Re: Ciphersuites Re: [Syslog] Updated Syslog-tls Document

2006-11-28 Thread tom.petch
Original Message - From: "Miao Fuyou" <[EMAIL PROTECTED]> To: "'Rainer Gerhards'" <[EMAIL PROTECTED]>; "'tom.petch'" <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]> Sent: Monday, November 27, 2006 7:58 AM Subject: RE: Ci

RE: [Syslog] Updated Syslog-tls Document

2006-11-28 Thread Rainer Gerhards
yslog] Updated Syslog-tls Document > > That wording satisfies me. > > dbh > > > -Original Message- > > From: Miao Fuyou [mailto:[EMAIL PROTECTED] > > Sent: Monday, November 27, 2006 9:07 PM > > To: 'David Harrington'; 'Rainer Ger

RE: [Syslog] Updated Syslog-tls Document

2006-11-27 Thread David Harrington
That wording satisfies me. dbh > -Original Message- > From: Miao Fuyou [mailto:[EMAIL PROTECTED] > Sent: Monday, November 27, 2006 9:07 PM > To: 'David Harrington'; 'Rainer Gerhards'; [EMAIL PROTECTED] > Subject: RE: [Syslog] Updated Syslog-tls

RE: [Syslog] Updated Syslog-tls Document

2006-11-27 Thread Miao Fuyou
you'; [EMAIL PROTECTED] > Subject: RE: [Syslog] Updated Syslog-tls Document > > > > > -Original Message- > > From: Rainer Gerhards [mailto:[EMAIL PROTECTED] > > Sent: Thursday, November 23, 2006 2:48 AM > > To: Miao

RE: [Syslog] Updated Syslog-tls Document

2006-11-27 Thread David Harrington
> -Original Message- > From: Rainer Gerhards [mailto:[EMAIL PROTECTED] > Sent: Thursday, November 23, 2006 2:48 AM > To: Miao Fuyou; [EMAIL PROTECTED] > Subject: RE: [Syslog] Updated Syslog-tls Document > > > - > > >

RE: Ciphersuites Re: [Syslog] Updated Syslog-tls Document

2006-11-26 Thread Miao Fuyou
gt; Subject: RE: Ciphersuites Re: [Syslog] Updated Syslog-tls Document > > Tom, Miao, > > might it be a compromise to add a sentence to -transport-tls > that tells an implementor to look for mandatory to implement > suites inside the TLS document. Something like > > &quo

RE: Ciphersuites Re: [Syslog] Updated Syslog-tls Document

2006-11-23 Thread Rainer Gerhards
] > Subject: RE: Ciphersuites Re: [Syslog] Updated Syslog-tls Document > > > My observation about ciphersuite: > 1, TLS wg can do a better job on ciphersuite selection than a profile > developer. > 2, TLS specification will be updated if the mandatory cipher > is t

RE: Ciphersuites Re: [Syslog] Updated Syslog-tls Document

2006-11-23 Thread Miao Fuyou
My observation about ciphersuite: 1, TLS wg can do a better job on ciphersuite selection than a profile developer. 2, TLS specification will be updated if the mandatory cipher is too weak to provide appropriate protection, but profile-specific suite may not be updated accordingly. 3, Before TLS

Ciphersuites Re: [Syslog] Updated Syslog-tls Document

2006-11-23 Thread tom.petch
Tom Petch - Original Message - From: "Rainer Gerhards" <[EMAIL PROTECTED]> To: "Miao Fuyou" <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]> Sent: Thursday, November 23, 2006 8:47 AM Subject: RE: [Syslog] Updated Syslog-tls Document Hi Miao, Rainer &

RE: [Syslog] Updated Syslog-tls Document

2006-11-23 Thread Miao Fuyou
> > Probably lower case. The point is confidentility is meaningless > > without authenticaion. > > Well... maybe it is just a wording issue. Are we actually > REQUIREING a sender to authenticate the receiver in all > cases? If so, we should state that. My impression so far is > that this is

