Re: protocol progress...

Magnus Nystrom <[email protected]> Tue, 14 May 2002 14:35:45 +0200 (W. Europe Daylight Time)
Newsgroups gmane.ietf.sacred
Message-ID <Pine.WNT.4.43.0205141127400.104-100000@mnystrom-lap>
All,

In an attempt to bring closure to the discussion over the
mandated-to-implement client authentication mechanism in SACRED, can I
suggest the following:

 For the initial version of SACRED, clients and servers are REQUIRED to
 support TLS for server authentication and transport security (mandated
 TLS cipher suite remains to be settled, but I cannot recall any objections
 to the proposed one) and to support DIGEST-MD5 (authentication only) for
 client authentication. This follows the plan outlined by Stephen in his 8
 April message.

Given that SACRED's protocol is based on BEEP and, in particular, BEEP's
support for SASL,

-particular implementations may easily choose to support any other
 SASL mechanism, and
-the SACRED WG may later on, without extensive work, decide to add to or
 otherwise change the set of mandated mechanisms, should implementation
 experience or other reasons motivate it.

-- Magnus