[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

BEEP session tuning



Hello,

I'm confused about BEEP session tuning in the SACRED protocol, and I'm
hoping someone can set me straight.  Section 4.1 of RFC 3080 says:

  Note that SASL may provide both user authentication and transport
  security. Once transport security is successfully negotiated for a
  BEEP session, then a SASL security layer must not be negotiated;
  similarly, once any SASL negotiation is successful, a transport
  security profile must not begin its underlying negotiation process.

To me, that says you can't tune with both http://iana.org/beep/TLS and
http://iana.org/SASL/DIGEST-MD5 as suggested in section 3.1 of
draft-ietf-sacred-protocol-bss-09.txt.  Am I misreading that paragraph
of RFC 3080?

-Jim