[TLS] Re: Review of draft-santesson-tls-gssapi-03

Simon Josefsson <simon@josefsson.org> Thu, 13 September 2007 08:31 UTC

Return-path: <tls-bounces@lists.ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1IVk6u-0002Nu-NT; Thu, 13 Sep 2007 04:31:40 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1IVk6t-0002No-Sh for tls@lists.ietf.org; Thu, 13 Sep 2007 04:31:39 -0400
Received: from yxa.extundo.com ([83.241.177.38]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1IVk6s-00074I-Ay for tls@lists.ietf.org; Thu, 13 Sep 2007 04:31:39 -0400
Received: from mocca.josefsson.org (yxa.extundo.com [83.241.177.38]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l8D8VL6x002371 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 13 Sep 2007 10:31:22 +0200
From: Simon Josefsson <simon@josefsson.org>
To: martin.rex@sap.com
References: <87abrse6y9.fsf@mocca.josefsson.org> <200709121716.l8CHGQrS015174@fs4113.wdf.sap.corp>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:070913:martin.rex@sap.com::BqUY6TJKa0ov6raX:21Yh
X-Hashcash: 1:22:070913:tls@lists.ietf.org::V/igS5hlOtSy2mBu:NejI
Date: Thu, 13 Sep 2007 10:31:21 +0200
In-Reply-To: <200709121716.l8CHGQrS015174@fs4113.wdf.sap.corp> (Martin Rex's message of "Wed, 12 Sep 2007 19:16:26 +0200 (MEST)")
Message-ID: <87abrrarvq.fsf@mocca.josefsson.org>
User-Agent: Gnus/5.110007 (No Gnus v0.7) Emacs/22.1 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
X-Spam-Status: No, score=-2.5 required=4.0 tests=AWL,BAYES_00, FORGED_RCVD_HELO,SPF_PASS autolearn=unavailable version=3.1.1
X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv
X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com
X-Virus-Status: Clean
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 1ac7cc0a4cd376402b85bc1961a86ac2
Cc: tls@lists.ietf.org
Subject: [TLS] Re: Review of draft-santesson-tls-gssapi-03
X-BeenThere: tls@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/tls>
List-Post: <mailto:tls@lists.ietf.org>
List-Help: <mailto:tls-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@lists.ietf.org?subject=subscribe>
Errors-To: tls-bounces@lists.ietf.org

Martin Rex <Martin.Rex@sap.com> writes:

>> Btw, I forgot to bring up channel bindings.  Have you considered
>> supporting it?  It is not critical to me, I consider X.509 or OpenPGP
>> authentication sufficient to solve the tunnel problem.
>
> AFAIK, the architecture of this proposal does provide secure channel
> bindings, in that it uses gss_prf output for the creation of the
> master secret using the PSK ciphersuites.

I missed that.  Right, it seems to be solved.

Thanks,
Simon

_______________________________________________
TLS mailing list
TLS@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls