Re: [Emu] salted EAP-pwd

"Jim Schaad" <ietf@augustcellars.com> Tue, 30 September 2014 21:18 UTC

Return-Path: <ietf@augustcellars.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D11D71A914C for <emu@ietfa.amsl.com>; Tue, 30 Sep 2014 14:18:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LJgPf0KF0T_y for <emu@ietfa.amsl.com>; Tue, 30 Sep 2014 14:18:58 -0700 (PDT)
Received: from smtp2.pacifier.net (smtp2.pacifier.net [64.255.237.172]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 645D31A9144 for <emu@ietf.org>; Tue, 30 Sep 2014 14:18:58 -0700 (PDT)
Received: from Philemon (winery.augustcellars.com [206.212.239.129]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: jimsch@nwlink.com) by smtp2.pacifier.net (Postfix) with ESMTPSA id C1D032CA1B; Tue, 30 Sep 2014 14:18:57 -0700 (PDT)
From: Jim Schaad <ietf@augustcellars.com>
To: 'Dan Harkins' <dharkins@lounge.org>, emu@ietf.org
References: <e000123dbf6d5c42568d26464ed55a08.squirrel@www.trepanning.net>
In-Reply-To: <e000123dbf6d5c42568d26464ed55a08.squirrel@www.trepanning.net>
Date: Tue, 30 Sep 2014 14:16:29 -0700
Message-ID: <0e3a01cfdcf3$cdca13d0$695e3b70$@augustcellars.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQJrPpFfgr3g/sqefUjDnX1/AEi665rjajdw
Content-Language: en-us
Archived-At: http://mailarchive.ietf.org/arch/msg/emu/ook0Tedy_RJ1W0PPrYVYKLQiHdM
Subject: Re: [Emu] salted EAP-pwd
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu/>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 Sep 2014 21:19:00 -0000

I can see two problems right off the bat.

1.  It does not allow me to use a different salted method for different
people so I can upgrade by salt function piecemeal.

2.  It does not allow me to do both SASLprep and salting on the same
password.

Jim


-----Original Message-----
From: Emu [mailto:emu-bounces@ietf.org] On Behalf Of Dan Harkins
Sent: Tuesday, September 30, 2014 12:02 PM
To: emu@ietf.org
Subject: [Emu] salted EAP-pwd


  Hello EMU,

  I've had requests to add support for salted password databases to EAP-pwd.
A newly posted draft does just that:

   http://tools.ietf.org/html/draft-harkins-salted-eap-pwd-00

  Please take a look and comment.

  regards,

  Dan.



_______________________________________________
Emu mailing list
Emu@ietf.org
https://www.ietf.org/mailman/listinfo/emu