Re: protocol progress...

Tom Wu <[email protected]> Tue, 09 Apr 2002 12:05:47 -0700
Newsgroups gmane.ietf.sacred
Organization Arcot Systems
Message-ID <[email protected]>
Stephen,

If uncertainty about the SASL-SRP draft is an issue, why not go with 
SRP/TLS, or some other strong password solution?  Item 2 requires a 
weakening in the previously agreed-to security requirements, which seems 
like a Bad Thing.

Tom

Stephen Farrell wrote:
> 
> Hi all,
> 
> Well, from reports of the sacred meeting it seems that though 
> we've managed to bottom out all the previously known issues with 
> the current draft, we still need to make some more changes to 
> remove the dependence on SASL-SRP, given the uncertain future 
> progress of that draft.
> 
> So if we want to progress the sacred protocol, we need to agree 
> on some approach that doesn't suffer the same uncertainty.
> 
> Here's what appears to be a possible plan:-
> 
> 1. remove srp dependencies from protocol document
> 2. make beep over tls mandatory to implement and pick 
>    a "traditional" password based sasl scheme (hopefully
>    with salt, iteration and digest - suggestions on a 
>    postcard please!)
> 3. add/change security considerations to the effect that
>    credential servers supporting the "must implement" 
>    option do get to see a value that allows them to 
>    mount a dictionary attack
> 
> As long as item 2 isn't controversial, this shouldn't take
> very long.
> 
> What do we all think of doing this?
> 
> Sigh,
> Stephen.
> 
> PS: I don't see much point in issuing a new protocol draft until
> we sort this one out, let me know if you disagree with that.
> 
> 
> 



-- 
Tom Wu
Principal Software Engineer
Arcot Systems
(408) 969-6124
"The Borg?  Sounds Swedish..."