Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-08-05 Thread Jonas Schäfer
On Dienstag, 30. Juni 2020 17:59:34 CEST Jonas Schäfer wrote: > Hi list, > > (Editor hat on) > > On behalf of the Council, I’d like to bring this pull request to the > attention of the community: > > https://github.com/xsf/xeps/pull/963 Okay, this took me a long time to look at. I think

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-08-02 Thread Dave Cridland
My apologies for not replying to this one, though I think it's covered elsewhere in this discussion. For completeness: On Wed, 1 Jul 2020 at 13:28, Philipp Hancke wrote: > If the receiving server follows the process described in #9 of >https://xmpp.org/extensions/xep-0178.html#s2s > which

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-09 Thread Ruslan N. Marchenko
Am Donnerstag, den 09.07.2020, 11:27 +0100 schrieb Dave Cridland: > On Wed, 8 Jul 2020 at 12:44, Ruslan N. Marchenko > wrote: > > Am Dienstag, den 07.07.2020, 10:55 +0100 schrieb Dave Cridland: > > > If Alice connects and authenticates Bob via some means, and Bob > > > authenticates Alice by some

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-09 Thread Dave Cridland
On Wed, 8 Jul 2020 at 12:44, Ruslan N. Marchenko wrote: > Am Dienstag, den 07.07.2020, 10:55 +0100 schrieb Dave Cridland: > > > > On Mon, 6 Jul 2020 at 15:41, Ruslan N. Marchenko wrote: > > Am Montag, den 06.07.2020, 16:20 +0200 schrieb Ruslan N. Marchenko: > > Am Montag, den 06.07.2020, 13:19

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-08 Thread Ruslan N. Marchenko
Am Dienstag, den 07.07.2020, 10:55 +0100 schrieb Dave Cridland: > On Mon, 6 Jul 2020 at 15:41, Ruslan N. Marchenko > wrote: > > Am Montag, den 06.07.2020, 16:20 +0200 schrieb Ruslan N. Marchenko: > > > Am Montag, den 06.07.2020, 13:19 +0100 schrieb Dave Cridland: > > > > On Mon, 6 Jul 2020 at

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-07 Thread Dave Cridland
On Mon, 6 Jul 2020 at 15:41, Ruslan N. Marchenko wrote: > Am Montag, den 06.07.2020, 16:20 +0200 schrieb Ruslan N. Marchenko: > > Am Montag, den 06.07.2020, 13:19 +0100 schrieb Dave Cridland: > > > > On Mon, 6 Jul 2020 at 12:44, Ruslan N. Marchenko wrote: > > Am Montag, den 06.07.2020, 10:46

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-06 Thread Ruslan N. Marchenko
Am Montag, den 06.07.2020, 16:20 +0200 schrieb Ruslan N. Marchenko: > Am Montag, den 06.07.2020, 13:19 +0100 schrieb Dave Cridland: > > On Mon, 6 Jul 2020 at 12:44, Ruslan N. Marchenko > > wrote: > > > Am Montag, den 06.07.2020, 10:46 +0100 schrieb Dave Cridland: > > > > On Sun, 5 Jul 2020 at

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-06 Thread Ruslan N. Marchenko
Am Montag, den 06.07.2020, 13:19 +0100 schrieb Dave Cridland: > On Mon, 6 Jul 2020 at 12:44, Ruslan N. Marchenko > wrote: > > Am Montag, den 06.07.2020, 10:46 +0100 schrieb Dave Cridland: > > > On Sun, 5 Jul 2020 at 22:13, Ruslan N. Marchenko > > > wrote: > > > > Am Samstag, den 04.07.2020,

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-06 Thread Dave Cridland
On Mon, 6 Jul 2020 at 12:44, Ruslan N. Marchenko wrote: > Am Montag, den 06.07.2020, 10:46 +0100 schrieb Dave Cridland: > > > > On Sun, 5 Jul 2020 at 22:13, Ruslan N. Marchenko wrote: > > Am Samstag, den 04.07.2020, 19:47 +0100 schrieb Dave Cridland: > > > > On Thu, 2 Jul 2020 at 06:58, Ruslan

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-06 Thread Ruslan N. Marchenko
Am Montag, den 06.07.2020, 10:46 +0100 schrieb Dave Cridland: > On Sun, 5 Jul 2020 at 22:13, Ruslan N. Marchenko > wrote: > > Am Samstag, den 04.07.2020, 19:47 +0100 schrieb Dave Cridland: > > > On Thu, 2 Jul 2020 at 06:58, Ruslan N. Marchenko > > > wrote: > > > > Am Mittwoch, den 01.07.2020,

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-06 Thread Dave Cridland
On Sun, 5 Jul 2020 at 22:13, Ruslan N. Marchenko wrote: > Am Samstag, den 04.07.2020, 19:47 +0100 schrieb Dave Cridland: > > > > On Thu, 2 Jul 2020 at 06:58, Ruslan N. Marchenko wrote: > > Am Mittwoch, den 01.07.2020, 22:53 +0100 schrieb Dave Cridland: > > > > On Wed, 1 Jul 2020 at 17:31,

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-05 Thread Ruslan N. Marchenko
Am Samstag, den 04.07.2020, 19:47 +0100 schrieb Dave Cridland: > On Thu, 2 Jul 2020 at 06:58, Ruslan N. Marchenko > wrote: > > Am Mittwoch, den 01.07.2020, 22:53 +0100 schrieb Dave Cridland: > > > On Wed, 1 Jul 2020 at 17:31, Ruslan N. Marchenko > > > wrote: > > > > Because Alice's

