Re: Serious design flaw in STARTLS documents
[email protected] (John Myers) Tue, 21 Apr 1998 10:39:12 -0700
| Newsgroups | gmane.ietf.apps-tls |
|---|---|
| Message-ID | <[email protected]> |
Harald Tveit Alvestrand wrote: > I believe the flaw you indicate is generic to any protocol that > negotiates an integrity or security layer (the same problem arises > with negotiating GSSAPI protection using SASL). > > As such, there are 2 layers of fixes needed: > - Document the problem in the SASL specification, and possibly in > some document that generically describes "negotiating TLS" This is already documented; it is the last paragraph of the "Security Considerations" section of RFC 2222. We may need to make this issue more visible in the IMAP, etc. protocol specifications.