TLS profile

Andrea Campi <[email protected]> Thu, 25 Jul 2002 12:04:41 +0200
Newsgroups gmane.network.beep.roadrunner.general
Organization I.NET S.p.A.
Message-ID <[email protected]>
Hi,

I'm working on a CAP profile and server based on roadrunner 0.8 [*].
The draft RFC for CAP mandates the use of

  for authentication: http://iana.org/beep/SASL/DIGEST-MD5
  for confidentiality: http://iana.org/beep/TLS (using the
	TLS_RSA_WITH_3DES_EDE_CBC_SHA cipher)
  for both: http://iana.org/beep/TLS (with
	TLS_RSA_WITH_3DES_EDE_CBC_SHA cipher supporting client-side
	certificates)

The problem is that, as far I can understand, the rrtls profile
only supports server certificates. Am I right or am I missing
something? Is this being worked on?

So, right now, the only way to authenticate an initiator is to use
SASL, correct?

Bye,
	andrea

-- 
Andrea Campi                              mailto:[email protected]
I.NET S.p.A.                              http://www.inet.it
Direzione Tecnica - R&D			  phone: +39 02 32863 ext 1
v. Darwin, 85 - I-20019			  fax: +39 02 32863 ext 7705
Settimo Milanese (MI), Italy