RE: "POP3 SASL Authentication Mechanism" submitted for publication
"Kurt D. Zeilenga" <[email protected]> Mon, 15 Jan 2007 12:46:40 -0800
| Newsgroups | gmane.ietf.pop3ext,gmane.ietf.sasl |
|---|---|
| Message-ID | <[email protected]> |
At 12:02 PM 1/15/2007, Paul Leach wrote: >Since DIGEST-MD5 was the MTI for SASL in LDAP, I don't quite get the >complaints about implementability -- plenty of people did it as a >result. Was but is no longer LDAP's "strong" authentication method. LDAP's current "strong" authentication method is currently TLS-protected simple DN/password. LDAPbis concluded DIGEST-MD5 interoperability, especially in regards to security layers, just wasn't there. I don't think any of LDAPbis's concerns about DIGEST-MD5 were specific to LDAP. >I really think that all use of plain text passwords, even over an >encrypted tunnel to a trusted party, should be discouraged. (At >the very least, a stern passage in the security considerations section is needed.) I concur. -- Kurt