Re: Fwd: New Version Notification for draft-ietf-uta-xmpp-03.txt
Peter Saint-Andre - &yet <[email protected]> Mon, 01 Dec 2014 18:31:39 -0700
| Newsgroups | gmane.ietf.xmpp |
|---|---|
| Message-ID | <[email protected]> |
BTW version -04 was intended to address this feedback: https://datatracker.ietf.org/doc/draft-ietf-uta-xmpp/ On 11/13/14, 4:08 PM, Peter Saint-Andre - &yet wrote: > Hi Dave, thanks for the feedback. > > On 11/12/14, 4:47 AM, Dave Cridland wrote: >> Lightning review: >> >> 1) §3.3 - I don't understand why session tickets would be bad compared >> to session ids? > > I freely admit that I don't understand the effective difference between > session IDs and session tickets for XMPP (or for TLS session resumption > in general). To my meager brain, the differences are not explained well > in the RFCs. Enlightenment would be appreciated. :-) > >> 2) Should there be a discussion about recommended SAN types? RFC 6120 >> currently says the only MTI is xmppAddr; RFC 6125 gives no MTI as I >> understand it. > > This is covered in §13.7.1.2.1 of RFC 6120. Perhaps a pointer to that > section would be helpful? > >> 3) If so, should we discuss wildcard resolution? Or not? RFC 5280 says >> wildcard resolution is within the scope of the application rather than >> TLS/PKIX itself. > > That's also covered in the aforementioned section of RFC 6120. However, > do we feel that it's time to revisit the text there? (BTW, Jeff Hodges > and I tried to kill off wildcard certs entirely in RFC 6125 but weren't > successful.) > >> 4) Finally, there's two different protocols in XMPP - C2S and S2S. It >> might be good to explicitly note the different requirements on these >> (the draft says C2S clients MUST authenticate servers, for example). > > And it doesn't say that servers need to authenticate peer servers over > s2s, which implies that unauthenticated s2s connections are allowed. > This is consistent with current practice. Are you suggesting that we > change the recommendation (e.g., SHOULD or MUST authenticate for s2s) or > at least make it explicit that unauthenticated s2s connections are allowed? > > Peter > _______________________________________________ xmpp mailing list [email protected] https://www.ietf.org/mailman/listinfo/xmpp