Re: protocol progress...

Alexey Melnikov <[email protected]> Mon, 29 Apr 2002 15:45:54 -0600
Newsgroups gmane.ietf.sacred
Organization ACI WorldWide / MessagingDirect
Message-ID <[email protected]>
Dale Gustafson wrote:

> ...
> It's been suggested that one or more SASL authentication methods might be able to
> provide an adequate SACRED security service { server authentication, client
> authentication, session key negotiation/derivation, roaming user support, ... } such
> that basic attack scenarios would not be practical.  Is that really true?
>
> I've not taken the time to go through all the SASL-based RFCs (and active drafts) to
> create a more complete list of candidate algorithms but here's the current list from
> IANA.  Perhaps others would care to comment on which algorithms appear to be suitable
> for use with SACRED.  Recall that CRAM-MD5 and DIGEST-MD5 have been suggested to
> date.  Also, based on a cursory read, it appears that RFC-3163 is N/A since it
> provides authentication only.  If anyone knows of others that should be considered,
> please send info.
>
> Excerpt from IANA sasl-mechanism list follows:

FYI, some other mechanisms also listed on the web page:

 http://www.sendmail.org/~ca/email/mel/Links.html

[Some links are broken as drafts expired.]

> SIMPLE AUTHENTICATION AND SECURITY LAYER (SASL) MECHANISMS
> ----------------------------------------------------------
>
> (last updated 2001 August 17)
>
> [ ... ]
>
> MECHANISMS              OWNER                                  REFERENCE
> ----------              -----                                  ---------
>
> KERBEROS_V4             IESG <[email protected]>                   [RFC2222]
>
> GSSAPI                  IESG <[email protected]>                   [RFC2222]
>
> SKEY (OBSOLETE)         IESG <[email protected]>                   [RFC2444]
>
> EXTERNAL                IESG <[email protected]>                   [RFC2222]
>
> CRAM-MD5                IESG <[email protected]>                   [RFC2195]
>
> ANONYMOUS               IESG <[email protected]>                   [RFC2245]
>
> OTP                     IESG <[email protected]>                   [RFC2444]
>
> GSS-SPNEGO              Paul Leach <[email protected]>        [Leach]
>
> PLAIN                   IESG <[email protected]>                   [RFC2595]
>
> SECURID                 Magnus Nystrom <[email protected]>[RFC2808]
>
> NTLM                    Paul Leach <[email protected]>        [Leach]
>
> NMAS_LOGIN              Mark G. Gayman <[email protected]>     [Gayman]
>
> NMAS_AUTHEN             Mark G. Gayman <[email protected]>     [Gayman]
>
> DIGEST-MD5              IESG <[email protected]>                   [RFC2831]
>
> 9798-U-RSA-SHA1-ENC     [email protected]          [RFC3163]
>
> 9798-M-RSA-SHA1-ENC     [email protected]          [RFC3163]
>
> 9798-U-DSA-SHA1         [email protected]          [RFC3163]
>
> 9798-M-DSA-SHA1         [email protected]          [RFC3163]
>
> 9798-U-ECDSA-SHA1       [email protected]          [RFC3163]
>
> 9798-M-ECDSA-SHA1       [email protected]          [RFC3163]

Alexey Melnikov
__________________________________________
R & D, ACI Worldwide/MessagingDirect
Richmond, Surrey, UK
Phone: +44 20 8332 4508

I speak for myself only, not for my employer.
__________________________________________