On May 29, 2009, at 5:22 PM, Nicolas Williams wrote:
I believe that making GS2 support in-mechanism negotiation of channelbinding type now or in the future would require _significant_ surgery onGS2.
So your proposal does preclude one possible negotiation approach that could be used in SCRAM and GS2.
It's too late to be doing major changes to GS2. Moreover, where
is the justification for requiring that GS2 support such a thing? If you believe that GS2 should support that, then please explain why, and then let's have a poll on that.
You asserted:Notice too that we are left in a position where we can actually add channel binding type negotiation later.
My assertion is that while certainly we might be able to to add channel binding type negotiation, the particulars of the SCRAM and GS2 specifications will have a significant impact on the engineering of solutions. Hence, I believe it appropriate to discuss the impact upon possible solutions during the consideration of the particulars of the SCRAM and GS2 specification.
I will discuss the suitability of in-the-mechanism exchange in the response to another list message.
-- Kurt