[TLS] Re: Review of draft-santesson-tls-gssapi-03
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[TLS] Re: Review of draft-santesson-tls-gssapi-03



Martin Rex <Martin.Rex at sap.com> writes:

>> Btw, I forgot to bring up channel bindings.  Have you considered
>> supporting it?  It is not critical to me, I consider X.509 or OpenPGP
>> authentication sufficient to solve the tunnel problem.
>
> AFAIK, the architecture of this proposal does provide secure channel
> bindings, in that it uses gss_prf output for the creation of the
> master secret using the PSK ciphersuites.

I missed that.  Right, it seems to be solved.

Thanks,
Simon

_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.