.cisco.com [173.37.183.83]) by rcdn-core-1.cisco.com (8.14.5/8.14.5) with ESMTP id r6BDKp5Y015436 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Thu, 11 Jul 2013 13:20:51 GMT
Received: from xmb-aln-x11.cisco.com ([169.254.6.51]) by xhc-rcd-x09.cisco.com ([173.37.183.83]) with mapi id 14.02.0318.004; Thu, 11 Jul 2013 08:20:51 -0500
From: "Matt Miller (mamille2)" <mamille2@cisco.com>
To: "<xmpp@ietf.org> Group" <xmpp@ietf.org>
Thread-Topic: Problems with draft-miller-xmpp-e2e [WAS: [Standards] Updated Yabasta Protocol (E2E-related)]
Thread-Index: AQHOfjl2+ccxs/bHNka4fpinYD/MVQ==
Date: Thu, 11 Jul 2013 13:20:51 +0000
Message-ID: <BF7E36B9C495A6468E8EC573603ED941152B1C3D@xmb-aln-x11.cisco.com>
References: <1693EFE1FD641C42A0D542FCBC732DE6BDE5BA3C@EX3.YODA.UTOPIA.LOCAL> <F930A551-9441-49BD-9564-FB1C43ADEA49@cisco.com>
In-Reply-To: <F930A551-9441-49BD-9564-FB1C43ADEA49@cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [10.129.24.90]
Content-Type: multipart/signed; boundary="Apple-Mail=_7768F4E1-A7E4-46DA-80B7-AB7CC9111823"; protocol="application/pkcs7-signature"; micalg=sha1
MIME-Version: 1.0
Cc: Peter Waher <Peter.Waher@clayster.com>
Subject: Re: [xmpp] Problems with draft-miller-xmpp-e2e [WAS: [Standards] Updated Yabasta Protocol (E2E-related)]
X-BeenThere: xmpp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: XMPP Working Group <xmpp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/xmpp>, <mailto:xmpp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/xmpp>
List-Post: <mailto:xmpp@ietf.org>
List-Help: <mailto:xmpp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Jul 2013 13:20:59 -0000

--Apple-Mail=_7768F4E1-A7E4-46DA-80B7-AB7CC9111823
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

Hello Jon,

>> -----Original Message-----
>> From: Jon Kristensen [mailto:info@jonkri.com]=20
>> Sent: den 27 juni 2013 15:30
>> To: Peter Waher
>> Cc: XMPP Standards
>> Subject: Re: [Standards] Updated Yabasta Protocol (E2E-related)
>>=20
>> Hi Peter, and thank you for your response!
>>=20
>> These are the problems of the draft as I understand it.
>>=20
>> It does not offer perfect forward secrecy, as the compromise of a =
private key would unlock all of the session keys protected by the =
corresponding public key.
>>=20

We talked about this on this list, and agreed that some form of "pure" =
DH agreement would be a way to address this, as well as remove the =
requirement for RSA keys.  I've been spending more energy on other =
tasks, and haven't had the time to work this out for myself.

As stated previously, suggested texts for draft-miller-xmpp-e2e are =
welcome.  If you can be in Berlin between 07/26 and 08/02, we can even =
sit down and hash something out face-to-face!

>> It also does not allow for anonymity (neither weak or strong), as the =
public key is being sent in the clear.
>>=20

See above.

>> A Diffie-Hellman key exchange request model could be used to tackle =
these problems, provided that two levels of <keyreq /> requests can be =
used. I don't know if this is part of the indended usage of the draft, =
or whether or not it would actually work. It would be great to see, =
though! Has any work been done to accommodate this feature?
>>=20

See above.

>> I'm also a little concerned about the fact that the public keys is =
used to protect the session keys from a deniability perspective, but I =
haven't really thought that through enough yet. Maybe it's nothing...
>>=20

I don't have empirical evidence to back this up, but seems to be there =
are at least as many people that want non-repudiation than there are =
people that want deniability.  While the two are mutually exclusive, I =
don't think it means it can't be done.

The draft uses JWK objects for keys.  As long as you can represent the =
DH agreement as a JWK, I don't see why you couldn't use that instead of =
an RSA public/private key pair.


- m&m

Matt Miller < mamille2@cisco.com >
Cisco Systems, Inc.


