[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Poll: use of TLS channel bindings in SCRAM





On May 29, 2009, at 5:22 PM, Nicolas Williams wrote:
I believe that making GS2 support in-mechanism negotiation of channel
binding type now or in the future would require _significant_ surgery on
GS2.

So your proposal does preclude one possible negotiation approach that could be used in SCRAM and GS2.

It's too late to be doing major changes to GS2.  Moreover, where

is the justification for requiring that GS2 support such a thing?  If
you believe that GS2 should support that, then please explain why, and
then let's have a poll on that.


You asserted:
Notice too that we are left in a position where we can actually add channel binding type negotiation later.

My assertion is that while certainly we might be able to to add channel binding type negotiation, the particulars of the SCRAM and GS2 specifications will have a significant impact on the engineering of solutions. Hence, I believe it appropriate to discuss the impact upon possible solutions during the consideration of the particulars of the SCRAM and GS2 specification.

I will discuss the suitability of in-the-mechanism exchange in the response to another list message.

-- Kurt