Re: Fwd: "POP3 SASL Authentication Mechanism" submitted for publication
Simon Josefsson <[email protected]> Sun, 14 Jan 2007 20:55:39 +0100
| Newsgroups | gmane.ietf.pop3ext,gmane.ietf.sasl |
|---|---|
| Message-ID | <[email protected]> |
Abhijit Menon-Sen <[email protected]> writes: >> A mandatory CRAM-MD5 as recommended in BCP 46 could make sense > > This draft (and rfc2554bis, which Alexey is editing) were both changed > to use DIGEST-MD5 based on concerns about security. That's the way it > was when I started editing it, so I'll change it only if there's clear > consensus about the preferred replacement. > > Having implemented both client and server sides of DIGEST-MD5, I can't > say I'm very fond of it either. Personally, I'd be happy with TLS+PLAIN > or CRAM-MD5 (or whatever else makes everyone happy without a significant > security penalty; and I gather CRAM-MD5 is frowned upon in that regard). I prefer TLS+PLAIN and TLS+CRAM-MD5 over DIGEST-MD5 as well. I believe they both offer better interoperability and security than DIGEST-MD5 currently can. /Simon