Re: comments on draft-ietf-impp-cpim-pidf-05

[email protected] (John D. Ramsdell)
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
"Peterson, Jon" <[email protected]> writes:

> Well, I would be surprised if anyone seriously contended that
> RFC2779 did not require us to adopt a common format for end-to-end
> security. Several of the requirements entail that directly. In the
> absence of some baseline common security mechanism (and ciphersuite)
> secure implementations will not be interoperable. I think we have a
> mandate to come to consensus on a format.

I fully agree with Jon Peterson on this point.  It's the same
situation we faced with notification authentication.  It's hard to
prove digital signatures are the only possible solution, but I have
heard no one advance any other practical solution.  In security text
books, the chapter on authentication usually begins by discussing
password and challenge/response systems, and then discusses digital
signatures.  I see no practical way to use a challenge/response
system, so we seem to be stuck with digital signatures.

John



  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.