Review of draft-ietf-krb-wg-referrals-13.txt
Jeffrey Hutzelman <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
Below is my review of referrals. This document looks pretty good; there
are only a few issues. As usual, I'd like to see some resolution to all
of these, though some may not necessarily require a change to the
document. Items 1, 4, 8, and 9 are blockers; they must be resolved
before the document can progress.
I would also like to hear from anyone who has implemented this
specification or is planning to do so.
-- Jeff
1) The abstract needs to specifically mention that this document
updates RFC4120.
2) In the last paragraph of section 1, s/compliments/complements/
3) Why is AD-LOGIN-ALIAS a one-element SEQUENCE?
4) In the last paragraph of section 6, s/MUST not/MUST NOT/; that
is, make the NOT be uppercase. This is required for consistency
with the terms as defined by RFC2119.
5) In the second paragraph of section 7, the phrase "KDC reply structure"
seems odd. Perhaps s/ structure// ?
6) Section 7, paragraph 6, begins "The true principal name of the
client, returned in AS-REQ...". I think AS-REP is meant here.
7) Section 11 includes a new PA type PA-REQ-ENC-PA-REP, which has
a rather unwieldy name. It looks like this is always empty in
requests, and in replies contains a checksum, rather than encrypted
data. It seems like this could have a better name, such as
PA-REQ-CHECKSUM.
8) Section 11 refers to a key usage value KEY_USAGE_AS_REQ. But this
is not called out in section 12 (Number assignments). Is this value
present in the key usage registry?
9) Various acronyms need to be expanded on first use:
Note that expansion in the abstract is not sufficient to cover uses
elsewhere in the document.
- TGT (abstract)
- AS, TGS (section 1, graf 1)
- KDC (section 1, graf 2)
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg