beep+sasl+srp draft issues

Stephen Farrell <[email protected]>
Newsgroups gmane.ietf.sacred
Organization Baltimore Technologies Ltd.
Message-ID <[email protected]>

All,

In transforming the sacred-pdm draft to the above, I've come 
across the following issues, about which I'd appreciate your 
feedback and/or ideas.

- We want to hash the userid in case the user types her
password into the "username" box. We could do this above
SASL-SRP or else could try get the SASL-SRP draft to include
the trick itself (I prefer the latter). Any opinions?

- The sacred-pdm draft had an "extra" rsa private key which 
was used for signing credential uploads - do we want to 
maintain this feature? (The reason for it was to make
it harder to benefit from stealing the server's database.)

- SASL-SRP makes it easy to authenticate and derive keys for
credential download, changes etc, but what about initial
registration? Is that to be offline only or do we need
to have a credential deposit operation that uses some other
"in-payload" security?

- The sacred-pdm draft had some notes about "away-from-home"
operation, which is harder using SASL (unless we put the 
SASL PDUs in our payload as Magnus suggested). Do we want
to support this & if so, how?

I'm sure there'll be more as I go through it, but that's
enough for now.

Stephen.

-- 
____________________________________________________________
Stephen Farrell         				   
Baltimore Technologies,   tel: (direct line) +353 1 881 6716
39 Parkgate Street,                     fax: +353 1 881 7000
Dublin 8.                mailto:[email protected]
Ireland                             http://www.baltimore.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.