Re: forging a new pppext charter
Barney Wolff <[email protected]>
| Newsgroups | gmane.ietf.pppext |
|---|---|
| Message-ID | <[email protected]> |
On Tue, Feb 17, 2004 at 01:24:20PM -0500, James Carlson wrote: > > The real issue (if there is one at all) is that PAP is still > operationally important, and is likely to be so for the indefinite > future. In security terms, it's exactly equivalent to the traditional > "login:/Password:" interface and carries no more or less risk than > that does. In particular, it allows access to existing user > authentication schemes (e.g., PAM) that don't require that the > password be stored in the clear, as is the case with CHAP. PAP works for token cards, although I suppose EAP is a better choice. But the PAP/CHAP decision is entangled with the unfortunate design of RADIUS that the PAP password is encrypted but the CHAP challenge and response are not, thus exposing the CHAP secret to offline dictionary attack. I also volunteer to participate in writing/editing updated RFCs, and add my thanks to Karl. Regards, Barney -- Barney Wolff http://www.databus.com/bwresume.pdf I'm available by contract or FT, in the NYC metro area or via the 'Net.