Re: beep+sasl+srp draft issues
Stephen Farrell <[email protected]>
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Organization | Baltimore Technologies Ltd. |
| Message-ID | <[email protected]> |
All, Here's what I take from the mail exchanges on these issues (but do continue discussion if there's more to be said): > - We want to hash the userid in case the user types her > password into the "username" box. We could do this above > SASL-SRP or else could try get the SASL-SRP draft to include > the trick itself (I prefer the latter). Any opinions? We drop this & ask the SASL-SRP authors if they'll include it. So this is closed. > - The sacred-pdm draft had an "extra" rsa private key which > was used for signing credential uploads - do we want to > maintain this feature? (The reason for it was to make > it harder to benefit from stealing the server's database.) No-one argued to keep the "extra" key, so it's gone. However, whether to allow support for something "better" than just SRP for uploads (e.g. signing) is still an issue - I'll think about this a bit more and send a separate mail. > - SASL-SRP makes it easy to authenticate and derive keys for > credential download, changes etc, but what about initial > registration? Is that to be offline only or do we need > to have a credential deposit operation that uses some other > "in-payload" security? I wasn't clear describing this one: what I wanted to know was whether we need to support a secure form of on-line user self-registration. (We clearly need to allow, but not specify mechanisms for, out-of-band/offline/bulk registration.) I got the (not very strong:-) impression that folks do want to support this, so I'll try to include something. > - The sacred-pdm draft had some notes about "away-from-home" > operation, which is harder using SASL (unless we put the > SASL PDUs in our payload as Magnus suggested). Do we want > to support this & if so, how? No-one so far seems to really need this, so I'll drop it (but maybe leave some notes in an appendix in case it turns up again later.) Stephen. -- ____________________________________________________________ Stephen Farrell Baltimore Technologies, tel: (direct line) +353 1 881 6716 39 Parkgate Street, fax: +353 1 881 7000 Dublin 8. mailto:[email protected] Ireland http://www.baltimore.com