Re: comments on draft-tan-epp-launchphase-09
Seth Goldman <[email protected]>
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <CAAHh_-Lo9+ETvoc4hih-J=0bZ216qcKqjakX8RbwrN=C-Nz=dA@mail.gmail.com> |
On Wed, Apr 24, 2013 at 8:21 AM, Gould, James <[email protected]> wrote: > > There is no definition of an unauthorized client for a non-existing > application, so I'm not sure whether we would want to return 2201 instead > of 2303 for that case. Is the existence or non-existence of an > application, which would be easy to identify using the 2303 and 2201 > return codes, a concern from a security perspective. I'm just not sure > whether a security concern would override accurately representing the > error via the 2303 return code for a non-existing application. What do > others think about this? > > I think it's a non-issue. Exposing the existence of a particular application id does not have any security implications AFAICT. A non-sponsoring registrar can't do anything with that application id, so the information is neither useful nor sensitive. _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg