[TLS] Re: Review of draft-santesson-tls-gssapi-03

Simon Josefsson <simon@josefsson.org> Thu, 13 September 2007 08:31 UTC

From: Simon Josefsson <simon@josefsson.org>
Date: Thu, 13 Sep 2007 10:31:21 +0200
Subject: [TLS] Re: Review of draft-santesson-tls-gssapi-03
Martin Rex <Martin.Rex@sap.com> writes:

>> Btw, I forgot to bring up channel bindings.  Have you considered
>> supporting it?  It is not critical to me, I consider X.509 or OpenPGP
>> authentication sufficient to solve the tunnel problem.
> AFAIK, the architecture of this proposal does provide secure channel
> bindings, in that it uses gss_prf output for the creation of the
> master secret using the PSK ciphersuites.

I missed that.  Right, it seems to be solved.


