Ian Paterson wrote:
> Are XMPP implementors
> experiencing interoperability issues with DIGEST-MD5? If so can't we fix
> them with a Best Practices XEP - as we did with SASL ANONYMOUS and SASL
> EXTERNAL? Which of the 7 problems with DIGEST-MD5 mentioned in [1] make
> DIGEST-MD5 less secure for XMPP authentication than SASL PLAIN?

+1 to a Best Practices XEP. If we can more tightly describe the XMPP
usage of DIGEST-MD5, then we can have consistent interoperability on our
network. At that point we won't need to worry so much about DIGEST-MD5
in general.

/psa

> [1]
> http://www.ietf.org/internet-drafts/draft-melnikov-digest-to-historic-00.txt

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to