[NNTP] draft-ietf-nntpext-tls-nntp-02.txt

Clive D.W. Feather clive at demon.net
Fri Oct 1 04:55:10 PDT 2004


Russ Allbery said:
> SMTP says (RFC 3207):
> 
>      After the TLS handshake has been completed, both parties MUST
>      immediately decide whether or not to continue based on the
>      authentication and privacy achieved.
> 
> Note the absence of the word "successfully."  I think we should just adopt
> the SMTP language, which makes the problem go away -- a failed TLS
> handshake that allows recovery of the NNTP session is then completion of
> the TLS handshake, with no authentication and privacy achieved, and the
> client and server should then proceed as described in 3.2.1.  We can say
> something explicit about that if it seems useful.

I agree. [Minor nit: I would say "... based on *any* ...".]

-- 
Clive D.W. Feather  | Work:  <clive at demon.net>   | Tel:    +44 20 8495 6138
Internet Expert     | Home:  <clive at davros.org>  | Fax:    +44 870 051 9937
Demon Internet      | WWW: http://www.davros.org | Mobile: +44 7973 377646
Thus plc            |                            |



More information about the ietf-nntp mailing list