RE: [Syslog] Updated Syslog-tls Document

2006-11-22 Thread Rainer Gerhards
Hi Miao, Rainer > -Original Message- > From: Miao Fuyou [mailto:[EMAIL PROTECTED] > Sent: Thursday, November 23, 2006 3:38 AM > To: Rainer Gerhards; [EMAIL PROTECTED] > Subject: RE: [Syslog] Updated Syslog-tls Document > > Hi, Rainer, > > Thanks for your

RE: [Syslog] Updated Syslog-tls Document

2006-11-22 Thread Rainer Gerhards
Miao, > -Original Message- > From: Miao Fuyou [mailto:[EMAIL PROTECTED] > Sent: Thursday, November 23, 2006 2:24 AM > To: Rainer Gerhards > Cc: [EMAIL PROTECTED] > Subject: RE: [Syslog] Updated Syslog-tls Document > > > > > The public messege c

RE: [Syslog] Updated Syslog-tls Document

2006-11-22 Thread Miao Fuyou
Hi, Rainer, Thanks for your thorough review! Some responses are inline. > - > 3.0 > == > The security service is also applicable to BSD Syslog defined in >RFC3164 [7]. But, it is not ensured that the protocol > specification >defined in this docum

RE: [Syslog] Updated Syslog-tls Document

2006-11-22 Thread Miao Fuyou
> > The public messege can be found at: > > http://www1.ietf.org/mail-archive/web/syslog/current/msg01273.html > > > > It seems there was a rough concensus that the version number was > > welcomed to save port resource when we discussed this issue on the > > mailing list. That is the reason why

RE: [Syslog] Updated Syslog-tls Document

2006-11-22 Thread Rainer Gerhards
Tom, > > Ports may or may not be scarce but they are expensive. > Introduce a new one and > - anyone with firewall > - anyone with an application level gateway > - anyone with a packet filtering router > has to go out and change each and every box to reflect the > new assignment, a > slow a

Re: [Syslog] Updated Syslog-tls Document

2006-11-22 Thread tom.petch
- Original Message - From: "Rainer Gerhards" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]>; "Miao Fuyou" <[EMAIL PROTECTED]> Cc: <[EMAIL PROTECTED]> Sent: Wednesday, November 22, 2006 10:12 AM Subject: RE: [Syslog] Updated Syslog-tls Document

RE: [Syslog] Updated Syslog-tls Document

2006-11-22 Thread Rainer Gerhards
> -Original Message- > From: Miao Fuyou [mailto:[EMAIL PROTECTED] > Sent: Wednesday, November 22, 2006 10:40 AM > To: Rainer Gerhards; [EMAIL PROTECTED] > Cc: [EMAIL PROTECTED] > Subject: RE: [Syslog] Updated Syslog-tls Document > > > > > I questio

RE: [Syslog] Updated Syslog-tls Document

2006-11-22 Thread Rainer Gerhards
Hi Miao, thanks for the update. I have gone through the draft again and found some, mostly minor, issue. I have listed them below: - 3.0 == The security service is also applicable to BSD Syslog defined in RFC3164 [7]. But, it is not ensured that the proto

RE: [Syslog] Updated Syslog-tls Document

2006-11-22 Thread Miao Fuyou
> > I questioned the need for a version number for the TLS transport in > > private conversation and now I bring this up again here. > > Was that private? I thought it was on-list. Anyhow... I The public messege can be found at: http://www1.ietf.org/mail-archive/web/syslog/current/msg01273.htm

RE: [Syslog] Updated Syslog-tls Document

2006-11-22 Thread Rainer Gerhards
> -Original Message- > From: Juergen Schoenwaelder [mailto:[EMAIL PROTECTED] > Sent: Wednesday, November 22, 2006 9:09 AM > To: Miao Fuyou > Cc: [EMAIL PROTECTED] > Subject: Re: [Syslog] Updated Syslog-tls Document > > On Wed, Nov 22, 2006 at 09:12:38AM

Re: [Syslog] Updated Syslog-tls Document

2006-11-22 Thread Juergen Schoenwaelder
On Wed, Nov 22, 2006 at 09:12:38AM +0800, Miao Fuyou wrote: > There are two major changes since last update. > 1, Section 3 is removed. It is an introductory text on TLS, and is neccesary > because TLS is already a normative reference. > 2, Updated the section 4.3.2 (original 5.3.2), removed the