-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 7/6/09 11:50 AM, Alexey Melnikov wrote:
> Eloi Bail wrote:
> 
>> Hi,
>>
>> Indeed this draft provides more detailed information. It's great :)
> 
> I like the new text on ANONYMOUS as well.

Good.

>> I think it would be useful to make a similar draft for PLAIN method,
>> the core xmpp RFC only explaining the digest-md5 method.
> 
> I think we need to be careful about describing handling of each SASL
> mechanism, as this defeats the purpose of having generic SASL libraries
> that support multiple authentication mechanisms.
> 
> While I agree that ANONYMOUS and PLAIN are a bit special, we need to
> have a criteria on which mechanisms should deserve own XEPs. If there
> are issues with how some SASL mechanisms are described, which are not
> specific to XMPP, then the IETF SASL WG needs to be notified.

Agreed. It seems to me that, for example, RFC 4505 (ANONYMOUS) leaves a
number of items up to the implementation or the using application. For
example, what does "restricted access" mean? That might mean something
different in XMPP vs. IMAP or LDAP or whatever, so I think it's good to
discuss those issues in a XEP. If our discussions raise more general
issues, then I think it's important for us to bring those to the SASL WG
list.

Peter

- --
Peter Saint-Andre
https://stpeter.im/


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkpSOzsACgkQNL8k5A2w/vzEZgCfSKTOtiT2n+R/+EfsRsr2uxFf
GB0AnRr27eozz+oJL4mUhQY3I7eagHz2
=9w6n
-----END PGP SIGNATURE-----

Reply via email to