Re: comments on draft-tan-epp-launchphase-09

Seth Goldman <[email protected]>
Newsgroups gmane.ietf.provreg
Message-ID <CAAHh_-Lo9+ETvoc4hih-J=0bZ216qcKqjakX8RbwrN=C-Nz=dA@mail.gmail.com>
On Wed, Apr 24, 2013 at 8:21 AM, Gould, James <[email protected]> wrote:

>
> There is no definition of an unauthorized client for a non-existing
> application, so I'm not sure whether we would want to return 2201 instead
> of 2303 for that case.  Is the existence or non-existence of an
> application, which would be easy to identify using the 2303 and 2201
> return codes, a concern from a security perspective.  I'm just not sure
> whether a security concern would override accurately representing the
> error via the 2303 return code for a non-existing application.  What do
> others think about this?
>
>
I think it's a non-issue. Exposing the existence of a particular
application id does not have any security implications AFAICT.  A
non-sponsoring registrar can't do anything with that application id, so the
information is neither useful nor sensitive.

_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.