--G4iJoqBmSsgzjUCe Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable
> 1) Can the User Registration that is built into SASL be used to join a=20 > Jabber Server or must the Jabber Registration system (as stated in=20 > http://www.jabber.org/protocol/registration.html ) be used? I ask=20 > because SASL has built in registration and authentication, and I am=20 > unsure how to tap into the SASL password files. This hasn't really been discussed in any detail. I would suggest joining the XMPP working group and bringing this question up there: http://www.jabber.org/cgi-bin/mailman/listinfo/xmppwg/ > 2) How felxable should a server be in the order of receved elements?=20 > Should a server be hard line on receving elements in the order listed,=20 > or should it be more open in the ordering, so long as all required=20 > elements are there? I'm not sure what you mean by this. Can you provide an example? > 3) Has anyone else thought that all servers should require SASL=20 > encription level of at least 40 (read 40 bit encription), and that with= =20 > this there should be an addition to Jabber:Server:DialBack and SASL so=20 > that Server to server comunications are encripted, because what is the=20 > good of a message that is only encripted some of the time. For backwards compatibility reasons, its not possible to enforce the use of SASL (and I doubt it ever will be). For guaranteed end-to-end security, its necessary to encrypt individual packets using GPG (or similar). The XMPP working group are actively pursuing these issues. I suggest you subscribe to the list and get involved :) Rob. --=20 Robert Norris GPG: 1024D/FC18E6C2 Email+Jabber: [EMAIL PROTECTED] Web: http://cataclysm.cx/ --G4iJoqBmSsgzjUCe Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQE+QEV+Wb13Z/wY5sIRAkdTAJ4xTahCAk7qowTIPA07xKyodSzaKgCfTru4 OzX4sPRkinsI3DHkuXcynT8= =S/D7 -----END PGP SIGNATURE----- --G4iJoqBmSsgzjUCe-- _______________________________________________ jdev mailing list [EMAIL PROTECTED] http://mailman.jabber.org/listinfo/jdev
