Re: WGLC of draft-ietf-xmpp-posh-02

Peter Saint-Andre - &yet <[email protected]> Fri, 07 Nov 2014 09:03:31 -0700
Newsgroups gmane.ietf.xmpp
Message-ID <[email protected]>
On 11/6/14, 8:49 PM, Peter Saint-Andre wrote:
> On 10/25/14, 2:41 AM, Philipp Hancke wrote:
>
>> section 5:
>>      The TLS client SHOULD perform all POSH retrievals
>>      before opening any socket connections to the application
>>      protocol server.
>> (ed: extra whitespace before that sentence)
>>
>> SHOULD is too strong here. I see it as a fallback rather and would only
>> do POSH when not finding a proper identity. This would mean that
>> sometimes, POSH is used without need.
>> I suspect this makes it easier to use POSH as part of the TLS handshake
>> rather than as an application layer check.
>>
>> This is also not possible for the s2s scenario where POSH may be
>> triggered by an incoming
>> <db:result>somekeywhichwouldnotbeused</db:result>
>> which would happen after <starttls/> and after the TLS handshake itself
>> is done.
>>
>> Should be easy to fix though.
>
> Yes, Matt and I will do some wordsmithing.

I propose the following:

    In cases where the POSH client initiates an
    application-layer connection, the client SHOULD perform all POSH
    retrievals before initiating a connection (naturally this is not
    possible in cases where the POSH client receives an application-layer
    connection).

Peter

-- 
Peter Saint-Andre
https://andyet.com/