SACRED Framework-03: Change Summary

Dale Gustafson <[email protected]> Mon, 04 Mar 2002 10:38:57 -0600
Newsgroups gmane.ietf.sacred
Message-ID <[email protected]>
Hi All,

Here is a summary of the changes made to create the latest draft of the SACRED Protocol
Framework document (draft-ietf-sacred-framework-03.txt).

Several sections of the document were reorganized (moved around) in order to make the document
easier to read, so I've referenced the changes both ways.

The primary changes made in this latest draft are:

-02 section  -03 section     editing changes made
-----------  -----------     ---------------------------------------------------------
 2.           2.             Changed requirements references to RFC-3157
                             Protocol framework applies to client/server only
                             "Account Password" and "Credential Password" terms used

 2.2          2.2            Session-level encryption key "derived" during mutual auth.

 3.1          4.2.1          Strong-password protocols "may" be used. xTLS is an alternative

 3.2          4.2.2          Reworded to describe "sTLS" and "cTLS" options
                             Added "4.3.3 Other Authentication Methods"

 4.           ---            Removed Authentication Options - this level of detail
                             is best covered by protocol document(s)

 ---          4.3            Added "Transport Protocol Suites" - included a "minimal"
                             summary of the list discussion on these topics.

 5.           3.             Protocol Framework - added summary description of protocol
                             elements used throughout (secured credential, credential name,
                             credential ID/fingerprint).  Note that ID is used throughout
                             this section based on our interpretation of the list discussion.
                             This should be clarified and harmonized with the protocol doc.

 5.1          3.1, 3.1.1     Added "Conditional Replace" description

 5.2          3.2, 3.2.1     Added GET-ALL credentials (GET-NULL) description
                             Clarified "Conditional Download" description

 6.           4.1            Secure Credential Formats - restructured and removed details
                             for PKCS#15 and PKCS#12 that can be found in the referenced
                             documents

 7.           7.             Updated to reference RFC-3157 (SACRED Requirements) and
                             added several references.

This revision attempted to capture the substance of recent list discussion and to improve
alignment with the approved Requirements document and the protocol document.  The need for
additional efforts, if any, can be discussed immediately on-list and/or in Minneapolis on
3/18.

Best Regards,

Dale Gustafson