: 3588 issue with Vendor-Specific-Application-Id

Avi Lior <[email protected]> Tue, 10 May 2005 11:57:14 -0400
Newsgroups gmane.ietf.aaa
Message-ID <F17FB067A86B2D488382C923C532EAA704F743D0@exch01.bridgewatersys.com>
Description of issue

Submitter name: Avi Lior	
Submitter email address: [email protected]
Date first submitted: May 10, 2005
Reference: 
Document: 3%88
Comment type: T
Priority: S
Section: 6.11
Rationale/Explanation of issue:

As the 3588 stands nowm Vendor-Specific-Application-Id AVP is allowed to
have just a vendor-id element. This does not make any sense.

Length description of problem

The ABNF of the Vendor-Specific-Application-Id given below:

<Vendor-Specific-Application-Id> ::= < AVP Header: 260 >
                                     1* [ Vendor-Id ]
                                     0*1{ Auth-Application-Id }
                                     0*1{ Acct-Application-Id }

And the following text from 3588 section 6.11:

"Exactly one of the Auth-Application-Id and Acct-Application-Id AVPs MAY be
present."

Allows us to have a Vendor-Specific-Application-Id containing only
Vendor-Id.

I don't think that that is the intent.

Requested change:

To fix this problem, 

Change:
"Exactly one of the Auth-Application-Id and Acct-Application-Id AVPs MAY be
present."

To:
"Exactly one of the Auth-Application-Id or Acct-Application-Id AVPs MUST be
present."





------------------------------------------------
Avi Lior                                    
Bridgewater Systems Corporation                
Phone :  (613) 591-9104 x6417
Cell    :  (613) 297-2177
E-mail : mailto:[email protected]
www.bridgewatersystems.com