Re: beep+sasl+srp draft issues
Stephen Farrell <[email protected]>
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Organization | Baltimore Technologies Ltd. |
| Message-ID | <[email protected]> |
Hi Mike, > As a sysadmin, I'm not all that well versed in hash algorithms. But if > the usernames are hashed, doesn't that present the possibility of unique > usernames generating the same hash key? Granted, it's probably a remote > possilibity, but Users will always find a way. No - hash functions are either collision resistant or broken. Those that we'd pick aren't broken (hopefully:-), so basically this is one of those "number of electrons in the universe" things. > > It didn't require that. The idea was that the client generated the > > key pair on the fly - the private being stored as an encrypted > > part of the credential & the public being a clear part of the credential. > > A client can then sign a credential upload & the server can verify > > off-of the previous instance of that credential. > > Will PDAs and cell phones, for example, be allowed to upload credentials? Should be. > (This would make sense to me--verifying, for instance, what your cell # > is) If so, wouldn't this be a bit computationally harsh for them? You've lost me a bit there - I can see rsa key gen & signing being too hard for current pdas, but what was it made sense? Good point about PDAs though (the PDM scheme wasn't really suited for constrained devices, as was stated in that draft). > > Probably can - if you know its name/address and there's no f/w in > > the way. For someone roaming around inside an intranet both are > > issues (e.g. when I'm in our Boston office). > > I don't see why this would be a problem. If the credential server is > (partially) exposed to the internet, and given a unique name > (credential-west.radioactivedata.org and > credential-east.radioactivedata.org, for example, if there are two > credential servers in a company), how does the firewall get in the way? Maybe I've just always worked for paranoid organisations, but I've seen such f/w issues in larger enterprises. On the name thing, sure, the user can enter the fqdn of the server, but only if the client s/w allows that and the user knows what it is and how to enter it etc. Stephen. -- ____________________________________________________________ Stephen Farrell Baltimore Technologies, tel: (direct line) +353 1 881 6716 39 Parkgate Street, fax: +353 1 881 7000 Dublin 8. mailto:[email protected] Ireland http://www.baltimore.com