re: New version of TLS + IMAP/POP/ACAP draft
Lyndon Nerenberg <[email protected]> Wed, 25 Nov 1998 12:58:59 -0700
| Newsgroups | gmane.ietf.apps-tls |
|---|---|
| Message-ID | <[email protected]> |
> I am trying to suggest that there may not be a clear cut order, and that > local preferences will abound depending on the avaliable SASL or TLS > methods. I would expect a client to take the "CAPABILITY" of the server > and make a preference list based on that and what it's capabilities and > preferences are. It has to be a combination of client and server policy. In addition to what you describe above, the server should be making intelligent choices on which SASL mechanisms it exports, based on where the client is connecting from (e.g. "inside" vs. "outside"). The client side is the tough one -- it's not easy to present the policy selection in a manner that's intuitive to most people (who don't know about the workings of the security layers). Common sense also has to play a part, otherwise you can get into some pathological situations (like encrypted Kerberos inside a TLS session running over encrypted IPsec). -- Finger [email protected] for PGP key.