Re: forging a new pppext charter
Nagi <[email protected]>
| Newsgroups | gmane.ietf.pppext |
|---|---|
| Organization | Alcatel Telecom |
| Message-ID | <[email protected]> |
> Nagi wrote: > >>one. Why do we need PAP, shouldn't we be making it historic instead...? > >>And isn't RFC 1334 already in obsoleted status? What are the important > >>cases where PAP is useful? > >> > >> > > > > > > Jari, > > > > I'm not sure if any of the reply clarified your question. PAP is still in > > use for token cards authentication mechanism. The user reads the randomly > > generated number from token card and can send it as plain text password. > > I agree that there is little security concern at that particular time > > interval, say a minute or two. > > Sure. But even if it is in use, does that warrant a new RFC? Is there > something broken in the old RFC? > I don't think so. But I'm not sure if any one else thinks it is broken. -Nagi.