[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Where do we stand? (Re: Poll: use of TLS channel bindings in SCRAM)



Kurt has not told us where he stands on our proposal.

Kurt has told us where he stands on the poll: a variant of option 3 is
his preferred approach.  Specifically Kurt prefers (preferred?) a
solution where we do channel binding type negotiation now, and we do it
via SASL mechanism names that incorporate both, an actual mechanism
name, and the name of a single channel binding type.  That was before
Jeff and I made our proposal.

Our proposal does not, in fact, preclude Kurt's preferred approach -- it
only defers the addition of channel binding type negotiation to some
future time.  Kurt has aknowledged this.

Therefore I wonder where we actually stand on this poll at this time?

I count at least three, probably five participants (including Sam) in
favor of the proposal that Jeff and I made, and which Simon helped us
refine.  I don't know where Kurt stands -- his comments w.r.t.
in-mechanism negotiation have me confused as to his actual position.
Other participants have not been heard from in a while.

Perhaps we can have a consensus call made now.  Perhaps we'll only be
close, but that may help us figure out how to get there.

Tom?  Kurt?  What do you think?

Nico
--