SASL capability (Was: [ietf-nntp] I-D ACTION:draft-ietf-nntpext-authinfo-00.txt)

Clive D.W. Feather clive at demon.net
Mon May 17 00:57:27 PDT 2004


Ken Murchison said:
>> Section 2#3: I don't like the separate SASL response to LIST EXTENSIONS.
>> This implies that there are two separate extensions, and there aren't. It
>> just doesn't fit the @@@@.

Gawd knows what I was thinking when I typed that ("@@@@" is my "I need to
go back and edit this" placeholder). Probably "It just doesn't fit the
conceptual model of NNTP extensions".

>> Instead of that, what's wrong with:

>>     AUTHINFO USER SASL:DIGEST-MD5,GSSAPI,PLAIN,EXTERNAL
> 
> I have no problems with this, or any variant.  Two variants which come 
> to mind would be:
> 
> AUTHINFO USER SASL(DIGEST-MD5,GSSAPI,PLAIN,EXTERNAL)
> 
> AUTHINFO USER SASL=DIGEST-MD5 SASL=GSSAPI SASL=PLAIN SASL=EXTERNAL
> 
> The latter is similar to the IMAP capability response.

I don't like the latter. It's more verbose than the others and it, to my
mind, puts more emphasis on the individual methods than on SASL itself. It
also means you can't easily locate all the SASL information: it would be
legal to have:

    AUTHINFO SASL=DIGEST-MD5 USER SASL=PLAIN XSIMPLE SASL=EXTERNAL

Of the other two:

     AUTHINFO USER SASL:DIGEST-MD5,GSSAPI,PLAIN,EXTERNAL
     AUTHINFO USER SASL(DIGEST-MD5,GSSAPI,PLAIN,EXTERNAL)

there's very little to choose between them. Mine has the extremely minor
benefit of not having to worry about what happens if the ) is missing; the
following white space delimits the list.

-- 
Clive D.W. Feather  | Work:  <clive at demon.net>   | Tel:    +44 20 8495 6138
Internet Expert     | Home:  <clive at davros.org>  | Fax:    +44 870 051 9937
Demon Internet      | WWW: http://www.davros.org | Mobile: +44 7973 377646
Thus plc            |                            |



More information about the ietf-nntp mailing list