[Fwd: Re: [secdir] Secdir review of draft-ietf-krb-wg-kdc-model-12]
Jeffrey Hutzelman <[email protected]> Thu, 05 Jul 2012 13:24:52 -0400
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
-------- Forwarded Message -------- From: Jeffrey Hutzelman <[email protected]> To: Alexey Melnikov <[email protected]> Cc: [email protected], [email protected], secdir <[email protected]> Subject: Re: [secdir] Secdir review of draft-ietf-krb-wg-kdc-model-12 Date: Thu, 05 Jul 2012 00:17:52 -0400 On Wed, 2012-07-04 at 22:04 +0100, Alexey Melnikov wrote: > I do however have a long list of nits and minor issues which I think > need to be addressed: I think the majority of your comments can be addressed by noting that this is an abstract data model, not a schema or protocol. So, it discusses values that must be representable, but not what the representation must look like, because that's up to some schema or protocol based on this data model (e.g. an LDAP schema or XML DTD). I thought at this point that the introduction makes this point reasonably clear, along with the notion that "implementations" of this documents are schemas or protocols, not pieces of software. However, if you didn't pick up on that, then maybe there's a better way to get it across. Aside from those, you also pointed three specific issues (quoted below) which I think are answered by text in RFC3961. If that information is sufficient to answer your questions, then appropriate references to that document should be inserted in the text. Otherwise, we'll have to talk about what the document can say to be more clear. > In Section 4.1.1.13 - what is an enctype? :-). See RFC3961. > 4.3.1.2. keyValue > > The binary representation of the key data. This MUST be a single- > valued octet string. > > > Can it be zero-length? A valid question, I suppose. But I don't see any point in saying, because then someone will just follow up with a question asking whether it is allowed to be length 1. In fact, a key held by the KDC will be a valid key for the appropriate enctype. The set of valid keys is a property of the enctype, as specified in RFC3961 section 3. > 4.3.1.3. keySaltValue > > The binary representation of the key salt. This MUST be a single- > valued octet string. > > As above. RFC3961 is quite clear that any valid UTF-8 string is permissible as a salt. You also pointed out several missing references; I agree with all of those. Leif, can you make sure we get in whatever changes are needed to address Alexey's comments? -- Jeff _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg