Re: Fwd: New Version Notification for draft-ietf-uta-xmpp-03.txt

Peter Saint-Andre - &yet <[email protected]> Mon, 01 Dec 2014 18:31:39 -0700
Newsgroups gmane.ietf.xmpp
Message-ID <[email protected]>
BTW version -04 was intended to address this feedback:

https://datatracker.ietf.org/doc/draft-ietf-uta-xmpp/

On 11/13/14, 4:08 PM, Peter Saint-Andre - &yet wrote:
> Hi Dave, thanks for the feedback.
>
> On 11/12/14, 4:47 AM, Dave Cridland wrote:
>> Lightning review:
>>
>> 1) §3.3 - I don't understand why session tickets would be bad compared
>> to session ids?
>
> I freely admit that I don't understand the effective difference between
> session IDs and session tickets for XMPP (or for TLS session resumption
> in general). To my meager brain, the differences are not explained well
> in the RFCs. Enlightenment would be appreciated. :-)
>
>> 2) Should there be a discussion about recommended SAN types? RFC 6120
>> currently says the only MTI is xmppAddr; RFC 6125 gives no MTI as I
>> understand it.
>
> This is covered in §13.7.1.2.1 of RFC 6120. Perhaps a pointer to that
> section would be helpful?
>
>> 3) If so, should we discuss wildcard resolution? Or not? RFC 5280 says
>> wildcard resolution is within the scope of the application rather than
>> TLS/PKIX itself.
>
> That's also covered in the aforementioned section of RFC 6120. However,
> do we feel that it's time to revisit the text there? (BTW, Jeff Hodges
> and I tried to kill off wildcard certs entirely in RFC 6125 but weren't
> successful.)
>
>> 4) Finally, there's two different protocols in XMPP - C2S and S2S. It
>> might be good to explicitly note the different requirements on these
>> (the draft says C2S clients MUST authenticate servers, for example).
>
> And it doesn't say that servers need to authenticate peer servers over
> s2s, which implies that unauthenticated s2s connections are allowed.
> This is consistent with current practice. Are you suggesting that we
> change the recommendation (e.g., SHOULD or MUST authenticate for s2s) or
> at least make it explicit that unauthenticated s2s connections are allowed?
>
> Peter
>

_______________________________________________
xmpp mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/xmpp