Re: WGLC of draft-ietf-xmpp-posh-02
Peter Saint-Andre - &yet <[email protected]> Fri, 07 Nov 2014 09:03:31 -0700
| Newsgroups | gmane.ietf.xmpp |
|---|---|
| Message-ID | <[email protected]> |
On 11/6/14, 8:49 PM, Peter Saint-Andre wrote:
> On 10/25/14, 2:41 AM, Philipp Hancke wrote:
>
>> section 5:
>> The TLS client SHOULD perform all POSH retrievals
>> before opening any socket connections to the application
>> protocol server.
>> (ed: extra whitespace before that sentence)
>>
>> SHOULD is too strong here. I see it as a fallback rather and would only
>> do POSH when not finding a proper identity. This would mean that
>> sometimes, POSH is used without need.
>> I suspect this makes it easier to use POSH as part of the TLS handshake
>> rather than as an application layer check.
>>
>> This is also not possible for the s2s scenario where POSH may be
>> triggered by an incoming
>> <db:result>somekeywhichwouldnotbeused</db:result>
>> which would happen after <starttls/> and after the TLS handshake itself
>> is done.
>>
>> Should be easy to fix though.
>
> Yes, Matt and I will do some wordsmithing.
I propose the following:
In cases where the POSH client initiates an
application-layer connection, the client SHOULD perform all POSH
retrievals before initiating a connection (naturally this is not
possible in cases where the POSH client receives an application-layer
connection).
Peter
--
Peter Saint-Andre
https://andyet.com/