--Apple-Mail=_7768F4E1-A7E4-46DA-80B7-AB7CC9111823
Content-Disposition: attachment; filename="smime.p7s"
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMezCCBjQw
ggQcoAMCAQICAR4wDQYJKoZIhvcNAQEFBQAwfTELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0
Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxKTAn
BgNVBAMTIFN0YXJ0Q29tIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MB4XDTA3MTAyNDIxMDE1NVoX
DTE3MTAyNDIxMDE1NVowgYwxCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSsw
KQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFy
dENvbSBDbGFzcyAxIFByaW1hcnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQTCCASIwDQYJKoZIhvcN
AQEBBQADggEPADCCAQoCggEBAMcJg8zOLdgasSmkLhOrlr6KMoOMpohBllVHrdRvEg/q6r8jR+EK
75xCGhR8ToREoqe7zM9/UnC6TS2y9UKTpT1v7RSMzR0t6ndl0TWBuUr/UXBhPk+Kmy7bI4yW4urC
+y7P3/1/X7U8ocb8VpH/Clt+4iq7nirMcNh6qJR+xjOhV+VHzQMALuGYn5KZmc1NbJQYclsGkDxD
z2UbFqE2+6vIZoL+jb9x4Pa5gNf1TwSDkOkikZB1xtB4ZqtXThaABSONdfmv/Z1pua3FYxnCFmdr
/+N2JLKutIxMYqQOJebr/f/h5t95m4JgrM3Y/w7YX9d7YAL9jvN4SydHsU6n65cCAwEAAaOCAa0w
ggGpMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMB0GA1UdDgQWBBRTcu2SnODaywFc
fH6WNU7y1LhRgjAfBgNVHSMEGDAWgBROC+8apEBbpRdphzDKNGhD0EGu8jBmBggrBgEFBQcBAQRa
MFgwJwYIKwYBBQUHMAGGG2h0dHA6Ly9vY3NwLnN0YXJ0c3NsLmNvbS9jYTAtBggrBgEFBQcwAoYh
aHR0cDovL3d3dy5zdGFydHNzbC5jb20vc2ZzY2EuY3J0MFsGA1UdHwRUMFIwJ6AloCOGIWh0dHA6
Ly93d3cuc3RhcnRzc2wuY29tL3Nmc2NhLmNybDAnoCWgI4YhaHR0cDovL2NybC5zdGFydHNzbC5j
b20vc2ZzY2EuY3JsMIGABgNVHSAEeTB3MHUGCysGAQQBgbU3AQIBMGYwLgYIKwYBBQUHAgEWImh0
dHA6Ly93d3cuc3RhcnRzc2wuY29tL3BvbGljeS5wZGYwNAYIKwYBBQUHAgEWKGh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL2ludGVybWVkaWF0ZS5wZGYwDQYJKoZIhvcNAQEFBQADggIBAAqDCH14qywG
XLhjjF6uHLkjd02hcdh9hrw+VUsv+q1eeQWB21jWj3kJ96AUlPCoEGZ/ynJNScWy6QMVQjbbMXlt
UfO4n4bGGdKo3awPWp61tjAFgraLJgDk+DsSvUD6EowjMTNx25GQgyYJ5RPIzKKR9tQW8gGK+2+R
HxkUCTbYFnL6kl8Ch507rUdPPipJ9CgJFws3kDS3gOS5WFMxcjO5DwKfKSETEPrHh7p5shuuNktv
sv6hxHTLhiMKX893gxdT3XLS9OKmCv87vkINQcNEcIIoFWbP9HORz9v3vQwR4e3ksLc2JZOAFK+s
sS5XMEoznzpihEP0PLc4dCBYjbvSD7kxgDwZ+Aj8Q9PkbvE9sIPP7ON0fz095HdThKjiVJe6vofq
+n6b1NBc8XdrQvBmunwxD5nvtTW4vtN6VY7mUCmxsCieuoBJ9OlqmsVWQvifIYf40dJPZkk9YgGT
zWLpXDSfLSplbY2LL9C9U0ptvjcDjefLTvqSFc7tw1sEhF0n/qpA2r0GpvkLRDmcSwVyPvmjFBGq
Up/pNy8ZuPGQmHwFi2/14+xeSUDG2bwnsYJQG2EdJCB6luQ57GEnTA/yKZSTKI8dDQa8Sd3zfXb1
9mOgSF0bBdXbuKhEpuP9wirslFe6fQ1t5j5R0xi72MZ8ikMu1RQZKCyDbMwazlHiMIIGPzCCBSeg
AwIBAgIDBoRIMA0GCSqGSIb3DQEBBQUAMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRD
b20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzE4MDYG
A1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGllbnQgQ0EwHhcN
MTMwNDMwMjE1NDQyWhcNMTQwNTAyMDUzOTA0WjBbMRkwFwYDVQQNExBiN2F6NndOY0t0R3JtMEpF
MRswGQYDVQQDDBJtYW1pbGxlMkBjaXNjby5jb20xITAfBgkqhkiG9w0BCQEWEm1hbWlsbGUyQGNp
c2NvLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJbKBMsG+9UFTx9uq/bhhXgu
vJvO8z7cwKaqqwZhVf5z/kHFyCNijtmTOE+YXjA8mWR4aoBwB5SvGypI/cJUofJ+AlBTC4g+RMx/
K0Ab4/jQqTQz9CDzMOB+Wm+rt8ZJ7A8ZzOJmNDAsf/VvB8l2A1SQz1UsAixgH16NTr8SlblAXEKk
4hwpCudUiNjjQokqJ0H686UBKVorcZSgXaza8XMqGtJF/8mNhR9GQYi7Xht1ky+9LFOrto2daZto
KJRwMeVusVdHUeKEQSu7jztw8HchH3KEb7Q+r5X+hhDZoddfKE8d5eyPuhiZdrzv7OlNZ0fSLdx7
3AE3nx9/R5YlXucCAwEAAaOCAtgwggLUMAkGA1UdEwQCMAAwCwYDVR0PBAQDAgSwMB0GA1UdJQQW
MBQGCCsGAQUFBwMCBggrBgEFBQcDBDAdBgNVHQ4EFgQUxGd+/qrdVudHrIKkw5xOMY7eaLUwHwYD
VR0jBBgwFoAUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHQYDVR0RBBYwFIESbWFtaWxsZTJAY2lzY28u
Y29tMIIBTAYDVR0gBIIBQzCCAT8wggE7BgsrBgEEAYG1NwECAzCCASowLgYIKwYBBQUHAgEWImh0
dHA6Ly93d3cuc3RhcnRzc2wuY29tL3BvbGljeS5wZGYwgfcGCCsGAQUFBwICMIHqMCcWIFN0YXJ0
Q29tIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MAMCAQEagb5UaGlzIGNlcnRpZmljYXRlIHdhcyBp
c3N1ZWQgYWNjb3JkaW5nIHRvIHRoZSBDbGFzcyAxIFZhbGlkYXRpb24gcmVxdWlyZW1lbnRzIG9m
IHRoZSBTdGFydENvbSBDQSBwb2xpY3ksIHJlbGlhbmNlIG9ubHkgZm9yIHRoZSBpbnRlbmRlZCBw
dXJwb3NlIGluIGNvbXBsaWFuY2Ugb2YgdGhlIHJlbHlpbmcgcGFydHkgb2JsaWdhdGlvbnMuMDYG
A1UdHwQvMC0wK6ApoCeGJWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL2NydHUxLWNybC5jcmwwgY4G
CCsGAQUFBwEBBIGBMH8wOQYIKwYBBQUHMAGGLWh0dHA6Ly9vY3NwLnN0YXJ0c3NsLmNvbS9zdWIv
Y2xhc3MxL2NsaWVudC9jYTBCBggrBgEFBQcwAoY2aHR0cDovL2FpYS5zdGFydHNzbC5jb20vY2Vy
dHMvc3ViLmNsYXNzMS5jbGllbnQuY2EuY3J0MCMGA1UdEgQcMBqGGGh0dHA6Ly93d3cuc3RhcnRz
c2wuY29tLzANBgkqhkiG9w0BAQUFAAOCAQEAlDhXbGEI7lbqUcu5r2JHZaMsbRZda/99ZqODzWGX
0llou9jGccsAWDPPwRRe2+ROpXfH4cuJZElTcLDeZSp/qpXKhjYieFSX8+Ml9sKEj5UOSqQLyoLk
PtrIJV12Jk3nuG2Jc0UeEnGwK/aqtzy7+bfEVI0ziyVM2gChHh0RH74KyiwYWknbOTRIkZcz/ulE
DVFQp63uj6wfmDNvAUHBAdhKVqA1S/rfP1KcDZpf1NfvwXJibiqTRA6K1EOxTJOP41n/XdvHqHXL
RWL2xrOUI9/URANr/ok3OrsuZEMFnAAGefS1bWS/hFtUGVkHGiKEBbyDW7da2ULXbuC7umrQnzGC
A28wggNrAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkG
A1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRD
b20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGllbnQgQ0ECAwaESDAJBgUrDgMCGgUA
oIIBrzAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzA3MTExMzIw
NTJaMCMGCSqGSIb3DQEJBDEWBBQM6lHYYslGgFcrhl2rqv7JNFkDYjCBpQYJKwYBBAGCNxAEMYGX
MIGUMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2Vj
dXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3Mg
MSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGllbnQgQ0ECAwaESDCBpwYLKoZIhvcNAQkQAgsxgZeg
gZQwgYwxCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1
cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAx
IFByaW1hcnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBoRIMA0GCSqGSIb3DQEBAQUABIIBAHjH
6ulr0ZP1HfITiw8PhcYSSJ5bMphGwKnyskpjozcSEKOTOwjIWtINjUqAZdlH/hGRn9OaoeNzFYQh
PEUCKzr3oN+Sl7fZlPq1TPGHajPOQz6N6isO3yMpXj3/NmUHCX8LLVA7jGTXZYzDH8eAE3VbEJea
MPhCsvkkxujM6+o/XgOC/vyX5R1bcUGgF22JgVzMHyUNNW9wr45SF6jmwm8OIfb3VF/lVAwGczeC
9c5dlpmmATBI1ZI1CuzVvYCmTQEaMx9wylcXhg3mFTBLcIqTH8nzUzqWja5SPUXvqo9SLGyk32Zl
5y/yrW/OU/AgAdBQf1QRfvJtIx0QYwkTNKAAAAAAAAA=

