2 Aug 2002 12:55
Reviving the SRP internet draft
David Taylor <dtaylo11 <at> bigpond.net.au>
2002-08-02 10:55:01 GMT
2002-08-02 10:55:01 GMT
Hi all, I am writing to ask the list's opinion on the idea of using SRP authentication in TLS. The draft went through a couple of revisions and caused some active discussion when it appeared but then it seemed to die off. I believe the idea of a safe username and password based authentication scheme for TLS is ideal for a lot of applications TLS is being put into (TELNET, POP, IMAP, etc). It also fits nicely with a lot of web based applications, most of which require usernames and passwords after establishing a TLS connection. The draft was certainly implementable - Nikos put it in GNU TLS and I implemented it in two different Java TLS libraries (neither of which I can release yet). So, does the group believe the draft would make TLS more usable? What are the arguments for not adding the handshake extensions and cipher suites defined by the draft? If I submit a new version of the draft that adheres to the latest extensions ideas (hopefully RFC by the time I have updated the SRP draft) would it get the support of the group to advance to an RFC? Regards, David Taylor. --- You are currently subscribed to ietf-tls as: ietf-ietf-tls <at> m.gmane.org(Continue reading)
RSS Feed