[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Updated SASL And Channel Binding document (-03)
On Tue, May 26, 2009 at 09:48:08AM -0700, Kurt Zeilenga wrote:
> Generally and with respect to SCRAM, I rather change the specification
> to always require the use of unique channel bindings. I do understand
> however that some prefer use of end-point channel binding types in
> certain cases.
Indeed, we'll not agree to always require the use of unique channel
bindings.
> One solution for SCRAM is to offer:
> SCRAM-SHA-1
> SCRAM-SHA-1-ENDPOINT
> SCRAM-SHA-1-UNIQUE
That complicates everything.
> However, as WG Chair, I'm willing to discuss and conclude on this
> issue (for SCRAM) as part of SCRAM WGLC.
I don't see what difference it makes whether we discuss this in the
context of a WGLC or not. Either way we need a resolution.
So let's discuss it now.
To solve this without adding yet another negotiation via SASL mechanism
name we could just declare that the negotiation will be done by
SCRAM/GS2, and that the application must furnish channel bindings all
available channel binding types. That would not precluse YAP, and it
would not complicate SCRAM/GS2.
Nico
--