--Apple-Mail=_7768F4E1-A7E4-46DA-80B7-AB7CC9111823--

From k.i.smith@gmail.com  Sun Jul 14 09:24:16 2013
Return-Path: <k.i.smith@gmail.com>
X-Original-To: xmpp@ietfa.amsl.com
Delivered-To: xmpp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BFC4D11E812D for <xmpp@ietfa.amsl.com>; Sun, 14 Jul 2013 09:24:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.978
X-Spam-Level: 
X-Spam-Status: No, score=-1.978 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, NO_RELAYS=-0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JL6DA9fmeJOK for <xmpp@ietfa.amsl.com>; Sun, 14 Jul 2013 09:24:16 -0700 (PDT)
Received: from mail-we0-x22a.google.com (mail-we0-x22a.google.com [IPv6:2a00:1450:400c:c03::22a]) by ietfa.amsl.com (Postfix) with ESMTP id 31D7911E812B for <xmpp@ietf.org>; Sun, 14 Jul 2013 09:24:16 -0700 (PDT)
Received: by mail-we0-f170.google.com with SMTP id w57so9546492wes.15 for <xmpp@ietf.org>; Sun, 14 Jul 2013 09:24:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:reply-to:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; bh=U36fTyZ4C3UWAwH83Vu7kDnbjc5pw8F3rpIt1wjEd/E=; b=zcmhDYc+leyCBonVkgq9k/x2kIbgcZXWXQv1FrIwIixFFENFaVN6zp5p5ExeeH3/ii lUz1/K4Z+jXIWM/nGw1GFOgneKj2i5h1j2tA9GMZBQ7ZDRG/mvgA9LDPQEfcoCgPpdEO lUJig7hdsoO7/qWM23vYEmYEzAatq0sLcA92qWQ2bhU/2iB50KcIFGuaqFiFYX78I1LR T8jdILrubXedm6S5U6QqsVAAE7goL9+MwZt6QoL/q58PFLq4faUPxKK6SPW5C42MdKZh OL4O5MfeQw8IruDmBv/d9rfp8Y8bdv3WGhQW83TFkP/ruQk73biX7BuRl4k5WAVvU0Mx bKPQ==
MIME-Version: 1.0
X-Received: by 10.194.58.239 with SMTP id u15mr29163282wjq.87.1373819055072; Sun, 14 Jul 2013 09:24:15 -0700 (PDT)
Sender: k.i.smith@gmail.com
Received: by 10.216.70.200 with HTTP; Sun, 14 Jul 2013 09:24:15 -0700 (PDT)
In-Reply-To: <516DDF85.5020700@stpeter.im>
References: <516DDF85.5020700@stpeter.im>
Date: Sun, 14 Jul 2013 17:24:15 +0100
X-Google-Sender-Auth: RxM-8C0ddoewKpm-VwmfBe6Ribc
Message-ID: <CAOb_FnwEh2FqQwRBJDdLOrXE572d0zZr9MHtJEMaHS=y5frnMA@mail.gmail.com>
From: Kevin Smith <kevin@kismith.co.uk>
To: Peter Saint-Andre <stpeter@stpeter.im>
Content-Type: text/plain; charset=ISO-8859-1
Cc: XMPP <xmpp@ietf.org>
Subject: Re: [xmpp] 6122bis: leading and trailing whitespace
X-BeenThere: xmpp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: kevin@kismith.co.uk
List-Id: XMPP Working Group <xmpp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/xmpp>, <mailto:xmpp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/xmpp>
List-Post: <mailto:xmpp@ietf.org>
List-Help: <mailto:xmpp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 14 Jul 2013 16:24:16 -0000

On Wed, Apr 17, 2013 at 12:32 AM, Peter Saint-Andre <stpeter@stpeter.im> wrote:
>        the ASCII space character at the beginning or end of a nickname)
>        MUST be removed (e.g., "stpeter " is mapped to "stpeter").
>
> It seems like good advice in general for resourceparts. Does anyone have objections to adding it?

Not I.

/K

From info@jonkri.com  Sun Jul 14 10:09:28 2013
Return-Path: <info@jonkri.com>
X-Original-To: xmpp@ietfa.amsl.com
Delivered-To: xmpp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6D9B021F9D40 for <xmpp@ietfa.amsl.com>; Sun, 14 Jul 2013 10:09:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level: 
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hTXh2TYoKZKa for <xmpp@ietfa.amsl.com>; Sun, 14 Jul 2013 10:09:18 -0700 (PDT)
Received: from mail-lb0-f193.google.com (mail-lb0-f193.google.com [209.85.217.193]) by ietfa.amsl.com (Postfix) with ESMTP id 0353421F9DDE for <xmpp@ietf.org>; Sun, 14 Jul 2013 10:09:17 -0700 (PDT)
Received: by mail-lb0-f193.google.com with SMTP id z5so2186619lbh.0 for <xmpp@ietf.org>; Sun, 14 Jul 2013 10:09:15 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=date:from:to:cc:subject:message-id:in-reply-to:references:x-mailer :mime-version:content-type:content-transfer-encoding :x-gm-message-state; bh=sWOq9WnzLIMCTzGUSGWHyG1KVINqv8JbKSqz+4o1WYY=; b=DJHQM1VfdTftTW0qiPYre21o/fwaYrArpwlS05IMz22W7i4T+kepyfZbCoSp9VBHIa FsFpoMEDP6neUEEZoxyEOYl8HlWfEbI9FBT803DCqEgAZXo06XUXjpTt0eVsl7gBVzL2 D7s918+6ZXX8VDOEF/lntL4IE+LIc60ouhAWHacJn0yg9HQnwtLPTmNZvZ40EfASb8ZJ aXYgfvQhOk9gvd2v58CbfNAb/qOYnbgb5tir4MOhC3lXjzhAY8aFgoiqCYBbFm2jJBHf ElzuRxw5L30BIhL4MYmGJEBS6JQchp+RTMfrW2zTo6pY0p/lYdM6vUaWzVIgh63ybjaC zGhA==
X-Received: by 10.112.54.161 with SMTP id k1mr22858568lbp.21.1373821755420; Sun, 14 Jul 2013 10:09:15 -0700 (PDT)
Received: from localhost.localdomain ([94.234.184.201]) by mx.google.com with ESMTPSA id n3sm17768872lag.9.2013.07.14.10.09.14 for <multiple recipients> (version=TLSv1.2 cipher=RC4-SHA bits=128/128); Sun, 14 Jul 2013 10:09:15 -0700 (PDT)
Date: Sun, 14 Jul 2013 19:09:11 +0200
From: Jon Kristensen <info@jonkri.com>
To: "Matt Miller (mamille2)" <mamille2@cisco.com>
Message-ID: <20130714190911.3a485030@jonkri.com>
In-Reply-To: <BF7E36B9C495A6468E8EC573603ED941152B1C3D@xmb-aln-x11.cisco.com>
References: <1693EFE1FD641C42A0D542FCBC732DE6BDE5BA3C@EX3.YODA.UTOPIA.LOCAL> <F930A551-9441-49BD-9564-FB1C43ADEA49@cisco.com> <BF7E36B9C495A6468E8EC573603ED941152B1C3D@xmb-aln-x11.cisco.com>
X-Mailer: Claws Mail 3.9.2 (GTK+ 2.24.19; x86_64-redhat-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
X-Gm-Message-State: ALoCoQnEMcfS8DQsf1j5yz35m9DkXXKCknYbGGyaFJsUsbaBbmKxwoYqILt3sunNx1eXynClx5iA
Cc: Peter Waher <Peter.Waher@clayster.com>, "<xmpp@ietf.org> Group" <xmpp@ietf.org>
Subject: Re: [xmpp] Problems with draft-miller-xmpp-e2e [WAS: [Standards] Updated Yabasta Protocol (E2E-related)]
X-BeenThere: xmpp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: XMPP Working Group <xmpp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/xmpp>, <mailto:xmpp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/xmpp>
List-Post: <mailto:xmpp@ietf.org>
List-Help: <mailto:xmpp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 14 Jul 2013 17:09:28 -0000

Hi, Matt!

