Re: forging a new pppext charter
James Carlson <[email protected]>
| Newsgroups | gmane.ietf.pppext |
|---|---|
| Message-ID | <[email protected]> |
Jari Arkko writes: > > - Consider writing a new Proposed Standard version of PAP to > > complement RFC 1994. I don't think that we're served well > > by leaving this out, and there are certainly important cases > > in which it's useful. > > Your list sounds otherwise excellent, but I was surprised by this > one. Why do we need PAP, shouldn't we be making it historic instead...? > And isn't RFC 1334 already in obsoleted status? What are the important > cases where PAP is useful? I said "consider." I've received private requests in the past to have this done. Personally, I have little stake in it. RFC 1334 is already obsoleted, and I think that's perhaps good enough. The real issue (if there is one at all) is that PAP is still operationally important, and is likely to be so for the indefinite future. In security terms, it's exactly equivalent to the traditional "login:/Password:" interface and carries no more or less risk than that does. In particular, it allows access to existing user authentication schemes (e.g., PAM) that don't require that the password be stored in the clear, as is the case with CHAP. If the consensus is "no way," that sounds as good to me. -- James Carlson, IP Systems Group <[email protected]> Sun Microsystems / 1 Network Drive 71.234W Vox +1 781 442 2084 MS UBUR02-212 / Burlington MA 01803-2757 42.497N Fax +1 781 442 1677