logo       

[Protocol] clarification on StartTLS resonse (WAS: authmeth-15 notes): msg#00021

ietf.ldapbis

Subject: [Protocol] clarification on StartTLS resonse (WAS: authmeth-15 notes)

> > 3.1.2. StartTLS Response

> >

> >    The server will return a resultCode other than success (as

> >    documented in [Protocol] section 4.13.2.2) if it is unwilling or

> >    unable to negotiate TLS. In this case the LDAP session is left

> >    without a TLS layer.

>

> This only says what happens at non‑success, not at success.

> [Protocol] is rather sparse about it too.

Based on Hallvard's query above, Jim Sermersheim and I recommend a change to paragraph 2 of [Protocol] section 14.4.2 to explicitly state that a success resultCode indicates that the protocol peers should begin TLS negotiation. I'll leave it to Jim to craft the wording.

Thanks,

Roger

<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise