Re: Any drafts for IMAP4/TLS and/or POP3/TLS

[email protected] (David P. Kemp) Tue, 2 Sep 1997 09:43:38 -0400
Newsgroups gmane.ietf.apps-tls
Message-ID <[email protected]>
> From: David Brownell <[email protected]>
> 
>   [many good points snipped ..]
>
> Finally, I wonder where one would want to put a conventional set
> of Diffie-Hellman parameters (modulus, exponent) that "MAY" be used
> by TLS servers implementing this spec.  The virtue of having such a
> set which "MAY" be used is that to the extent they're widely used,
> clients can precompute their private keys, producing better TLS
> session setup times (one less prime search, one less modExp).
> Of course the idea is not to mandaate ("MUST") such parameters.
> There are both security and performance implications to the modulus
> (specifically, its size) being used.
> 
> Arguably such a set of parameters should be in the TLS spec.
> But, it's not there now, and not looking to be.  Perhaps it'd
> be approprate as a separate informational RFC, rather than as
> part of either the IETF's TLS or {IMAP4,POP3}/TLS specs.


If the IMAP/POP profile were to specify one or a few fixed DH
parameters, it may be worthwhile referencing the exponential groups in
the IPsec Oakley protocol, instead of writing up another document
with different parameters.