[Fwd: Re: [secdir] Secdir review of draft-ietf-krb-wg-kdc-model-12]

Jeffrey Hutzelman <[email protected]> Thu, 05 Jul 2012 13:24:52 -0400
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
-------- Forwarded Message --------
From: Jeffrey Hutzelman <[email protected]>
To: Alexey Melnikov <[email protected]>
Cc: [email protected], [email protected],
secdir <[email protected]>
Subject: Re: [secdir] Secdir review of draft-ietf-krb-wg-kdc-model-12
Date: Thu, 05 Jul 2012 00:17:52 -0400

On Wed, 2012-07-04 at 22:04 +0100, Alexey Melnikov wrote:

> I do however have a long list of nits and minor issues which I think 
> need to be addressed:

I think the majority of your comments can be addressed by noting that
this is an abstract data model, not a schema or protocol.  So, it
discusses values that must be representable, but not what the
representation must look like, because that's up to some schema or
protocol based on this data model (e.g. an LDAP schema or XML DTD).

I thought at this point that the introduction makes this point
reasonably clear, along with the notion that "implementations" of this
documents are schemas or protocols, not pieces of software.  However, if
you didn't pick up on that, then maybe there's a better way to get it
across.


Aside from those, you also pointed three specific issues (quoted below)
which I think are answered by text in RFC3961.  If that information is
sufficient to answer your questions, then appropriate references to that
document should be inserted in the text.  Otherwise, we'll have to talk
about what the document can say to be more clear.



> In Section 4.1.1.13 - what is an enctype? :-).

See RFC3961.

> 4.3.1.2.  keyValue
> 
>     The binary representation of the key data.  This MUST be a single-
>     valued octet string.
> 
> 
> Can it be zero-length?

A valid question, I suppose.  But I don't see any point in saying,
because then someone will just follow up with a question asking whether
it is allowed to be length 1.

In fact, a key held by the KDC will be a valid key for the appropriate
enctype.  The set of valid keys is a property of the enctype, as
specified in RFC3961 section 3.


> 4.3.1.3.  keySaltValue
> 
>     The binary representation of the key salt.  This MUST be a single-
>     valued octet string.
> 
> As above.

RFC3961 is quite clear that any valid UTF-8 string is permissible as a
salt.



You also pointed out several missing references; I agree with all of
those.


Leif, can you make sure we get in whatever changes are needed to address
Alexey's comments?

-- Jeff



_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg