On Mar 12, 2007, at 11:27 AM, Frank Ellermann wrote:
Anyway, if you don't like to replace PLAIN you can either add a "SHOULD check cert" (the TLS RFC might have some MUSTard in this direction, I'm too lazy to look), or maybe Sam's argument isn't correct (?)
IIRC, it is the application protocol specification which specifies what, if any, TLS certificate verification is required in its use of TLS.-- Kurt