Re: comments on draft-ietf-impp-cpim-pidf-05
[email protected] (John D. Ramsdell)
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
"Peterson, Jon" <[email protected]> writes: > Well, I would be surprised if anyone seriously contended that > RFC2779 did not require us to adopt a common format for end-to-end > security. Several of the requirements entail that directly. In the > absence of some baseline common security mechanism (and ciphersuite) > secure implementations will not be interoperable. I think we have a > mandate to come to consensus on a format. I fully agree with Jon Peterson on this point. It's the same situation we faced with notification authentication. It's hard to prove digital signatures are the only possible solution, but I have heard no one advance any other practical solution. In security text books, the chapter on authentication usually begins by discussing password and challenge/response systems, and then discusses digital signatures. I see no practical way to use a challenge/response system, so we seem to be stuck with digital signatures. John [reminder: [email protected] for non-technical discussions, please]