Re: Re: Password change via HTTP

>While I wholeheartedly agree that PKCS is *far* superior to password based
>schemes, I suspect passwords will be around for some time to come. The idea
>that every workstation out there will be equipped with smart-card readers
>and all users will be walking around with smart cards that contain their
>personal client certificate is lovely but not one I think we're likely
>to see everywhere for many years to come.

Smartcards are not a requirement for PKI. I have installed many PKIs
and very few use smartcards.


>Password based systems are just too easy to manage and can be trivially
>used with existing legacy systems.

Actually management of password systems in a large enterprise is far
from easy.

Management of passwords in a small system is no simpler than
locally issued certificates.

Either way, I don't think that the HTTP working group should spend
any more time trying to make passwords work when applications such
as SSH have demonstrated that public key based systems are more
feasible and easier to manage.


        Phill

Received on Sunday, 13 June 1999 16:34:09 UTC