Re: authmeth-15: mandatory-to-implement strong authentication

"Roger Harrison" <[email protected]> Wed, 05 Oct 2005 09:29:45 -0600
Newsgroups gmane.ietf.ldapbis
Message-ID <[email protected]>
Kurt,
 
Your opinion was to remove requirements on using the DIGEST-MD5
authentication mechanism in such a way that the DIGEST-MD5 spec was no
longer normative. I support your approach as outlined in
 
http://www.openldap.org/lists/ietf-ldapbis/200509/msg00024.html
and I would recommend that we remove section 10 (SASL DIGEST-MD5
Authentication Mechanism) from authmeth and simply refer to RFC2829 as
an informative reference on this mechanism.
 
Roger

>>> "Kurt D. Zeilenga" <[email protected]> 10/5/2005 8:20:39 am >>>
At 06:42 AM 10/5/2005, Roger Harrison wrote:
>I've made this change to the requirements section of authmeth.  The
next question is what to do with section 10 (SASL DIGEST-MD5
Authentication Mechanism). Should we remove it from the ldapbis
specification and allow it to be referenced as part of RFC 2829, or
should I leave it in the ldapbis specification for informational
purposes? 

As co-chair, I think we need some more discussion on this.

As an individual contributor, I offered my opinion (and
specific recommendation) in:
http://www.openldap.org/lists/ietf-ldapbis/200509/msg00024.html

Kurt