[TLS] Re: Review of draft-santesson-tls-gssapi-03
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[TLS] Re: Review of draft-santesson-tls-gssapi-03
Martin Rex <Martin.Rex at sap.com> writes:
>> Btw, I forgot to bring up channel bindings. Have you considered
>> supporting it? It is not critical to me, I consider X.509 or OpenPGP
>> authentication sufficient to solve the tunnel problem.
>
> AFAIK, the architecture of this proposal does provide secure channel
> bindings, in that it uses gss_prf output for the creation of the
> master secret using the PSK ciphersuites.
I missed that. Right, it seems to be solved.
Thanks,
Simon
_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.