RE: Proposal for new HTTP 1.1 authentication scheme

Paul:

% I talked to Scott Lawrence, and his products implements entity-digest, but
% he said he'd be glad to change if we (MS) implement it that way. (We
% currently have no implementation.) SInce WebDAV seems like it will require
% Digest, and we love WebDAV, there's a good chance we will be implementing
% it.

A not-too-much-correlated thought:

I was wondering why Digest does not use a salt, so that the server needn't
keep the password in clear.

Or is it me who misread the RFC?

ciao, .mau.

Received on Tuesday, 9 December 1997 15:01:08 UTC