Re: Fwd: "POP3 SASL Authentication Mechanism" submitted for publication

Alexey Melnikov <[email protected]> Mon, 15 Jan 2007 11:36:17 +0000
Newsgroups gmane.ietf.pop3ext,gmane.ietf.sasl
Message-ID <[email protected]>
Simon Josefsson wrote:

>Abhijit Menon-Sen <[email protected]> writes:
>  
>
>>>A mandatory CRAM-MD5 as recommended in BCP 46 could make sense
>>>      
>>>
>>This draft (and rfc2554bis, which Alexey is editing) were both changed
>>to use DIGEST-MD5 based on concerns about security. That's the way it
>>was when I started editing it, so I'll change it only if there's clear
>>consensus about the preferred replacement.
>>
>>Having implemented both client and server sides of DIGEST-MD5, I can't
>>say I'm very fond of it either. Personally, I'd be happy with TLS+PLAIN
>>or CRAM-MD5 (or whatever else makes everyone happy without a significant
>>security penalty; and I gather CRAM-MD5 is frowned upon in that regard).
>>    
>>
>I prefer TLS+PLAIN
>
That would be fine with me, even though I somewhat dislike of having 
dependency on TLS.

>and TLS+CRAM-MD5
>
This doesn't give anything over TLS+PLAIN and also doesn't support 
authorization identity.
I am against this choice.

>over DIGEST-MD5 as well.  I
>believe they both offer better interoperability and security than
>DIGEST-MD5 currently can.
>  
>