[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Poll: use of TLS channel bindings in SCRAM




I hereby cancel the WGLC on this document as it is reasonably clear that a lack of consensus exists as to the publication of the I-D as it currently reads. I also intend to defer the WGLC on the GS2 document.

I encourage the WG to respond to this poll. The chairs will determine WG consensus of responses, including comments, including discussions not restricted to the variants listed. The chairs will also consider off-list comments. (Participants are of course free to reach independent conclusions of the responses they are aware of, however the chairs have not and will not delegated their RFC 2418 responsibilities in this area.)

-- Kurt, as co-chair

On May 28, 2009, at 2:49 PM, Alexey Melnikov wrote:


I've discussed channel bindings with Nico in jabber and we agreed that we need to get WG consensus on how TLS channel bindings should be used with SCRAM. Please provide an orded list of alternatives you find acceptable from the choices listed below. (Please restrict discussions of variants of these choices at the moment. I will do another poll on such choices later, depending on the outcome of this poll. Also, please read notes for the choices before answering). Please answer the poll by the end of June 7th.

1). SCRAM should just use a single allowed TLS channel binding and don't have any negotiation of other TLS channel bindings (*) (**)
a). the default is tls-unique
b). the default is tls-server-end-point
2). SCRAM should just use tls-server-end-point, fallback to tls- unique, no negotiation of other TLS channel bindings (*)
3). SCRAM should always use channel binding negotiation (*)
4). SCRAM should have a default TLS channel binding with optional negotiation of TLS channel bindings (*)
a). the default is tls-unique
b). the default is
5). I have another opinion [this is for the case when there is some valid choice which you think should be considered by the WG]

Notes:
(*) - whether such negotiation happens inside or outside of SCRAM
(**) - channel binding negotiation can be added later on