Why GSSAPI/SPKM? (Was: Re: SACRED Protocol (long!))
Stephen Farrell <[email protected]> Fri, 07 Dec 2001 14:32:07 +0000
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Organization | Baltimore Technologies Ltd. |
| Message-ID | <[email protected]> |
Magnus, Gareth, (Trying to split up the issues involved in your proposals...) Its not clear to me why there's any advantage in adding this, and it also seems to me to add quite a bit of complexity. So, my questions are: - What can I do with this that I couldn't do with just SASL as an extensibility mechanism? - Why would all this be MUST? Stephen. > 2.2.2 GSSAPI > > An implementation MUST support the GSSAPI SASL mechanism which in > turn must support the SPKM GSS-API mechanism. > > The SPKM implentation MUST support: > > - The NULL-MAC [LIPKEY] and sha1WithRSAEncryption algorithmgs as > I-ALGs. (Targets MUST not use this algorithm.) > - AES as a C-ALG. > - SHA-1 [FIPS] as an O-ALG. > > << QOP bitmap needs to be defined.>>" > -- ____________________________________________________________ Stephen Farrell Baltimore Technologies, tel: (direct line) +353 1 881 6716 39 Parkgate Street, fax: +353 1 881 7000 Dublin 8. mailto:[email protected] Ireland http://www.baltimore.com