Re: draft-ietf-ldapext-ldapv3-tls-01.txt & draft-ietf-ldapext-authmeth-02.txt
[email protected] Fri, 10 Jul 1998 23:27:23 -0700
| Newsgroups | gmane.ietf.apps-tls |
|---|---|
| Message-ID | <[email protected]> |
Re the availability of new versions of..
draft-ietf-ldapext-authmeth-02.txt
draft-ietf-ldapext-ldapv3-tls-01.txt
..here's a summary of what's new in these docs since the last versions.
-----------------------------------------------------------------------------
Doc changes for draft-ietf-ldapext-authmeth-02.txt from -01 version...
- updated section: 3. Introduction
with revised threats and security mechanisms enumerations.
- updated section: 4. Deployment scenarios
with revised scenarios.
- added section: 5. Authentication and Authorization:
Definitions and Concepts
from draft-ietf-ldapext-ldapv3-tls-01.txt
- updated section: 6. Required Security Mechanisms
- draws distinctions between passive eavesdropping attacks and active
intermediary attacks.
- revised security conformance requirements.
- various detailed refinements to sections:
7. Anonymous authentication
8. Password-based authentication
9. Certificate-based authentication
- added section: 11. Authorization Identity
- syntax for authorization id included with SASL "EXTERNAL"-flavored Bind
- updated section: 12. TLS Ciphersuites
- refined and expanded ciphersuite list. Commented on threats different
classes of ciphersuites are susceptable to.
- Overall subtle-but-important change to doc is to recognize..
- authorization identities are not always represented as DNs
-----------------------------------------------------------------------------
Doc changes for draft-ietf-ldapext-ldapv3-tls-01.txt from -00 version...
- Removed Section: 6. Authentication and Authorization:
Definitions and Concepts
..and moved it to draft-ietf-ldapext-authmeth-02.txt
- added Section: 4.3. TLS Version Negotiation
- added Section: 4.6. Server Identity Check
- refined and expanded: 6. Effects of TLS on a Client's Authorization Identity
- changed "invalidAuthorizationId" error to "invalidCredentials"
A state diagram corresponding to this draft is available at..
http://www.stanford.edu/~hodges/doc/StartTLSStateDiagram-8-May-1998.html
-----------------------------------------------------------------------------