Wording of Session Security Requirements
"Gareth Richards" <[email protected]> Mon, 4 Mar 2002 15:33:59 -0000
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Message-ID | <[email protected]> |
In section 2, normative lines requiring either SRP or TLS have been added to most of the sub-sections. For example, 2.1.3 Remove Account This operation REQUIRES one of SRP or TLS mutual authentication. It seems that these lines could be interpreted as not consistent with section 2.3.1 defining the security requirements of the six operations in section 2. Following the table is a paragraph that states that these requirements may be met by several mechanisms: The security requirements can be met by several mechanisms. This document REQUIRES credential servers to support TLS and SASL-SRP. Clients MUST support SASL-SRP or TLS. The new lines added to section 2 appear to not only require that SRP or TLS be supported but that they be used. This seems to be counter the recent SRP adjustments which allow for the use of SASL negotiation in BEEP and thus allow other mechanisms to be supported while mandating support for SRP to ensure interoperability with good security. I therefore suggest that the first lines be removed from sections 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.2.1 and 2.2.2.