I see. Thank you for your clarifications. I'm really glad that you're
open to look into meeting these (to me, very important) requirements.
PFS, repudiability, and anonymity (preferably strong) are "MUST"
requirements for the system that I'm building, and that's why I'm
developing the Yabasta protocol.

Unfortunately, as I'm quite busy with other matters, I don't think
that I will be able to contribute much to your draft, at least not
during the summer. I will not be able to travel to Berlin during those
days, either. :-( However, I will be following this mailing-list for
further developments of your drafts, and I hope that I will find the
time to review any suggestions related to the above.

Good luck!

Jon

On Thu, 11 Jul 2013 13:20:51 +0000
"Matt Miller (mamille2)" <mamille2@cisco.com> wrote:

> Hello Jon,
> 
> >> -----Original Message-----
> >> From: Jon Kristensen [mailto:info@jonkri.com] 
> >> Sent: den 27 juni 2013 15:30
> >> To: Peter Waher
> >> Cc: XMPP Standards
> >> Subject: Re: [Standards] Updated Yabasta Protocol (E2E-related)
> >> 
> >> Hi Peter, and thank you for your response!
> >> 
> >> These are the problems of the draft as I understand it.
> >> 
> >> It does not offer perfect forward secrecy, as the compromise of a
> >> private key would unlock all of the session keys protected by the
> >> corresponding public key.
> >> 
> 
> We talked about this on this list, and agreed that some form of
> "pure" DH agreement would be a way to address this, as well as remove
> the requirement for RSA keys.  I've been spending more energy on
> other tasks, and haven't had the time to work this out for myself.
> 
> As stated previously, suggested texts for draft-miller-xmpp-e2e are
> welcome.  If you can be in Berlin between 07/26 and 08/02, we can
> even sit down and hash something out face-to-face!
> 
> >> It also does not allow for anonymity (neither weak or strong), as
> >> the public key is being sent in the clear.
> >> 
> 
> See above.
> 
> >> A Diffie-Hellman key exchange request model could be used to
> >> tackle these problems, provided that two levels of <keyreq />
> >> requests can be used. I don't know if this is part of the indended
> >> usage of the draft, or whether or not it would actually work. It
> >> would be great to see, though! Has any work been done to
> >> accommodate this feature?
> >> 
> 
> See above.
> 
> >> I'm also a little concerned about the fact that the public keys is
> >> used to protect the session keys from a deniability perspective,
> >> but I haven't really thought that through enough yet. Maybe it's
> >> nothing...
> >> 
> 
> I don't have empirical evidence to back this up, but seems to be
> there are at least as many people that want non-repudiation than
> there are people that want deniability.  While the two are mutually
> exclusive, I don't think it means it can't be done.
> 
> The draft uses JWK objects for keys.  As long as you can represent
> the DH agreement as a JWK, I don't see why you couldn't use that
> instead of an RSA public/private key pair.
> 
> 
> - m&m
> 
> Matt Miller < mamille2@cisco.com >
> Cisco Systems, Inc.
> 


From stpeter@stpeter.im  Sun Jul 14 13:32:40 2013
Return-Path: <stpeter@stpeter.im>
X-Original-To: xmpp@ietfa.amsl.com
Delivered-To: xmpp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5FF5021F9C39 for <xmpp@ietfa.amsl.com>; Sun, 14 Jul 2013 13:32:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.448
X-Spam-Level: 
X-Spam-Status: No, score=-102.448 tagged_above=-999 required=5 tests=[AWL=0.151, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gz8dbDiDe1i4 for <xmpp@ietfa.amsl.com>; Sun, 14 Jul 2013 13:32:35 -0700 (PDT)
Received: from stpeter.im (mailhost.stpeter.im [207.210.219.225]) by ietfa.amsl.com (Postfix) with ESMTP id 4A60A21F99DA for <xmpp@ietf.org>; Sun, 14 Jul 2013 13:32:35 -0700 (PDT)
Received: from ergon.local (unknown [71.237.13.154]) (Authenticated sender: stpeter) by stpeter.im (Postfix) with ESMTPSA id 3F317E8280; Sun, 14 Jul 2013 14:33:54 -0600 (MDT)
Message-ID: <51E30AE5.3000705@stpeter.im>
Date: Sun, 14 Jul 2013 14:32:37 -0600
From: Peter Saint-Andre <stpeter@stpeter.im>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:17.0) Gecko/20130620 Thunderbird/17.0.7
MIME-Version: 1.0
To: kevin@kismith.co.uk
References: <516DDF85.5020700@stpeter.im> <CAOb_FnwEh2FqQwRBJDdLOrXE572d0zZr9MHtJEMaHS=y5frnMA@mail.gmail.com>
In-Reply-To: <CAOb_FnwEh2FqQwRBJDdLOrXE572d0zZr9MHtJEMaHS=y5frnMA@mail.gmail.com>
X-Enigmail-Version: 1.5.1
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Cc: XMPP <xmpp@ietf.org>
Subject: Re: [xmpp] 6122bis: leading and trailing whitespace
X-BeenThere: xmpp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: XMPP Working Group <xmpp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/xmpp>, <mailto:xmpp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/xmpp>
List-Post: <mailto:xmpp@ietf.org>
List-Help: <mailto:xmpp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 14 Jul 2013 20:32:40 -0000

On 7/14/13 10:24 AM, Kevin Smith wrote:
> On Wed, Apr 17, 2013 at 12:32 AM, Peter Saint-Andre <stpeter@stpeter.im> wrote:
>>        the ASCII space character at the beginning or end of a nickname)
>>        MUST be removed (e.g., "stpeter " is mapped to "stpeter").
>>
>> It seems like good advice in general for resourceparts. Does anyone have objections to adding it?
> 
> Not I.

Thanks for the feedback.

I *think* 6122bis is done -- we're waiting on the PRECIS framework to be
completed, but it too is getting close.

One thing I still need to do is compare the output of (1) the stringprep
profiles from RFC 6122 against Unicode 3.2, with (2) the PRECIS profiles
from 6122bis against Unicode 6.2. Now that I have some code that mostly
works, I'll do that soon.

