Wording of Session Security Requirements

"Gareth Richards" <[email protected]> Mon, 4 Mar 2002 15:33:59 -0000
Newsgroups gmane.ietf.sacred
Message-ID <[email protected]>

In section 2, normative lines requiring either SRP or TLS have been added
to most of the sub-sections.

For example,

2.1.3   Remove Account

   This operation REQUIRES one of SRP or TLS mutual authentication.


It seems that these lines could be interpreted as not consistent with
section 2.3.1 defining the security requirements of the six operations in
section 2.   Following the table is a paragraph that states that these
requirements may be met by several mechanisms:

   The security requirements can be met by several mechanisms. This
   document REQUIRES credential servers to support TLS and SASL-SRP.
   Clients MUST support SASL-SRP or TLS.

The new lines added to section 2 appear to not only require that SRP or TLS
be supported but that they be used.  This seems to be counter the recent
SRP adjustments which allow for the use of SASL negotiation in BEEP and
thus allow other mechanisms to be supported while mandating support for SRP
to ensure interoperability with good security.


I therefore suggest that the first lines be removed from sections 2.1.1,
2.1.2, 2.1.3, 2.1.4, 2.2.1 and  2.2.2.