GIST TSL issue out of IESG review
"Martin Stiemerling" <[email protected]>
| Newsgroups | gmane.ietf.nsis |
|---|---|
| Message-ID | <[email protected]> |
Hi all, There is one open DISCUSS out of the IESG review of GIST we need to address: (ballot: https://datatracker.ietf.org/idtracker/ballot/1546/) Tim Polk's comment [2008-03-27]: Support for TLS is required, but different modes may be selected (e.g., different ciphersuites and authentication mechanisms). These changes significantly impact the security provided (and as a result, the degree to which the requirements in 4081 are met.) The security considerations section should elaborate on the impact of server-only vs. mutually authenticated TLS, as well as alternative authentication procedures, with respect to the various requirements. Any help is appreciated. Martin [email protected] NEC Laboratories Europe - Network Research Division NEC Europe Limited | Registered Office: NEC House, 1 Victoria Road, London W3 6BL | Registered in England 2832014