[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: New work for sacred working group?



Simon Josefsson <jas@xxxxxxxxxxx> writes:

>Which unencumbered alternatives are you thinking of?

TLS-PSK.

>Anything beyond TLS+PLAIN seem to me be either surrounded with IPR concerns
>(SPEKE, SRP); or incredible poorly designed and implemented (DIGEST-MD5); or
>deprecated (CRAM-MD5); or too complex to allow a reasonable implementations
>(X.509, CMS); or too experimental (TLS PSK); or burdened by history
>(Kerberos), to be applicable.

Hmm, I'd hardly call a standards-track TLS RFC "experimental".  Given the
strong support there is for this from low-powered device vendors, and the fact
that it's a trivial mod to TLS, I'd hope there'd be good support for this in
the future.

Peter.