Peter

-- 
Peter Saint-Andre
https://stpeter.im/



From daniele.athome@gmail.com  Wed Jul 24 13:18:31 2013
Return-Path: <daniele.athome@gmail.com>
X-Original-To: xmpp@ietfa.amsl.com
Delivered-To: xmpp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DEB4111E8239 for <xmpp@ietfa.amsl.com>; Wed, 24 Jul 2013 13:18:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.111
X-Spam-Level: 
X-Spam-Status: No, score=-1.111 tagged_above=-999 required=5 tests=[BAYES_05=-1.11, NO_RELAYS=-0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zhO0-RRMxfgq for <xmpp@ietfa.amsl.com>; Wed, 24 Jul 2013 13:18:30 -0700 (PDT)
Received: from mail-wg0-x234.google.com (mail-wg0-x234.google.com [IPv6:2a00:1450:400c:c00::234]) by ietfa.amsl.com (Postfix) with ESMTP id CE04C11E80D2 for <xmpp@ietf.org>; Wed, 24 Jul 2013 13:18:29 -0700 (PDT)
Received: by mail-wg0-f52.google.com with SMTP id b13so854496wgh.19 for <xmpp@ietf.org>; Wed, 24 Jul 2013 13:18:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:from:date:message-id:subject:to:content-type; bh=QWIRP48EeRzL9j9clU91AaxZsK49tDv0mCl9CtFrwdg=; b=Gt3D3QLSd13gt1oNEo7cFvboXW4/G+7uTqCK+UcefmHXn/zWLvg8+n37dvP5rclFQO i+DP5CTSbUc1BYZDGVtJsuMaEQtxa7+XOkfvRumyvzpiU4KT8GDUJy12YAyo1LzKD94q D742BlPKBeBrPnBmWrSRu/4jNMsiuylM1z6FckwXyJNnb1jcOffIsh6p42EGEV5dfuK+ BSJFJ5BJNAvVKjbzDmHMGMDLw3z06d8+shrWbotj55Q7KZ6XT+Uc83oI4SFLAODeHXsL g0frD5fZkrmu/zig0i5HalD5JH4wdvjY7c7jAl34+t87eiT/KACbr1je+pPuqcdxITvJ MeXw==
X-Received: by 10.194.243.101 with SMTP id wx5mr28044587wjc.49.1374697108974;  Wed, 24 Jul 2013 13:18:28 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.217.116.138 with HTTP; Wed, 24 Jul 2013 13:17:48 -0700 (PDT)
From: Daniele Ricci <daniele.athome@gmail.com>
Date: Wed, 24 Jul 2013 22:17:48 +0200
Message-ID: <CA+yWqeWiEtx2SPUCnQWkTG20dAxETV2OKSdjr647BKURM+8nfA@mail.gmail.com>
To: xmpp@ietf.org
Content-Type: text/plain; charset=UTF-8
Subject: [xmpp] draft-miller-xmpp-e2e: forwarded envelope
X-BeenThere: xmpp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: XMPP Working Group <xmpp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/xmpp>, <mailto:xmpp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/xmpp>
List-Post: <mailto:xmpp@ietf.org>
List-Help: <mailto:xmpp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Jul 2013 20:18:31 -0000

Hello,
draft-miller-xmpp-e2e-06, at 3.2.2-3 states: "Constructs a forwarding
envelope (M) using a <forwarded/> element [...]"
why the <forwarded/>? Why not encode the stanza itself?


Regards
-- 
Daniele

From fippo@goodadvice.pages.de  Wed Jul 31 00:51:06 2013
Return-Path: <fippo@goodadvice.pages.de>
X-Original-To: xmpp@ietfa.amsl.com
Delivered-To: xmpp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AAB7D11E80AD; Wed, 31 Jul 2013 00:51:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.164
X-Spam-Level: 
X-Spam-Status: No, score=-2.164 tagged_above=-999 required=5 tests=[AWL=0.435,  BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XVRgSfi9ikjl; Wed, 31 Jul 2013 00:50:51 -0700 (PDT)
Received: from lo.psyced.org (lost.IN.psyced.org [188.40.42.221]) by ietfa.amsl.com (Postfix) with ESMTP id 5A10021F9F13; Wed, 31 Jul 2013 00:50:51 -0700 (PDT)
Received: from [130.129.18.133] (dhcp-1285.meeting.ietf.org [130.129.18.133]) (authenticated bits=0) by lo.psyced.org (8.14.3/8.14.3/Debian-9.4) with ESMTP id r6V7odNl006225 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 31 Jul 2013 09:50:49 +0200
Message-ID: <51F8C1CE.1010701@goodadvice.pages.de>
Date: Wed, 31 Jul 2013 09:50:38 +0200
From: Philipp Hancke <fippo@goodadvice.pages.de>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20130623 Thunderbird/17.0.7
MIME-Version: 1.0
To: posh@ietf.org
References: <CAPms+wRR_ZtLq94mRCDVXEW9WyZeDmYx+1hU+zCXV1fT0GSZ+g@mail.gmail.com> <51F401CE.9080803@stpeter.im>
In-Reply-To: <51F401CE.9080803@stpeter.im>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Cc: XMPP Working Group <xmpp@ietf.org>
Subject: Re: [xmpp] [POSH] Comments/questions on draft-miller-posh-00
X-BeenThere: xmpp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: XMPP Working Group <xmpp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/xmpp>, <mailto:xmpp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/xmpp>
List-Post: <mailto:xmpp@ietf.org>
List-Help: <mailto:xmpp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 Jul 2013 07:51:07 -0000

Am 27.07.2013 19:22, schrieb Peter Saint-Andre:
[...]
>> Similarly, I can't see anything obviously wrong with letting the
>> application handshake complete, then performing the POSH
>> operations before deciding the application connection is not
>> suitable and should be terminated before being used.  Is the MUST
>> in this section mandating the order of operations necessary for
>> some other reason?
>
> As mentioned above, the MUST here is perhaps a bit silly because it's
> so obvious. I think there is a better way to word it...

While implementing this I found another reason why this MUST doesn't work.

In XMPP we want DNA to have the ability to multiplex several domain 
pairs, with multiple remote domains.

However, at the time of the TLS handshake we only know a single remote 
domain (taken from the stream's from).

At any later time, the remote end may use this <db:result/> stuff to add 
another remote domain. This might trigger the POSH dance and clearly 
happens after the TLS handshake is done.

I would suggest removing this MUST.

