[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: proposed charter revision
Kurt Zeilenga <Kurt.Zeilenga@xxxxxxxxx> writes:
> On Aug 9, 2007, at 10:16 AM, Jeffrey Hutzelman wrote:
>
>> Put more simply, I think it is desirable that SASL-FOO and SASL-GS2-
>> FOO interoperate, and I believe this requires that they have the
>> same mechanism name and the same bits on the wire, so that both
>> implementation paths lead to the same protocol.
>
> Yes, one SASL mechanism, in the GS2 family, a GSS-API password-based
> mechanism.
>
> I envision this work to result in a single RFC containing the normative
> specification of the GSS-API mechanism and an informative specification
> (in an appendix) of how one could implement the associated SASL/GS2
> mechanism
> without understanding and/or implementing (or using someone else's
> implementation)
> SASL/GS2 and GSS-API frameworks.
I believe that it is quite feasible, and a good idea.
The intention behind draft-josefsson-password-auth-00.txt was to
demonstrate that idea:
http://www.ietf.org/internet-drafts/draft-josefsson-password-auth-00.txt
I believe the GS2 spec needs to get published before we can seriously
consider this approach, though.
/Simon