Issue 24 MUST/SHOULD in clock skew (section 7.1)
Kazunori Miyazawa <[email protected]> Fri, 04 Feb 2005 13:35:17 +0900
| Newsgroups | gmane.ietf.kink |
|---|---|
| Message-ID | <[email protected]> |
Hello, #24 [*] MUST/SHOULD in clock skew (section 7.1) The time difference MUST be computed and SHOULD be stored and used? Why the different requirement levels? (And is this sort of thing in the domain of KINK or Kerberos?) (Ken Raeburn) I considered this issue. The clarifications does not mention clock skew processing in the client/server authentication exchange. The way to process the skew is left to an application. I think the clock skew processing is an implementation and/or operational issue in KINK. However the server must provide the ctime because the client may want to continue the process though there is skew. I propose that KINK filling out ctime is MUST but KINK should not decide the processing. -- Kazunori Miyazawa