Re: Internet Draft: HTTP += SASL

Hallo Ken,

>> FYI.  Are you aware of the previous effort in this area
>> https://tools.ietf.org/html/draft-nystrom-http-sasl-12

>From the document history in the datatracker, as well as the last draft,
there was interest in improving on the last draft, but it never seems to
have concluded.

AFAIK our new proposal improves on the raised points,

Scalability:

 - stateless server side (server state passes via the client)
 - distribution of a sequence of connections is no problem

Security:

 - no fixation on DIGEST-MD5 (compatibility pulls down security)
 - support for channel binding without fixating protocol layering


Cheers,
 -Rick

Received on Thursday, 23 January 2020 11:19:32 UTC