The IESG has received a request from the Registration Protocols Extensions WG
(regext) to consider the following document: - 'Extensible Provisioning
Protocol (EPP) Secure Authorization
   Information for Transfer'
  <draft-ietf-regext-secure-authinfo-transfer-06.txt> as Proposed Standard

The IESG plans to make a decision in the next few weeks, and solicits final
comments on this action. Please send substantive comments to the
[email protected] mailing lists by 2021-03-22. Exceptionally, comments may
be sent to [email protected] instead. In either case, please retain the beginning
of the Subject line to allow automated sorting.

Abstract


   The Extensible Provisioning Protocol (EPP), in RFC 5730, defines the
   use of authorization information to authorize a transfer.  Object-
   specific, password-based authorization information (see RFC 5731 and
   RFC 5733) is commonly used, but raises issues related to the
   security, complexity, storage, and lifetime of authentication
   information.  This document defines an operational practice, using
   the EPP RFCs, that leverages the use of strong random authorization
   information values that are short-lived, not stored by the client,
   and stored by the server using a cryptographic hash that provides for
   secure authorization information that can safely be used for object
   transfers.




The file can be obtained via
https://datatracker.ietf.org/doc/draft-ietf-regext-secure-authinfo-transfer/



No IPR declarations have been submitted directly on this I-D.





_______________________________________________
regext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/regext

Reply via email to