Re: [ftpext] FTP password protection?

Daniel Stenberg <daniel@haxx.se> Wed, 23 June 2010 11:10 UTC

Return-Path: <daniel@haxx.se>
X-Original-To: ftpext@core3.amsl.com
Delivered-To: ftpext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 5194B3A6990 for <ftpext@core3.amsl.com>; Wed, 23 Jun 2010 04:10:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.229
X-Spam-Level:
X-Spam-Status: No, score=-4.229 tagged_above=-999 required=5 tests=[AWL=-1.980, BAYES_00=-2.599, HELO_EQ_SE=0.35]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 45AO1x2-TCOt for <ftpext@core3.amsl.com>; Wed, 23 Jun 2010 04:10:12 -0700 (PDT)
Received: from giant.haxx.se (giant.haxx.se [80.67.6.50]) by core3.amsl.com (Postfix) with ESMTP id A94C93A699E for <ftpext@ietf.org>; Wed, 23 Jun 2010 04:10:10 -0700 (PDT)
Received: from giant.haxx.se (dast@giant.haxx.se [80.67.6.50]) by giant.haxx.se (8.14.3/8.14.3/Debian-9.1) with ESMTP id o5NBAHNE032344; Wed, 23 Jun 2010 13:10:17 +0200
Date: Wed, 23 Jun 2010 13:10:17 +0200
From: Daniel Stenberg <daniel@haxx.se>
X-X-Sender: dast@giant.haxx.se
To: Iljitsch van Beijnum <iljitsch@muada.com>
In-Reply-To: <D7ECC9F4-9DD9-44F6-B525-9ECF5CE2E49E@muada.com>
Message-ID: <alpine.DEB.2.00.1006231309480.15043@tvnag.unkk.fr>
References: <D7ECC9F4-9DD9-44F6-B525-9ECF5CE2E49E@muada.com>
User-Agent: Alpine 2.00 (DEB 1167 2008-08-23)
X-fromdanielhimself: yes
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"; format="flowed"
X-Greylist: Default is to whitelist mail, not delayed by milter-greylist-4.3.5 (giant.haxx.se [80.67.6.50]); Wed, 23 Jun 2010 13:10:17 +0200 (CEST)
Cc: ftpext@ietf.org
Subject: Re: [ftpext] FTP password protection?
X-BeenThere: ftpext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: <ftpext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ftpext>, <mailto:ftpext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ftpext>
List-Post: <mailto:ftpext@ietf.org>
List-Help: <mailto:ftpext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ftpext>, <mailto:ftpext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Jun 2010 11:10:15 -0000

On Wed, 23 Jun 2010, Iljitsch van Beijnum wrote:

> In my opinion, this is the main reason non-anonymous FTP is problematic, and 
> I think defining a login mechanism that doesn't expose cleartext passwords 
> would be a good addition to FTP.

Isn't RFC4217, FTP with TLS good enough for this?

-- 

  / daniel.haxx.se