re: New version of TLS + IMAP/POP/ACAP draft

Lyndon Nerenberg <[email protected]> Wed, 25 Nov 1998 12:58:59 -0700
Newsgroups gmane.ietf.apps-tls
Message-ID <[email protected]>
> I am trying to suggest that there may not be a clear cut order, and that
> local preferences will abound depending on the avaliable SASL or TLS
> methods. I would expect a client to take the "CAPABILITY" of the server
> and make a preference list based on that and what it's capabilities and
> preferences are.

It has to be a combination of client and server policy. In addition to
what you describe above, the server should be making intelligent
choices on which SASL mechanisms it exports, based on where the client
is connecting from (e.g. "inside" vs. "outside"). The client side is
the tough one -- it's not easy to present the policy selection in a
manner that's intuitive to most people (who don't know about the
workings of the security layers). Common sense also has to play a part,
otherwise you can get into some pathological situations (like encrypted
Kerberos inside a TLS session running over encrypted IPsec).
-- 
Finger [email protected] for PGP key.