Why GSSAPI/SPKM? (Was: Re: SACRED Protocol (long!))

Stephen Farrell <[email protected]> Fri, 07 Dec 2001 14:32:07 +0000
Newsgroups gmane.ietf.sacred
Organization Baltimore Technologies Ltd.
Message-ID <[email protected]>

Magnus, Gareth,

(Trying to split up the issues involved in your proposals...)

Its not clear to me why there's any advantage in adding this, and
it also seems to me to add quite a bit of complexity. So, my
questions are:

- What can I do with this that I couldn't do with just SASL as an 
extensibility mechanism?
- Why would all this be MUST?

Stephen.

>   2.2.2 GSSAPI
> 
>    An implementation MUST support the GSSAPI SASL mechanism which in
>    turn must support the SPKM GSS-API mechanism.
> 
>    The SPKM implentation MUST support:
> 
>    - The NULL-MAC [LIPKEY] and sha1WithRSAEncryption algorithmgs as
>      I-ALGs. (Targets MUST not use this algorithm.)
>    - AES  as a C-ALG.
>    - SHA-1 [FIPS] as an O-ALG.
> 
>    << QOP bitmap needs to be defined.>>"
> 

-- 
____________________________________________________________
Stephen Farrell         				   
Baltimore Technologies,   tel: (direct line) +353 1 881 6716
39 Parkgate Street,                     fax: +353 1 881 7000
Dublin 8.                mailto:[email protected]
Ireland                             http://www.baltimore.com