Re: bss-04 comments

Stephen Farrell <[email protected]> Thu, 07 Nov 2002 13:08:51 +0000
Newsgroups gmane.ietf.sacred
Organization Baltimore Technologies Ltd.
Message-ID <[email protected]>

Hi Bill,

[email protected] wrote:
> 
>  while it might be interesting to work through sacred on other
>  transports (and yes, i'll read the archives), the main point
>  that comes out of this draft is an unstated dependence on BEEP

"unstated" is a bit of a stretch. Look at the 2nd para in the
introduction. I could buy changing the wording a bit though. Care
to make a suggestion?

>  and a presumption on when/where authentication steps are performed.

I kind of agree with you here - we're assuming the reader knows that
BEEP supports SASL and TLS. I'll clarify that, but again welcome your
suggestion - since you found the current wording misleading, you
might be best placed to suggest the fix.

Stephen.

> 
>  it might be more honest/forthright to state up front that the
>  current sacred protocols are designed to run exclusively on BEEP
>  or that much of the authentication is expected to occur prior
>  to involking sacred.
> 
> >
> >
> > (Bringing a couple of off-list comments to the list.)
> >
> > Hi Bill,
> >
> > There's a very long thread (that we don't want to revisit) in the mail
> > archive about sacred over other transports. Let's just say that concensus
> > was reached on specifying the BEEP profile, which is what the current
> > draft does.
> >
> > If you want to write up an I-D specifying how to run the sacred protocol
> > over another transport, then go right ahead. I for one would be glad to
> > see it (but first read the mail archive!).
> >
> > [email protected] wrote:
> > >
> > > > Hi Bill,
> > > >
> > > > These are probably BEEP artefacts.
> > > >
> > > > [email protected] wrote:
> > > > >
> > > > > a thought or two.
> > > > > most of the protocol stanzas state: "... operation REQUIRES mutual authent..."
> > > > > but the following paragraphs discuss single-pass transactions, e.g.
> > > > >         ... client sends request ...
> > > > >         ... the server MUST ....
> > > > > (2.1.3 for example)
> > > > >
> > > > > where is the authentication step?
> > > >
> > > > That's happened in the SASL &/or TLS exchanges in BEEP.
> > >
> > >         what happens if the BEEP profile is not used?
> > >
> > > > > in 3.1, you use the term "tuning" which looks like the basis for what might
> > > > > be mutual authentication.  is this correct?
> > > >
> > > > Yeah. "Tuning" is a BEEP term of art.
> > > >
> > > > I'll try clarify these some more, (but text suggestions appreciated),
> > >
> > >         so, state; "... authentication is required...."
> > >         and  "for the default profile, BEEP, the term for authentication
> > >         is tuning."
> >
> > I'm not sure that's quite right, but maybe Marshall can suggest something better.
> >
> > Stephen.
> >
> > --
> > ____________________________________________________________
> > Stephen Farrell
> > Baltimore Technologies,   tel: (direct line) +353 1 881 6716
> > 39 Parkgate Street,                     fax: +353 1 881 7000
> > Dublin 8.                mailto:[email protected]
> > Ireland                             http://www.baltimore.com
> >

-- 
____________________________________________________________
Stephen Farrell         				   
Baltimore Technologies,   tel: (direct line) +353 1 881 6716
39 Parkgate Street,                     fax: +353 1 881 7000
Dublin 8.                mailto:[email protected]
Ireland                             http://www.baltimore.com