-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 9/11/13 11:38 AM, Simon Josefsson wrote:
> Nico Williams <[email protected]> writes:
> 
>>> In version -04, based on PRECIS WG discussion, we changed that
>>> to:
>>> 
>>> 3.  Uppercase and titlecase characters SHOULD be mapped to
>>> their lowercase equivalents (not doing so can lead to false
>>> positives during authentication and authorization, as described
>>> in [RFC6943]).
>>> 
>> 
>> This is the third time, I think, that I've had to voice my
>> vehement objections to this.  I thought we were done the second
>> time.  I believe SASL applications and mechanisms MUST NOT do the
>> above, not on the client side, and that the server should be
>> allowed to do what it wishes.
> 
> If the text above would have any bearing on SASL implementations
> (which isn't clear to me), I would strongly agree with you that the
> text above is a Bad Idea.
> 
> Generally, I believe the use-case of I18N of username & password
> have special requirements that have been ignored by the PRECIS WG
> because the username/password requirements are sometimes
> conflicting with other goals of PRECIS and there doesn't seem to be
> enough interest to cater to both communities at the same time.
> Perhaps that is fine (I understand PRECIS wants to publish), but
> then it should be made clear that PRECIS will have no immediate
> bearing on SASLprepNG.

Hi Simon,

Actually that text comes from draft-ietf-precis-saslprepbis:

http://tools.ietf.org/html/draft-ietf-precis-saslprepbis-04#section-4.2

As I noted to Nico, we need to get this right and we need to take the
time to do so. Alexey and I are committed to doing that, and we'll
find a way to make it happen.

Peter

- -- 
Peter Saint-Andre
https://stpeter.im/


-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.19 (Darwin)
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBAgAGBQJSMLFkAAoJEOoGpJErxa2pfv4P/Roq3J1EiaVyQVBErahCX8Lz
b1HoYUgq0DfMYcTQtf69U8+MA9CFklaJiPOnaiWwZ0Wy7cXNTMMvNSBbDOFkbpiS
y0pgc6Y2mel2WRwlAgAjX45SB4cfSiAEToFeG8LBST8a5hpd5Bd6zTJFaY/vOQFX
e0yR99BpuPKy7DH9VGauWxFMGDOmTWo42YmBkcREwPbuuqdGttFgOqSRUxPDsQiS
VNdkfWygOKunZtRa5iV6dBsloCcZLuuQBjD7iw2tjeP6cEI85mKB+QruBY4V5n/0
Bff1YkwKAaKeR2GQfz1UZMqzFy/1Ko9SmoXiW+Cvt/utY1eqqD+9VPN5lg95IU4u
GrgxBT38DJmhvR0FuaFb6QKJDRVPWZG9mppj7Y8Qt/LZeZPvyvyDLKr1TBf7iMKz
QLU0Osak+2YGTVXKAFCv30522IgVMcTH54GSX99Ej+CDYbJEiqK9F1FmZBl1wNko
Pn9eHF31frZY4DaiLSQMyEws0p2a4CvqmBU03EPKE62J/tR7EoZSgB8cv2Dkuh1O
tAvZQ4cAHR2LLl3r7nHGcuFkqQiXACh+vYC52Xogl+GxfMFfGlvooKd80TakuJt9
9OYm0ojltWihVL+bJTriIAB3ZjtxkmPMaXKNNHya7emX9tOX2MQaYS8edpwPTpL/
LTOHtJGqsBM+k2LcaZ7Z
=Gat7
-----END PGP SIGNATURE-----
_______________________________________________
precis mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/precis

Reply via email to