Re: TLS profile

[email protected] (Jonas Borgström) 25 Jul 2002 16:52:17 +0200
Newsgroups gmane.network.beep.roadrunner.general
Message-ID <[email protected]>
Andrea Campi <[email protected]> writes:

> Hi,
> 
Hi,

> I'm working on a CAP profile and server based on roadrunner 0.8 [*].
> The draft RFC for CAP mandates the use of
> 
Cool, please note that the cvs version of roadrunner contains some
changes in profile api.

>   for authentication: http://iana.org/beep/SASL/DIGEST-MD5
>   for confidentiality: http://iana.org/beep/TLS (using the
> 	TLS_RSA_WITH_3DES_EDE_CBC_SHA cipher)
>   for both: http://iana.org/beep/TLS (with
> 	TLS_RSA_WITH_3DES_EDE_CBC_SHA cipher supporting client-side
> 	certificates)
> 
> The problem is that, as far I can understand, the rrtls profile
> only supports server certificates. Am I right or am I missing
> something? Is this being worked on?
> 
This is correct, this is one of the things that has to be implemented
before the 1.0 version can be released.

> So, right now, the only way to authenticate an initiator is to use
> SASL, correct?
> 

Yep

/ Jonas
-- 
Jonas Borgström                  [email protected]
CodeFactory AB                   http://www.codefactory.se/
Office: +46 (0)90 71 86 10       Cell: +46 (0)70 248 89 58