protocol progress...

Stephen Farrell <[email protected]> Mon, 08 Apr 2002 12:34:10 +0100
Newsgroups gmane.ietf.sacred
Organization Baltimore Technologies Ltd.
Message-ID <[email protected]>

Hi all,

Well, from reports of the sacred meeting it seems that though 
we've managed to bottom out all the previously known issues with 
the current draft, we still need to make some more changes to 
remove the dependence on SASL-SRP, given the uncertain future 
progress of that draft.

So if we want to progress the sacred protocol, we need to agree 
on some approach that doesn't suffer the same uncertainty.

Here's what appears to be a possible plan:-

1. remove srp dependencies from protocol document
2. make beep over tls mandatory to implement and pick 
   a "traditional" password based sasl scheme (hopefully
   with salt, iteration and digest - suggestions on a 
   postcard please!)
3. add/change security considerations to the effect that
   credential servers supporting the "must implement" 
   option do get to see a value that allows them to 
   mount a dictionary attack

As long as item 2 isn't controversial, this shouldn't take
very long.

What do we all think of doing this?

Sigh,
Stephen.

PS: I don't see much point in issuing a new protocol draft until
we sort this one out, let me know if you disagree with that.


-- 
____________________________________________________________
Stephen Farrell         				   
Baltimore Technologies,   tel: (direct line) +353 1 881 6716
39 Parkgate Street,                     fax: +353 1 881 7000
Dublin 8.                mailto:[email protected]
Ireland                             http://www.baltimore.com