From mamille2@cisco.com  Wed Jul 31 01:19:47 2013
Return-Path: <mamille2@cisco.com>
X-Original-To: xmpp@ietfa.amsl.com
Delivered-To: xmpp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2176E21F9ED8; Wed, 31 Jul 2013 01:19:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.599
X-Spam-Level: 
X-Spam-Status: No, score=-10.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mKwdZ3dJ3Ze5; Wed, 31 Jul 2013 01:19:27 -0700 (PDT)
Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) by ietfa.amsl.com (Postfix) with ESMTP id D298221F9926; Wed, 31 Jul 2013 01:18:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=8075; q=dns/txt; s=iport; t=1375258732; x=1376468332; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=Ce2D2l5ln2Ixo4YMdF+p0KNDSOmhs+500y8if15tgto=; b=HgwfOAXnObnw5jsqFR37bja+ODqc9d41RCGe1PqyFZvuM6M6WAyu6Ydq Mn3SINkHV3RGkAuWoqa5iaGrIQ1OYf6xH1BdlEqd6YrlK2Aspz0Wn6Z8G rGN0+QTaI4KzmZzE5Ng728enEWGqxcppIIoTSk0OgK06NPXnFZiMSi+sp Y=;
X-Files: smime.p7s : 4136
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhQFACLH+FGtJXHB/2dsb2JhbABbgwaBBb4cgRgWdIIkAQEBAwF5BQsCAQgOFCQCMCUCBA4FCAaHfAa4T49NFhsHgxhxA5ASgS2CSZUjgxSBaCMf
X-IronPort-AV: E=Sophos;i="4.89,785,1367971200";  d="p7s'?scan'208";a="241677481"
Received: from rcdn-core2-6.cisco.com ([173.37.113.193]) by rcdn-iport-6.cisco.com with ESMTP; 31 Jul 2013 08:18:51 +0000
Received: from xhc-rcd-x06.cisco.com (xhc-rcd-x06.cisco.com [173.37.183.80]) by rcdn-core2-6.cisco.com (8.14.5/8.14.5) with ESMTP id r6V8Ipet003705 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Wed, 31 Jul 2013 08:18:51 GMT
Received: from xmb-aln-x11.cisco.com ([169.254.6.159]) by xhc-rcd-x06.cisco.com ([173.37.183.80]) with mapi id 14.02.0318.004; Wed, 31 Jul 2013 03:18:51 -0500
From: "Matt Miller (mamille2)" <mamille2@cisco.com>
To: Philipp Hancke <fippo@goodadvice.pages.de>
Thread-Topic: [POSH] Comments/questions on draft-miller-posh-00
Thread-Index: AQHOieYn3zcp/gJiFUS1gabrGyMGtpl5G7oAgAWplgCAAAfhAA==
Date: Wed, 31 Jul 2013 08:18:50 +0000
Message-ID: <BF7E36B9C495A6468E8EC573603ED9411EE55C3F@xmb-aln-x11.cisco.com>
References: <CAPms+wRR_ZtLq94mRCDVXEW9WyZeDmYx+1hU+zCXV1fT0GSZ+g@mail.gmail.com> <51F401CE.9080803@stpeter.im> <51F8C1CE.1010701@goodadvice.pages.de>
In-Reply-To: <51F8C1CE.1010701@goodadvice.pages.de>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [10.21.77.137]
Content-Type: multipart/signed; boundary="Apple-Mail=_3AB2945B-0B72-416B-B783-F10050DB8279"; protocol="application/pkcs7-signature"; micalg=sha1
MIME-Version: 1.0
Cc: "<posh@ietf.org>" <posh@ietf.org>, XMPP Working Group <xmpp@ietf.org>
Subject: Re: [xmpp] [POSH] Comments/questions on draft-miller-posh-00
X-BeenThere: xmpp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: XMPP Working Group <xmpp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/xmpp>, <mailto:xmpp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/xmpp>
List-Post: <mailto:xmpp@ietf.org>
List-Help: <mailto:xmpp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 Jul 2013 08:19:48 -0000

--Apple-Mail=_3AB2945B-0B72-416B-B783-F10050DB8279
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii


On Jul 31, 2013, at 9:50 AM, Philipp Hancke <fippo@goodadvice.pages.de>
 wrote:

> Am 27.07.2013 19:22, schrieb Peter Saint-Andre:
> [...]
>>> Similarly, I can't see anything obviously wrong with letting the
>>> application handshake complete, then performing the POSH
>>> operations before deciding the application connection is not
>>> suitable and should be terminated before being used.  Is the MUST
>>> in this section mandating the order of operations necessary for
>>> some other reason?
>>=20
>> As mentioned above, the MUST here is perhaps a bit silly because it's
>> so obvious. I think there is a better way to word it...
>=20
> While implementing this I found another reason why this MUST doesn't =
work.
>=20
> In XMPP we want DNA to have the ability to multiplex several domain =
pairs, with multiple remote domains.
>=20
> However, at the time of the TLS handshake we only know a single remote =
domain (taken from the stream's from).
>=20
> At any later time, the remote end may use this <db:result/> stuff to =
add another remote domain. This might trigger the POSH dance and clearly =
happens after the TLS handshake is done.
>=20
> I would suggest removing this MUST.

These are all good points.

I will note that there is general queasiness with suspending disbelief =
on a connection, accepting the TLS handshake but then actually verifying =
 (and potentially failing) the connection because of TLS failings; not =
the least of which is the potential for abuse is very very great.  This =
also means that any error reporting that one might get from their TLS =
implementations for better error reporting is lost.

However, the multiplexing case is important for XMPP (not sure about =
others).  We need to allow for that to work.

I'll confer with my co-author, and we'll try to come up with some text =
that preserved the intent without being overly constricting.


- m&m

Matt Miller < mamille2@cisco.com >
Cisco Systems, Inc.


