Re: beep+sasl+srp draft issues
Magnus Nystrom <[email protected]>
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Message-ID | <Pine.WNT.4.31.0110241414110.652-100000@mnystrom-lap> |
Stephen, Thanks for the summary. Just two more comments: On Wed, 24 Oct 2001, Stephen Farrell wrote: [...] > > - The sacred-pdm draft had an "extra" rsa private key which > > was used for signing credential uploads - do we want to > > maintain this feature? (The reason for it was to make > > it harder to benefit from stealing the server's database.) > > No-one argued to keep the "extra" key, so it's gone. However, > whether to allow support for something "better" than just SRP > for uploads (e.g. signing) is still an issue - I'll think > about this a bit more and send a separate mail. I think we certainly should _allow_ for alternate methods for the upload. This could include a PKI-based upload, e.g. along the lines of Mike Just's scenario were the user is in possession of a private key certified by an authority trusted by the credential server. If SASL is being used, this (allowing other methods) should be virtually a no-op. > > - SASL-SRP makes it easy to authenticate and derive keys for > > credential download, changes etc, but what about initial > > registration? Is that to be offline only or do we need > > to have a credential deposit operation that uses some other > > "in-payload" security? > > I wasn't clear describing this one: what I wanted to know was > whether we need to support a secure form of on-line user > self-registration. (We clearly need to allow, but not specify > mechanisms for, out-of-band/offline/bulk registration.) > > I got the (not very strong:-) impression that folks do want to > support this, so I'll try to include something. That's fine, I should not prioritize this work however, as the focus right now probably should be on the down- and up-load.(?) -- Magnus