Question about how to proceed on PIC
Paul Hoffman / VPNC <[email protected]> Fri, 2 May 2003 08:12:50 -0700
| Newsgroups | gmane.ietf.ipsra |
|---|---|
| Message-ID | <p05210605bad83b349146@[63.202.92.152]> |
Greetings again. As many of you know, PIC was sent to the RFC Editor for publication, and before the RFC came out, a security problem with the way that PIC, EAP, and other related protocols do authentication was discovered. The problem is described in detail in <http://www.ietf.org/internet-drafts/draft-puthenkulam-eap-binding-02.txt>. We now have a clearer idea on how to modify PIC to avoid the security problem, but in the meantime, IKEv2 has moved much closer to being finished. IKEv2 includes a single standard method for doing legacy authentication. Also, we have heard little or no interest in deploying PIC. So our question to you is, should we fix PIC and get a standards-track RFC, an informational RFC, or should we withdraw it? There is no reason for us to create an RFC that no one will implement. We want to hear from folks in the WG about this so we can decide to go forwards. --Paul Hoffman and Sara Bitan, WG chairs