protocol progress...
Stephen Farrell <[email protected]> Mon, 08 Apr 2002 12:34:10 +0100
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Organization | Baltimore Technologies Ltd. |
| Message-ID | <[email protected]> |
Hi all, Well, from reports of the sacred meeting it seems that though we've managed to bottom out all the previously known issues with the current draft, we still need to make some more changes to remove the dependence on SASL-SRP, given the uncertain future progress of that draft. So if we want to progress the sacred protocol, we need to agree on some approach that doesn't suffer the same uncertainty. Here's what appears to be a possible plan:- 1. remove srp dependencies from protocol document 2. make beep over tls mandatory to implement and pick a "traditional" password based sasl scheme (hopefully with salt, iteration and digest - suggestions on a postcard please!) 3. add/change security considerations to the effect that credential servers supporting the "must implement" option do get to see a value that allows them to mount a dictionary attack As long as item 2 isn't controversial, this shouldn't take very long. What do we all think of doing this? Sigh, Stephen. PS: I don't see much point in issuing a new protocol draft until we sort this one out, let me know if you disagree with that. -- ____________________________________________________________ Stephen Farrell Baltimore Technologies, tel: (direct line) +353 1 881 6716 39 Parkgate Street, fax: +353 1 881 7000 Dublin 8. mailto:[email protected] Ireland http://www.baltimore.com