Re: RFC 2617 Authentication and character sets revisited

Yngve Nysaeter Pettersen <yngve@opera.com> writes:

> The server and client must *also* agree about the binary representation
> (character set and encoding) of the username, as the username is used as an
> index into the password database.

The difference is that the username is also passed in clear, so the
encoding used on the wire for that attribute can be used (as is the
case for all the other inputs to the hash).  Perhaps we need a
sentence to make that explicit?

-- 
Scott Lawrence        
  http://skrb.org/scott/

Received on Wednesday, 26 November 2003 13:57:49 UTC