[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Poll: use of TLS channel bindings in SCRAM





On May 29, 2009, at 10:46 PM, Jeffrey Hutzelman wrote:
Have you missed that part?

We're NOT TRYING TO DECIDE HOW NEGOTIATION SHOULD WORK.

Yes, but we are trying to decide what SCRAM I-D says about channel bindings. I have tried to point out that what the SCRAM I-D says about channel bindings have an impact upon on possible negotiation solutions, and hence feel it reasonable to discuss these impacts.


Unfortunately, despite the fact that we've shown that a variety of approaches can work with GS2 modified as we've described, including several very different approaches proposed by different people, we keep finding ourselves arguing about which of those proposals is the right one instead of finishing the documents that don't depend on the outcome of that discussion.

I have tried hard not to argue about the suitability of negotiation approaches, instead trying to focus on how changes we might make in the SCRAM I-D might impact possible solutions. However, at times it might well be appropriate to discuss the suitability of possible solutions in order to reach consensus on what changes we make to SCRAM.

I believe we all understand that multi-level negotiation is a bad idea.

And this is a case in point. When I raised concerned that the proposal seemed to preclude a particular possible solution, I think it quite reasonable for you and others to engage me in questions of the suitability of such a solution, so that we can determine whether this is something we think is "okay" to preclude (or hinder or disadvantage).

But you seem to be saying that you don't want to move forward with GS2 and SCRAM because in their current form they might preclude an approach involving multi-level negotiation, which we all agree is a bad idea.

I am more making sure we consider now the impacts of what we do now on our subsequent work to develop a negotiation solution. This naturally involves some discussion of possible negotiation solutions. In my opinion, we should defer attempting to reach consensus on a negotiation solution, however we should continue to discuss possible negotiation solutions, especially in the context of how proposed changes to SCRAM and GS2 impact possible negotiation solutions.

Why in the world would you want to hold up a document because it doesn't allow for doing something that no one wants to do anyway?

I'm trying to understand all the impacts of the proposals for this document, so that I can decide whether which of the proposals I might support. I am not trying to hold up the document. The poll doesn't expire until the 7th. I am sure I will be able to decide before the conclusion of the poll as which proposals I support. It may well that I'll end up being in the rough.

-- Kurt