SACRED Protocol

"Gareth Richards" <[email protected]> Thu, 22 Nov 2001 08:17:32 -0000
Newsgroups gmane.ietf.sacred
Message-ID <[email protected]>
I have been going through the SACRED mail archive to try and get an
understanding of how SACRED will handle authentication and transport and I
wanted to check that I understand the current situation.

The proposal appears to be that SACRED will rely on the built-in security
of the transport and so will be limited in the transport systems it can
use.  Since BEEP can use the SASL-SRP mechanism to provide both mutual
authentication and a session encryption key it can be used.  Isn't this
approach, rather than having a self-contained protocol specifying the use
of SASL, going to cause problems if other transport protocols such as
XML-Protocol are used?

For example, I've noticed that the draft charter for the W3C XKMS WG [1]
proposes "harmonizing the SACRED protocol layer with the X-KRSS roaming
operation".  It could be desirable for the same technology to be applied
for this purpose in both environments.  It seems, however, that XKMS is
likely to specify XML-Protocol as its initial binding and to follow an
approach where security sublayers (XMLDSig, XML Encryption) are directly
applied to the XKMS application protocol, rather than being consumed from
an underlying transport.


[1]
http://lists.w3.org/Archives/Public/www-xkms-ws/2001Oct/att-0011/01-xkms-ch
arter.html

Gareth Richards

RSA Security