Re: protocol progress...
Tom Wu <[email protected]> Tue, 09 Apr 2002 12:05:47 -0700
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Organization | Arcot Systems |
| Message-ID | <[email protected]> |
Stephen, If uncertainty about the SASL-SRP draft is an issue, why not go with SRP/TLS, or some other strong password solution? Item 2 requires a weakening in the previously agreed-to security requirements, which seems like a Bad Thing. Tom Stephen Farrell wrote: > > Hi all, > > Well, from reports of the sacred meeting it seems that though > we've managed to bottom out all the previously known issues with > the current draft, we still need to make some more changes to > remove the dependence on SASL-SRP, given the uncertain future > progress of that draft. > > So if we want to progress the sacred protocol, we need to agree > on some approach that doesn't suffer the same uncertainty. > > Here's what appears to be a possible plan:- > > 1. remove srp dependencies from protocol document > 2. make beep over tls mandatory to implement and pick > a "traditional" password based sasl scheme (hopefully > with salt, iteration and digest - suggestions on a > postcard please!) > 3. add/change security considerations to the effect that > credential servers supporting the "must implement" > option do get to see a value that allows them to > mount a dictionary attack > > As long as item 2 isn't controversial, this shouldn't take > very long. > > What do we all think of doing this? > > Sigh, > Stephen. > > PS: I don't see much point in issuing a new protocol draft until > we sort this one out, let me know if you disagree with that. > > > -- Tom Wu Principal Software Engineer Arcot Systems (408) 969-6124 "The Borg? Sounds Swedish..."