beep+sasl+srp draft issues
Stephen Farrell <[email protected]>
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Organization | Baltimore Technologies Ltd. |
| Message-ID | <[email protected]> |
All, In transforming the sacred-pdm draft to the above, I've come across the following issues, about which I'd appreciate your feedback and/or ideas. - We want to hash the userid in case the user types her password into the "username" box. We could do this above SASL-SRP or else could try get the SASL-SRP draft to include the trick itself (I prefer the latter). Any opinions? - The sacred-pdm draft had an "extra" rsa private key which was used for signing credential uploads - do we want to maintain this feature? (The reason for it was to make it harder to benefit from stealing the server's database.) - SASL-SRP makes it easy to authenticate and derive keys for credential download, changes etc, but what about initial registration? Is that to be offline only or do we need to have a credential deposit operation that uses some other "in-payload" security? - The sacred-pdm draft had some notes about "away-from-home" operation, which is harder using SASL (unless we put the SASL PDUs in our payload as Magnus suggested). Do we want to support this & if so, how? I'm sure there'll be more as I go through it, but that's enough for now. Stephen. -- ____________________________________________________________ Stephen Farrell Baltimore Technologies, tel: (direct line) +353 1 881 6716 39 Parkgate Street, fax: +353 1 881 7000 Dublin 8. mailto:[email protected] Ireland http://www.baltimore.com