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-04 Thread Dave Cridland
On Thu, 2 Jul 2020 at 06:58, Ruslan N. Marchenko wrote: > Am Mittwoch, den 01.07.2020, 22:53 +0100 schrieb Dave Cridland: > > > > On Wed, 1 Jul 2020 at 17:31, Ruslan N. Marchenko wrote: > > > Because Alice's authentication fails on this particualr conneciton? So it > may be not Alice after all

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-01 Thread Ruslan N. Marchenko
Am Mittwoch, den 01.07.2020, 22:53 +0100 schrieb Dave Cridland: > On Wed, 1 Jul 2020 at 17:31, Ruslan N. Marchenko > wrote: > > Because Alice's authentication fails on this particualr conneciton? > > So it may be not Alice after all speaking, despite what 'from' > > tells (or does not). From

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-01 Thread Dave Cridland
On Wed, 1 Jul 2020 at 17:31, Ruslan N. Marchenko wrote: > Am Mittwoch, den 01.07.2020, 10:37 +0100 schrieb Dave Cridland: > > > > On Tue, 30 Jun 2020 at 17:59, Ruslan N. Marchenko wrote: > > Am Dienstag, den 30.06.2020, 17:59 +0200 schrieb Jonas Schäfer: > > Hi list, > > > > (Editor hat on) > >

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-01 Thread Ruslan N. Marchenko
Am Mittwoch, den 01.07.2020, 10:37 +0100 schrieb Dave Cridland: > On Tue, 30 Jun 2020 at 17:59, Ruslan N. Marchenko > wrote: > > Am Dienstag, den 30.06.2020, 17:59 +0200 schrieb Jonas Schäfer: > > > > > Hi list, > > > > > > > > > > (Editor hat on) > > > > > > > > > > On behalf of the

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-01 Thread Philipp Hancke
If the receiving server follows the process described in #9 of https://xmpp.org/extensions/xep-0178.html#s2s which says that you do the authentication at this point (and then again in #11) how can external fail? If the receiving server can not authenticate the request its a policy decision to

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-01 Thread Dave Cridland
On Tue, 30 Jun 2020 at 19:59, Holger Weiß wrote: > * Jonas Schäfer [2020-06-30 17:59]: > > On behalf of the Council, I'd like to bring this pull request to the > attention > > of the community: > > > > https://github.com/xsf/xeps/pull/963 > > Wait, is this PR actually modifying the

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-01 Thread Dave Cridland
On Wed, 1 Jul 2020 at 10:41, Dave Cridland wrote: > > > On Tue, 30 Jun 2020 at 19:46, Kim Alvefur wrote: > >> This does result in a number of different possible configurations. Not >> great for something security related. Personally I hope we might be able >> to phase out Dialback in the

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-01 Thread Dave Cridland
On Tue, 30 Jun 2020 at 19:46, Kim Alvefur wrote: > This does result in a number of different possible configurations. Not > great for something security related. Personally I hope we might be able > to phase out Dialback in the future. Today, largely thanks to Let's > Encrypt, more and more

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-07-01 Thread Dave Cridland
On Tue, 30 Jun 2020 at 17:59, Ruslan N. Marchenko wrote: > Am Dienstag, den 30.06.2020, 17:59 +0200 schrieb Jonas Schäfer: > > Hi list, > > > > (Editor hat on) > > > > On behalf of the Council, I’d like to bring this pull request to the > > attention > > of the community: > > > >

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-06-30 Thread Holger Weiß
* Jonas Schäfer [2020-06-30 17:59]: > On behalf of the Council, I'd like to bring this pull request to the > attention > of the community: > > https://github.com/xsf/xeps/pull/963 Wait, is this PR actually modifying the authentication step it intends to change? I was assuming we're talking

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-06-30 Thread Kim Alvefur
Hello list On Tue, Jun 30, 2020 at 05:59:34PM +0200, Jonas Schäfer wrote: > https://github.com/xsf/xeps/pull/963 > > Input from server operators specifically would be welcomed to see if > this change is in fact desirable or if you can see any issues with > that. At least one member of the

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-06-30 Thread Ruslan N. Marchenko
Am Dienstag, den 30.06.2020, 19:27 +0200 schrieb Holger Weiß: > * Ruslan N. Marchenko [2020-06-30 18:58]: > > Now if EXTERNAL fails - that means there's something wrong with the > > certificates. And proposal to fail back to dialback means we want > > to > > tolerate certificate validation

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-06-30 Thread Holger Weiß
* Ruslan N. Marchenko [2020-06-30 18:58]: > Now if EXTERNAL fails - that means there's something wrong with the > certificates. And proposal to fail back to dialback means we want to > tolerate certificate validation errors. Which is a downgrade. Whether or not this downgrade is acceptable is a

Re: [Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-06-30 Thread Ruslan N. Marchenko
Am Dienstag, den 30.06.2020, 17:59 +0200 schrieb Jonas Schäfer: > Hi list, > > (Editor hat on) > > On behalf of the Council, I’d like to bring this pull request to the > attention > of the community: > > https://github.com/xsf/xeps/pull/963 > > Input from server operators specifically would

[Standards] XEP-0178: Clarify SASL-EXTERNAL specification when s2s auth fails

2020-06-30 Thread Jonas Schäfer
Hi list, (Editor hat on) On behalf of the Council, I’d like to bring this pull request to the attention of the community: https://github.com/xsf/xeps/pull/963 Input from server operators specifically would be welcomed to see if this change is in fact desirable or if you can see any issues