Re: draft-ietf-ldapext-ldapv3-tls-01.txt & draft-ietf-ldapext-authmeth-02.txt

[email protected] Fri, 10 Jul 1998 23:27:23 -0700
Newsgroups gmane.ietf.apps-tls
Message-ID <[email protected]>
Re the availability of new versions of..

  draft-ietf-ldapext-authmeth-02.txt
  draft-ietf-ldapext-ldapv3-tls-01.txt


..here's a summary of what's new in these docs since the last versions.

-----------------------------------------------------------------------------

Doc changes for draft-ietf-ldapext-authmeth-02.txt from -01 version...

- updated section:	3.  Introduction
    with revised threats and security mechanisms enumerations. 

- updated section:	4.  Deployment scenarios
    with revised scenarios.

- added section:	5.  Authentication and Authorization:  
			    Definitions and Concepts
    from draft-ietf-ldapext-ldapv3-tls-01.txt

- updated section:	6.  Required Security Mechanisms
  - draws distinctions between passive eavesdropping attacks and active 
    intermediary attacks. 
  - revised security conformance requirements.

- various detailed refinements to sections:	
	7. Anonymous authentication
	8. Password-based authentication
	9. Certificate-based authentication

- added section:	11. Authorization Identity
  - syntax for authorization id included with SASL "EXTERNAL"-flavored Bind

- updated section:	12. TLS Ciphersuites
  - refined and expanded ciphersuite list. Commented on threats different 
    classes of ciphersuites are susceptable to. 

- Overall subtle-but-important change to doc is to recognize..
  - authorization identities are not always represented as DNs


-----------------------------------------------------------------------------

Doc changes for draft-ietf-ldapext-ldapv3-tls-01.txt from -00 version...


- Removed Section:	6.  Authentication and Authorization:  
			    Definitions and Concepts

  ..and moved it to draft-ietf-ldapext-authmeth-02.txt


- added Section:	4.3.  TLS Version Negotiation


- added Section:	4.6.  Server Identity Check

- refined and expanded: 6.  Effects of TLS on a Client's Authorization Identity

- changed "invalidAuthorizationId" error to "invalidCredentials"


A state diagram corresponding to this draft is available at..

 http://www.stanford.edu/~hodges/doc/StartTLSStateDiagram-8-May-1998.html

-----------------------------------------------------------------------------