Re: KITTEN BOF at IETF 60?
Nicolas Williams <[email protected]> Mon, 22 Mar 2004 16:28:12 -0600
| Newsgroups | gmane.ietf.cat |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Mar 22, 2004 at 05:23:23PM -0500, Sam Hartman wrote: > I think I agree with Martin here. Channel bindings in GSSAPI V2 have > not proven to be a feature that is as portable or robust as the rest > of the spec. > > I think they are a strong candidate for dropping in advancing GSSAPI > V2 to draft. OF course you cannot just drop them because doing so > would be backward incompatible. I'm not quite sure how you indicate > this, but Martin's suggested approach seems like a fine idea to run > past the IESG. I don't agree that they can be dropped, just that they can be made optional to support for all mechanisms (except those that, like CCM, will require the use of channel bindings). > But my personal preference is to enhance channel bindings for > cryptographic keys until they can (and are) portably used in GSSAPI V3 With IPsec we won't use cryptographic keys, after all. We'll use the IPsec initiator and responder IDs bound to the channel. Nico -- -++**==--++**==--++**==--++**==--++**==--++**==--++**== This message was posted through the Stanford campus mailing list server. If you wish to unsubscribe from this mailing list, send the message body of "unsubscribe ietf-cat-wg" to [email protected]