--Apple-Mail=_3AB2945B-0B72-416B-B783-F10050DB8279
Content-Disposition: attachment; filename="smime.p7s"
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMezCCBjQw
ggQcoAMCAQICAR4wDQYJKoZIhvcNAQEFBQAwfTELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0
Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxKTAn
BgNVBAMTIFN0YXJ0Q29tIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MB4XDTA3MTAyNDIxMDE1NVoX
DTE3MTAyNDIxMDE1NVowgYwxCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSsw
KQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFy
dENvbSBDbGFzcyAxIFByaW1hcnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQTCCASIwDQYJKoZIhvcN
AQEBBQADggEPADCCAQoCggEBAMcJg8zOLdgasSmkLhOrlr6KMoOMpohBllVHrdRvEg/q6r8jR+EK
75xCGhR8ToREoqe7zM9/UnC6TS2y9UKTpT1v7RSMzR0t6ndl0TWBuUr/UXBhPk+Kmy7bI4yW4urC
+y7P3/1/X7U8ocb8VpH/Clt+4iq7nirMcNh6qJR+xjOhV+VHzQMALuGYn5KZmc1NbJQYclsGkDxD
z2UbFqE2+6vIZoL+jb9x4Pa5gNf1TwSDkOkikZB1xtB4ZqtXThaABSONdfmv/Z1pua3FYxnCFmdr
/+N2JLKutIxMYqQOJebr/f/h5t95m4JgrM3Y/w7YX9d7YAL9jvN4SydHsU6n65cCAwEAAaOCAa0w
ggGpMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMB0GA1UdDgQWBBRTcu2SnODaywFc
fH6WNU7y1LhRgjAfBgNVHSMEGDAWgBROC+8apEBbpRdphzDKNGhD0EGu8jBmBggrBgEFBQcBAQRa
MFgwJwYIKwYBBQUHMAGGG2h0dHA6Ly9vY3NwLnN0YXJ0c3NsLmNvbS9jYTAtBggrBgEFBQcwAoYh
aHR0cDovL3d3dy5zdGFydHNzbC5jb20vc2ZzY2EuY3J0MFsGA1UdHwRUMFIwJ6AloCOGIWh0dHA6
Ly93d3cuc3RhcnRzc2wuY29tL3Nmc2NhLmNybDAnoCWgI4YhaHR0cDovL2NybC5zdGFydHNzbC5j
b20vc2ZzY2EuY3JsMIGABgNVHSAEeTB3MHUGCysGAQQBgbU3AQIBMGYwLgYIKwYBBQUHAgEWImh0
dHA6Ly93d3cuc3RhcnRzc2wuY29tL3BvbGljeS5wZGYwNAYIKwYBBQUHAgEWKGh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL2ludGVybWVkaWF0ZS5wZGYwDQYJKoZIhvcNAQEFBQADggIBAAqDCH14qywG
XLhjjF6uHLkjd02hcdh9hrw+VUsv+q1eeQWB21jWj3kJ96AUlPCoEGZ/ynJNScWy6QMVQjbbMXlt
UfO4n4bGGdKo3awPWp61tjAFgraLJgDk+DsSvUD6EowjMTNx25GQgyYJ5RPIzKKR9tQW8gGK+2+R
HxkUCTbYFnL6kl8Ch507rUdPPipJ9CgJFws3kDS3gOS5WFMxcjO5DwKfKSETEPrHh7p5shuuNktv
sv6hxHTLhiMKX893gxdT3XLS9OKmCv87vkINQcNEcIIoFWbP9HORz9v3vQwR4e3ksLc2JZOAFK+s
sS5XMEoznzpihEP0PLc4dCBYjbvSD7kxgDwZ+Aj8Q9PkbvE9sIPP7ON0fz095HdThKjiVJe6vofq
+n6b1NBc8XdrQvBmunwxD5nvtTW4vtN6VY7mUCmxsCieuoBJ9OlqmsVWQvifIYf40dJPZkk9YgGT
zWLpXDSfLSplbY2LL9C9U0ptvjcDjefLTvqSFc7tw1sEhF0n/qpA2r0GpvkLRDmcSwVyPvmjFBGq
Up/pNy8ZuPGQmHwFi2/14+xeSUDG2bwnsYJQG2EdJCB6luQ57GEnTA/yKZSTKI8dDQa8Sd3zfXb1
9mOgSF0bBdXbuKhEpuP9wirslFe6fQ1t5j5R0xi72MZ8ikMu1RQZKCyDbMwazlHiMIIGPzCCBSeg
AwIBAgIDBoRIMA0GCSqGSIb3DQEBBQUAMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRD
b20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzE4MDYG
A1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGllbnQgQ0EwHhcN
MTMwNDMwMjE1NDQyWhcNMTQwNTAyMDUzOTA0WjBbMRkwFwYDVQQNExBiN2F6NndOY0t0R3JtMEpF
MRswGQYDVQQDDBJtYW1pbGxlMkBjaXNjby5jb20xITAfBgkqhkiG9w0BCQEWEm1hbWlsbGUyQGNp
c2NvLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJbKBMsG+9UFTx9uq/bhhXgu
vJvO8z7cwKaqqwZhVf5z/kHFyCNijtmTOE+YXjA8mWR4aoBwB5SvGypI/cJUofJ+AlBTC4g+RMx/
K0Ab4/jQqTQz9CDzMOB+Wm+rt8ZJ7A8ZzOJmNDAsf/VvB8l2A1SQz1UsAixgH16NTr8SlblAXEKk
4hwpCudUiNjjQokqJ0H686UBKVorcZSgXaza8XMqGtJF/8mNhR9GQYi7Xht1ky+9LFOrto2daZto
KJRwMeVusVdHUeKEQSu7jztw8HchH3KEb7Q+r5X+hhDZoddfKE8d5eyPuhiZdrzv7OlNZ0fSLdx7
3AE3nx9/R5YlXucCAwEAAaOCAtgwggLUMAkGA1UdEwQCMAAwCwYDVR0PBAQDAgSwMB0GA1UdJQQW
MBQGCCsGAQUFBwMCBggrBgEFBQcDBDAdBgNVHQ4EFgQUxGd+/qrdVudHrIKkw5xOMY7eaLUwHwYD
VR0jBBgwFoAUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHQYDVR0RBBYwFIESbWFtaWxsZTJAY2lzY28u
Y29tMIIBTAYDVR0gBIIBQzCCAT8wggE7BgsrBgEEAYG1NwECAzCCASowLgYIKwYBBQUHAgEWImh0
dHA6Ly93d3cuc3RhcnRzc2wuY29tL3BvbGljeS5wZGYwgfcGCCsGAQUFBwICMIHqMCcWIFN0YXJ0
Q29tIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MAMCAQEagb5UaGlzIGNlcnRpZmljYXRlIHdhcyBp
c3N1ZWQgYWNjb3JkaW5nIHRvIHRoZSBDbGFzcyAxIFZhbGlkYXRpb24gcmVxdWlyZW1lbnRzIG9m
IHRoZSBTdGFydENvbSBDQSBwb2xpY3ksIHJlbGlhbmNlIG9ubHkgZm9yIHRoZSBpbnRlbmRlZCBw
dXJwb3NlIGluIGNvbXBsaWFuY2Ugb2YgdGhlIHJlbHlpbmcgcGFydHkgb2JsaWdhdGlvbnMuMDYG
A1UdHwQvMC0wK6ApoCeGJWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL2NydHUxLWNybC5jcmwwgY4G
CCsGAQUFBwEBBIGBMH8wOQYIKwYBBQUHMAGGLWh0dHA6Ly9vY3NwLnN0YXJ0c3NsLmNvbS9zdWIv
Y2xhc3MxL2NsaWVudC9jYTBCBggrBgEFBQcwAoY2aHR0cDovL2FpYS5zdGFydHNzbC5jb20vY2Vy
dHMvc3ViLmNsYXNzMS5jbGllbnQuY2EuY3J0MCMGA1UdEgQcMBqGGGh0dHA6Ly93d3cuc3RhcnRz
c2wuY29tLzANBgkqhkiG9w0BAQUFAAOCAQEAlDhXbGEI7lbqUcu5r2JHZaMsbRZda/99ZqODzWGX
0llou9jGccsAWDPPwRRe2+ROpXfH4cuJZElTcLDeZSp/qpXKhjYieFSX8+Ml9sKEj5UOSqQLyoLk
PtrIJV12Jk3nuG2Jc0UeEnGwK/aqtzy7+bfEVI0ziyVM2gChHh0RH74KyiwYWknbOTRIkZcz/ulE
DVFQp63uj6wfmDNvAUHBAdhKVqA1S/rfP1KcDZpf1NfvwXJibiqTRA6K1EOxTJOP41n/XdvHqHXL
RWL2xrOUI9/URANr/ok3OrsuZEMFnAAGefS1bWS/hFtUGVkHGiKEBbyDW7da2ULXbuC7umrQnzGC
A28wggNrAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkG
A1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRD
b20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGllbnQgQ0ECAwaESDAJBgUrDgMCGgUA
oIIBrzAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzA3MzEwODE4
NTBaMCMGCSqGSIb3DQEJBDEWBBTF/F2OFdZoc+EVBpUd9w2CmHN6kDCBpQYJKwYBBAGCNxAEMYGX
MIGUMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2Vj
dXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3Mg
MSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGllbnQgQ0ECAwaESDCBpwYLKoZIhvcNAQkQAgsxgZeg
gZQwgYwxCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1
cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAx
IFByaW1hcnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBoRIMA0GCSqGSIb3DQEBAQUABIIBADMC
1CKSVEB7W64wrm0qm1RQiRs6G/XCgu3L6y5ptCuqTpCA4An1spHklUFq79A0Z9ermYSJtlgGBGm7
lBJ9Va/d7h8ZjL/wy6AWwKvXEDW0L+wDiaP0YdJkVrAr7lo2dK0PmZMxq/1KrMi0Nu2e+tdrEL7h
QrIcjFmN4OhCrqhinhu4UttMuK9AN+RGzt321s2NZe/rjCwLcvkmi/KG6rgpcfuDFFdeh3K3H6JR
xgjFVQQxfXqWxn95WwutnNhWhwHXDcTyy4Lo4V+nNOYcrIRO+WMecpCyxZ7u/XN2/1kukCU3MKvP
nMR7AQUblU66116nfAPeACyeAi9OcqVG6xMAAAAAAAA=

