Re: Fwd: "POP3 SASL Authentication Mechanism" submitted for publication

Arnt Gulbrandsen <arnt@oryx.com> Mon, 15 January 2007 12:03 UTC

Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l0FC3DOt028301 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 15 Jan 2007 05:03:13 -0700 (MST) (envelope-from owner-ietf-pop3ext@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l0FC3Di7028300; Mon, 15 Jan 2007 05:03:13 -0700 (MST) (envelope-from owner-ietf-pop3ext@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-pop3ext@mail.imc.org using -f
Received: from kalyani.oryx.com (kalyani.oryx.com [195.30.37.30]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l0FC3BiF028288; Mon, 15 Jan 2007 05:03:12 -0700 (MST) (envelope-from arnt@oryx.com)
Received: from libertango.oryx.com (libertango.oryx.com [195.30.37.9]) by kalyani.oryx.com (Postfix) with ESMTP id 18E564AD83; Mon, 15 Jan 2007 13:03:11 +0100 (CET)
Message-Id: <zS/BiUKvu0x5QwxFHJEDcg.md5@libertango.oryx.com>
Date: Mon, 15 Jan 2007 13:05:22 +0100
From: Arnt Gulbrandsen <arnt@oryx.com>
To: Alexey Melnikov <alexey.melnikov@isode.com>
Subject: Re: Fwd: "POP3 SASL Authentication Mechanism" submitted for publication
Cc: robsiemb@google.com, Abhijit Menon-Sen <ams@oryx.com>, Frank Ellermann <nobody@xyzzy.claranet.de>, ietf-pop3ext@imc.org, ietf-sasl@imc.org, Simon Josefsson <simon@josefsson.org>, lisa@osafoundation.org
References: <FDF696C1-7407-4C60-8D8F-04CC492BE435@osafoundation.org> <1E59CC0D-7022-4400-BA48-D9D7B427ABEF@commerce.net> <45A9DFA8.68E4@xyzzy.claranet.de> <20070114105359.GA30833@penne.toroid.org> <87k5zpgz7o.fsf@latte.josefsson.org> <45AB6731.9090906@isode.com>
In-Reply-To: <45AB6731.9090906@isode.com>
Content-Type: text/plain; format="flowed"
MIME-Version: 1.0
Sender: owner-ietf-pop3ext@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-pop3ext/mail-archive/>
List-ID: <ietf-pop3ext.imc.org>
List-Unsubscribe: <mailto:ietf-pop3ext-request@imc.org?body=unsubscribe>

Alexey Melnikov writes:
> Simon Josefsson wrote:
>> and TLS+CRAM-MD5
>
> This doesn't give anything over TLS+PLAIN and also doesn't support 
> authorization identity.
> I am against this choice.

TLS+CRAM-MD5 doesn't reveal the user's secret to the server. A very nice 
property if you're not 100% sure that you're talking to the right 
server.

Arnt