SACRED Protocol
"Gareth Richards" <[email protected]> Thu, 22 Nov 2001 08:17:32 -0000
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Message-ID | <[email protected]> |
I have been going through the SACRED mail archive to try and get an understanding of how SACRED will handle authentication and transport and I wanted to check that I understand the current situation. The proposal appears to be that SACRED will rely on the built-in security of the transport and so will be limited in the transport systems it can use. Since BEEP can use the SASL-SRP mechanism to provide both mutual authentication and a session encryption key it can be used. Isn't this approach, rather than having a self-contained protocol specifying the use of SASL, going to cause problems if other transport protocols such as XML-Protocol are used? For example, I've noticed that the draft charter for the W3C XKMS WG [1] proposes "harmonizing the SACRED protocol layer with the X-KRSS roaming operation". It could be desirable for the same technology to be applied for this purpose in both environments. It seems, however, that XKMS is likely to specify XML-Protocol as its initial binding and to follow an approach where security sublayers (XMLDSig, XML Encryption) are directly applied to the XKMS application protocol, rather than being consumed from an underlying transport. [1] http://lists.w3.org/Archives/Public/www-xkms-ws/2001Oct/att-0011/01-xkms-ch arter.html Gareth Richards RSA Security