Re: Serious design flaw in STARTLS documents

[email protected] (John Myers) Tue, 21 Apr 1998 10:39:12 -0700
Newsgroups gmane.ietf.apps-tls
Message-ID <[email protected]>
Harald Tveit Alvestrand wrote:
> I believe the flaw you indicate is generic to any protocol that
> negotiates an integrity or security layer (the same problem arises
> with negotiating GSSAPI protection using SASL).
> 
> As such, there are 2 layers of fixes needed:
> - Document the problem in the SASL specification, and possibly in
>   some document that generically describes "negotiating TLS"

This is already documented; it is the last paragraph of the "Security
Considerations" section of RFC 2222.

We may need to make this issue more visible in the IMAP, etc. protocol
specifications.