Re: Servers that just want to have TLS

Jeff Williams <[email protected]>
Newsgroups gmane.ietf.apps-tls
Organization IEG. INC.
Message-ID <[email protected]>
Chris,

  I think you are absolutely correct here.  Well put!

Chris Newman wrote:
> 
> On Thu, 8 May 1997, Paul E. Hoffman wrote:
> > And, I still want a general model for application protocols where the
> > client talks first.
> 
> First we need to realize that SMTP is a special case since it's an
> unauthenticated protocol by default.
> 
> Second, there's a more general problem of indicate that a higher security
> level is required.
> 
> For application protocols, the right thing to do is say NO to
> LOGIN/AUTHENTICATE commands until the right level of security is achieved
> for the desired user.
> 
> With IMAP, you'd get:
> 
> A001 NO [ENCRYPT-REQUIRED] Access not permitted without encryption
> 
> or
> 
> A001 NO [INTEGRITY-REQUIRED] Access not permitted without integrity
> protection
> 
> then you know STARTTLS or an equivalent SASL mechanism is needed.

Regards,
-- 
Jeffrey A. Williams
DIR. Internet Network Eng/SR. Java Development Eng.
Information Eng. Group. 
Phone :913-294-2375 (v- office)
E-Mail [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.