--Apple-Mail=_3AB2945B-0B72-416B-B783-F10050DB8279--

From dave@cridland.net  Wed Jul 31 02:09:47 2013
Return-Path: <dave@cridland.net>
X-Original-To: xmpp@ietfa.amsl.com
Delivered-To: xmpp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8FF3611E8171 for <xmpp@ietfa.amsl.com>; Wed, 31 Jul 2013 02:09:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.327
X-Spam-Level: 
X-Spam-Status: No, score=-1.327 tagged_above=-999 required=5 tests=[AWL=0.650,  BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, NO_RELAYS=-0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5Gf6oXjXSYjV for <xmpp@ietfa.amsl.com>; Wed, 31 Jul 2013 02:09:45 -0700 (PDT)
Received: from mail-la0-x22f.google.com (mail-la0-x22f.google.com [IPv6:2a00:1450:4010:c03::22f]) by ietfa.amsl.com (Postfix) with ESMTP id 52C9711E817D for <xmpp@ietf.org>; Wed, 31 Jul 2013 02:01:34 -0700 (PDT)
Received: by mail-la0-f47.google.com with SMTP id eo20so303133lab.6 for <xmpp@ietf.org>; Wed, 31 Jul 2013 02:01:21 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cridland.net; s=google; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=FWkkp9P/ywka76bKnBeAkdZiGAGloyWNgtHp6uwAGp0=; b=Bq9jtxZX50c0jsVIySUX/AIADjYZBIP8Yd+1YiX4+jFa/8bk78K0jq/Tas2P53gjCL N9CV5+zxX4XQTGfQ1cMJykdtByuXriKSa7bM+xJbp4wECKgct18svNwmrOWGBL5Yzdfp rdQinfLRgtlO8xM1iKWJfCUeD7hXqiAcogzr8=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:x-gm-message-state; bh=FWkkp9P/ywka76bKnBeAkdZiGAGloyWNgtHp6uwAGp0=; b=Tplz7EHCWHDkdb9zTz1DSSJopmRi0z0KZZIPM/QEZcwR8JHUb9jQQ6kxQtHt9Mu618 RIds+0LWPhxDk2kq2eeL9dSVsyPdSkOd/hdahub17Q0ebP5bkigoo8cShx3mekjJqKmI eKQ6o5qbHleeywBTB2NknBz1QnLXpsYpaUmN7a/haZQ3Cjy3HgA4MZxhRSW9z1d+VE3W 86u0V27zI/PykfH2R3px0kOVxIi68XlO64H3SK6WkA6lsKSlvtn7BecGBzmarsgC2r7Y hNyH4mSNcYj9wxgMGN9IhTFsYRVV8IBBR/p/9ZuaemD/y8gVRFTqPhlJwh1K0x8B0AxF k/iQ==
MIME-Version: 1.0
X-Received: by 10.112.185.36 with SMTP id ez4mr6704224lbc.81.1375261280888; Wed, 31 Jul 2013 02:01:20 -0700 (PDT)
Received: by 10.114.184.137 with HTTP; Wed, 31 Jul 2013 02:01:20 -0700 (PDT)
In-Reply-To: <BF7E36B9C495A6468E8EC573603ED9411EE55C3F@xmb-aln-x11.cisco.com>
References: <CAPms+wRR_ZtLq94mRCDVXEW9WyZeDmYx+1hU+zCXV1fT0GSZ+g@mail.gmail.com> <51F401CE.9080803@stpeter.im> <51F8C1CE.1010701@goodadvice.pages.de> <BF7E36B9C495A6468E8EC573603ED9411EE55C3F@xmb-aln-x11.cisco.com>
Date: Wed, 31 Jul 2013 10:01:20 +0100
Message-ID: <CAKHUCzzBssWF8vLq9dcdXnd5LsMt5S7xoo6J8QvXUhmQd5jtyA@mail.gmail.com>
From: Dave Cridland <dave@cridland.net>
To: "Matt Miller (mamille2)" <mamille2@cisco.com>
Content-Type: multipart/alternative; boundary=001a11c3cc1c1ef7d604e2caf8e8
X-Gm-Message-State: ALoCoQn0CLhpiWKC44hbqkBbF/IKM+0Borbk7ppZtL+HTYaMkl+dXl2IF0OqTvZcvdiR0CofUBNu
Cc: Philipp Hancke <fippo@goodadvice.pages.de>, "<posh@ietf.org>" <posh@ietf.org>, XMPP Working Group <xmpp@ietf.org>
Subject: Re: [xmpp] [POSH] Comments/questions on draft-miller-posh-00
X-BeenThere: xmpp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: XMPP Working Group <xmpp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/xmpp>, <mailto:xmpp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/xmpp>
List-Post: <mailto:xmpp@ietf.org>
List-Help: <mailto:xmpp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/xmpp>, <mailto:xmpp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 Jul 2013 09:09:47 -0000

--001a11c3cc1c1ef7d604e2caf8e8
Content-Type: text/plain; charset=ISO-8859-1

On Wed, Jul 31, 2013 at 9:18 AM, Matt Miller (mamille2)
<mamille2@cisco.com>wrote:

> I will note that there is general queasiness with suspending disbelief on
> a connection, accepting the TLS handshake but then actually verifying  (and
> potentially failing) the connection because of TLS failings; not the least
> of which is the potential for abuse is very very great.  This also means
> that any error reporting that one might get from their TLS implementations
> for better error reporting is lost.
>

If there is queasiness here it's misplaced. The case for abuse here is
predicated on the TLS handshake being the authorization, which it is not in
any SASL based protocol.

So in XMPP, we must already perform auth during the SASL exchange, and
during the <db:result/>, too.

If you have a protocol which conflates authentication and authorization, of
course, then the situation is different.

--001a11c3cc1c1ef7d604e2caf8e8
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">On Wed, Jul 31, 2013 at 9:18 AM, Matt Miller (mamille2) <s=
pan dir=3D"ltr">&lt;<a href=3D"mailto:mamille2@cisco.com" target=3D"_blank"=
>mamille2@cisco.com</a>&gt;</span> wrote:<br><div class=3D"gmail_extra"><di=
v class=3D"gmail_quote">
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">I will note that there is general queasiness=
 with suspending disbelief on a connection, accepting the TLS handshake but=
 then actually verifying =A0(and potentially failing) the connection becaus=
e of TLS failings; not the least of which is the potential for abuse is ver=
y very great. =A0This also means that any error reporting that one might ge=
t from their TLS implementations for better error reporting is lost.<br>
</blockquote><div><br></div><div>If there is queasiness here it&#39;s mispl=
aced. The case for abuse here is predicated on the TLS handshake being the =
authorization, which it is not in any SASL based protocol.</div><div><br>
</div><div>So in XMPP, we must already perform auth during the SASL exchang=
e, and during the &lt;db:result/&gt;, too.</div><div><br></div><div>If you =
have a protocol which conflates authentication and authorization, of course=
, then the situation is different.</div>
</div></div></div>

--001a11c3cc1c1ef7d604e2caf8e8--
