RE: protocol progress...
"Eamon O'Tuathail" <[email protected]> Mon, 8 Apr 2002 15:14:18 +0100
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Message-ID | <000001c1df07$ad17d570$56c8fea9@central> |
Stephen,
Text such as the following is in the "APEX", "SOAP over BEEP" and other
BEEP profiles. Would you consider it or something similar for SACRED?
It is much more likely BEEP implementions will automatically support a
common set of security considerations (so SACRED implementors will have
less work to do).
Eamon
======================
Section 8 of
http://www.ietf.org/internet-drafts/draft-etal-beep-soap-06.txt
"8. Security Considerations
Although service provisioning is a policy matter, at a minimum, all
implementations must provide the following tuning profiles:
for authentication: http://iana.org/beep/SASL/DIGEST-MD5
for confidentiality: http://iana.org/beep/TLS (using the
TLS_RSA_WITH_3DES_EDE_CBC_SHA cipher)
for both: http://iana.org/beep/TLS (using the
TLS_RSA_WITH_3DES_EDE_CBC_SHA cipher supporting client-side
certificates)"