The IESG has received a request from the Registration Protocols Extensions WG (regext) to consider the following document: - 'Extensible Provisioning Protocol (EPP) Secure Authorization Information for Transfer' <draft-ietf-regext-secure-authinfo-transfer-06.txt> as Proposed Standard
The IESG plans to make a decision in the next few weeks, and solicits final comments on this action. Please send substantive comments to the [email protected] mailing lists by 2021-03-22. Exceptionally, comments may be sent to [email protected] instead. In either case, please retain the beginning of the Subject line to allow automated sorting. Abstract The Extensible Provisioning Protocol (EPP), in RFC 5730, defines the use of authorization information to authorize a transfer. Object- specific, password-based authorization information (see RFC 5731 and RFC 5733) is commonly used, but raises issues related to the security, complexity, storage, and lifetime of authentication information. This document defines an operational practice, using the EPP RFCs, that leverages the use of strong random authorization information values that are short-lived, not stored by the client, and stored by the server using a cryptographic hash that provides for secure authorization information that can safely be used for object transfers. The file can be obtained via https://datatracker.ietf.org/doc/draft-ietf-regext-secure-authinfo-transfer/ No IPR declarations have been submitted directly on this I-D. _______________________________________________ regext mailing list [email protected] https://www.ietf.org/mailman/listinfo/regext
