Re: forging a new pppext charter

James Carlson <[email protected]>
Newsgroups gmane.ietf.pppext
Message-ID <[email protected]>
Jari Arkko writes:
> > 	- Consider writing a new Proposed Standard version of PAP to
> > 	  complement RFC 1994.  I don't think that we're served well
> > 	  by leaving this out, and there are certainly important cases
> > 	  in which it's useful.
> 
> Your list sounds otherwise excellent, but I was surprised by this
> one. Why do we need PAP, shouldn't we be making it historic instead...?
> And isn't RFC 1334 already in obsoleted status? What are the important
> cases where PAP is useful?

I said "consider."  I've received private requests in the past to have
this done.

Personally, I have little stake in it.  RFC 1334 is already obsoleted,
and I think that's perhaps good enough.

The real issue (if there is one at all) is that PAP is still
operationally important, and is likely to be so for the indefinite
future.  In security terms, it's exactly equivalent to the traditional
"login:/Password:" interface and carries no more or less risk than
that does.  In particular, it allows access to existing user
authentication schemes (e.g., PAM) that don't require that the
password be stored in the clear, as is the case with CHAP.

If the consensus is "no way," that sounds as good to me.

-- 
James Carlson, IP Systems Group                <[email protected]>
Sun Microsystems / 1 Network Drive         71.234W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.497N   Fax +1 781 442 1677
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.