Re: WG last call on framework document.

"Nystrom, Magnus" <[email protected]> Fri, 23 Aug 2002 11:19:16 +0200 (W. Europe Daylight Time)
Newsgroups gmane.ietf.sacred
Message-ID <Pine.WNT.4.43.0208231116520.992-100000@mnystrom-lap>
> This message is to start a WG last call on the framework
> document. Since its summer (here) the last call will have
> a duration of one month, i.e. it ends on August 24th.

Here are a few editorial things I have found when reviewing this
memo. I do not think any of these warrants a new last-call period, but
perhaps others feel differently.

-Section 1, first paragraph: (and elsewhere) Replace "Private
 credentials" with "Digital credentials". First sentence could read:
 "Digital credentials, such as private keys and digital
 certificates,..."

 Reason: We are talking about digital credentials, private credentials
 are broader.

-Section 1, second paragraph: Replace "user credentials" with
 "credentials".

 Reason: It may be a host or some other entity's credentials.

-Section 2.1:

 a) Replace "private signing key credential" with "signature key".

 Reason: Shorter and clearer, that it is a credential has already been
 indicated.

 b) Replace "Credentials are cryptographically protected for
 confidentiality and integrity by encoding them in a standard
 format..." with: "Credentials may be cryptographically protected for
 confidentiality and integrity and encoded in a standard format..."

 Reason: Credentials are not necessarily protected, it is really up to
 the parties. And encoding them in a standard format is not needed to
 achieve this protection.

 c) Penultimate paragraph: Remove the reference to [PKCS15] and
 [PKCS12].

 Reason: They have already been referred to earlier on the page.

-Section 2.2, first paragraph: Replace "secure use and..." with
 "secure transfer and..."

 Reason: The document describes a protocol framework for transfer of
 credentials, not their use.

-Section 2.2, last paragraph:

 Replace "Prior to" with "During".

 Reason: It is the session/connection which is protected and hence is
 creating this second layer.

-Section 3, definition of "disconnect": Replace "operations that
 bound" with "operations that are bound".

-Section 3, definition of "Name-x": Remove the sentence "A credential
 name is required..."

 Reason: The intent was to allow, e.g. for deleting all credentials
 for a particular account. The current protocol document also does not
 require a name to be present

-Section 3.1, first paragraph: Replace "capability" with "operation"

-Section 4.1, first paragraph: Replace "conforming client and server
 implementations" with "conforming client implementations".

 Reason: Servers do not need to interpret the format.

-Section 4.1, second paragraph: Remove last sentence.

 Reason: Already covered in first paragraph.

-Section 4.2: In the list of examples of existing protocols that offer
 authentication services, replace "TLS authentication" with just "TLS"

 Reason: "TLS authentication" is not a protocol, TLS is.

-Section 4.2.2, second paragraph: Remove "CA root key".

 Reason: The root key is not strictly necessary, the client may have
 been configured to trust the server's public key directly.

-Section 4.2.2, paragraph starting "When necessary...": Replace "the
 server" with "the credential server" and replace "a SASL-based" with
 "an".

 Reason: a) clarity. b) the framework document should not assume
 SASL.

-Section 4.2.2, subsection "TLS with Remote Client Authentication":
 Change title, remove the word "Remote". Remoce last sentence in first
 paragraph (the sentence starting "Following...").

 Reason: a) Not needed. b) The server does not know if it has been
 succesfully authenticated or not. The sentence is not needed.

-Section 4.2.3: Remove the itemized list.

 Reason: It is not referred to, and requirements on authentication
 protocols are already in Section 4.2.

-Section 4.3: Just before the list of TCP, BEEP, and HTTP, insert:
 "Among these protocols are:"

 Reason: Clarity.

-Remove Section 5.

-Section 6: Replace "frameworksupporting" with "framework
 supporting".

-Section 6.1.3: Suggest shortening the text somewhat. E.g. replace the
 end of the sentence starting "These goals may be achieved..."
 (i.e. everything after "in which...") with "or explicitly." Change
 the start of the next sentence to "If the server...", and replace
 "root keys" with "trusted keys".

 Reasons: The paragraph is partially a repeat of text already in the
 memo, and references to what strong password protocols have already
 been made too. The last change is just to recognize that the
 important thing about these keys is that they are trusted.

-Section 6.2.1:

 a) "protocols secure" -> "protocols, secure"

 b) "In the case of a SACRED protocol" -> "In the case of a
    passwords-based SACRED protocol"

 c) Second paragraph: How is that to be done? Either some guidance or
    remove the paragraph.

 Reasons: b): SACRED protocols does not necessarily have to be
 password-based. c): If one is making such a statement some guidance
 ought to be provided.

-Section 7: The reference to PDM will probably have to go, the draft
 has expired and I could not find a new one.

-- Magnus