RE: Question about how to proceed on PIC
"Glen Zorn" <[email protected]> Fri, 2 May 2003 13:14:38 -0700
| Newsgroups | gmane.ietf.ipsra |
|---|---|
| Organization | Cisco Systems |
| Message-ID | <[email protected]> |
> Greetings again. Hi, Paul. > As many of you know, PIC was sent to the RFC > Editor for publication, and before the RFC came out, a > security problem with the way that PIC, EAP, and other > related protocols do authentication was discovered. The problem is described in > detail in <http://www.ietf.org/internet-drafts/draft-puthenkulam-eap-binding-02.tx t>. > We now have a clearer idea on how to modify PIC to avoid the security problem, Cool! How is it done? ... > So our question to you is, should we fix PIC and get a standards-track RFC, an informational > RFC, or should we withdraw it? There is no reason for us to create an RFC that no one will > > implement. Serious question: was anybody actually planning to implement PIC _before_ the problems were discovered? > We want to hear from folks in the WG about this so we can decide to go forwards. --Paul Hoffman and Sara Bitan, WG chairs