Re: SACRED Protocol
Stephen Farrell <[email protected]> Wed, 05 Dec 2001 16:26:56 +0000
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Organization | Baltimore Technologies Ltd. |
| Message-ID | <[email protected]> |
Hi Gareth, You're right - using BEEP's SASL support does have that effect and is different from what other groups are doing. I'm quite open to changing this, if that's the concensus (and even more so, if someone posts the suggested delta from the current draft:-). However, if we change it then we'll have to specify how the key established using SASL gets used to encrypt payload messages. Are you suggesting that we use xml encryption for this? Stephen. Gareth Richards wrote: > > I have been going through the SACRED mail archive to try and get an > understanding of how SACRED will handle authentication and transport and I > wanted to check that I understand the current situation. > > The proposal appears to be that SACRED will rely on the built-in security > of the transport and so will be limited in the transport systems it can > use. Since BEEP can use the SASL-SRP mechanism to provide both mutual > authentication and a session encryption key it can be used. Isn't this > approach, rather than having a self-contained protocol specifying the use > of SASL, going to cause problems if other transport protocols such as > XML-Protocol are used? > > For example, I've noticed that the draft charter for the W3C XKMS WG [1] > proposes "harmonizing the SACRED protocol layer with the X-KRSS roaming > operation". It could be desirable for the same technology to be applied > for this purpose in both environments. It seems, however, that XKMS is > likely to specify XML-Protocol as its initial binding and to follow an > approach where security sublayers (XMLDSig, XML Encryption) are directly > applied to the XKMS application protocol, rather than being consumed from > an underlying transport. > > [1] > http://lists.w3.org/Archives/Public/www-xkms-ws/2001Oct/att-0011/01-xkms-ch > arter.html > > Gareth Richards > > RSA Security -- ____________________________________________________________ Stephen Farrell Baltimore Technologies, tel: (direct line) +353 1 881 6716 39 Parkgate Street, fax: +353 1 881 7000 Dublin 8. mailto:[email protected] Ireland http://www.baltimore.com