[Ach] Fwd: Re: !SRP

Aaron Zauner azet at azet.org
Fri Dec 20 17:50:21 CET 2013


Hi,

Mailed with Philipp a couple of times w.r.t SRP. We asked me to share my
views on the ML as well (completely forgot to do that):
I've read through the SRP specs. a couple of days ago, the protocol looks
fine to me. In fact it looks elegantly engineered.

So I too think we should remove the !SRP statement.

Thanks,
Aaron


On Fri, Dec 20, 2013 at 12:56 AM, Adi Kriegisch <adi at kriegisch.at> wrote:

> Hi!
>
> > > own ciphers). What we have right now:
> > > Key Exchange:
> > > "Other key exchange mechanisms like Pre-Shared Key (PSK) or Secure
> Remote
> > >  Password (SRP) are irrelevant for regular SSL/TLS use."
> > I would remove "or Secure Remote Password (SRP) " from that sentence,
> > since it is actually relevant for regular SSL/TLS use, especially for
> > password-authentication applications like POP3S, SMTPS-Submission, IMAPS.
> Ok, done! Thanks!
>
> -- Adi
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.6 (GNU/Linux)
>
> iQIVAwUBUrOHr3REfA6phVy/AQjfiQ//YZSvbZsJNMFCjKJopKIJHr/44kcEvJP1
> Sahty8X5o1iyZVyvPjOQFgdf2g7kBpRePWrez784npFzV5nvmwXcXQkE0ZdDH4E2
> SNGOSD94pThPjeTtLpf8U5WabVmFIZu7L/DdmBB8UEOL55ZtElbUqCYzrzmnyZR+
> XU2TC24KbPOdzLkM0IHzqgo14btXI1UKsQ3+M2qwEFcd0X3K4DwjtB/UziM6lALR
> BH07oYmoTAn0oPhfqPMG0G4/S3roW3EfaIou5z/9W8savmrYX3f4i17+lm5RvkpO
> p3FJiKiOsZboQ9eOB+IRQ/kAVpAvX4zYlJa+jNN7j0Eg7kmG2LJPuDxlJ/RNdFDR
> emcAj6wfM9GgdYHREfGUOEaDmA9bw4mAsnyFfCprlhrsV+tJgOqL/kpoh1ZS+Jat
> 0OP5Lqb4yyJAbJ/MilcXnyWSBrPFbzixoW1UJa2oqxV68pT+rkELaGmWPImiHIcb
> HvUc13yEMyZKtmFhGnisxbL8Yj1zcwoDyLSC+OJsuUq3/KRIjJsMZUsiqWX2KhWo
> Op8tBLUSJjztUaSdxDZCKuax0GPnVtpiKI/ztW+8g1AVlqVeVo6ujMNIgo/nHViw
> UdgKFSam64K4rfqwGeIwmdwrEC4a7SVx1OvJXOYd2HshFyV0fCIe5FfCqU8swcrf
> olQjpFKq+qQ=
> =+369
> -----END PGP SIGNATURE-----
>
> _______________________________________________
> Ach mailing list
> Ach at lists.cert.at
> http://lists.cert.at/cgi-bin/mailman/listinfo/ach
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.cert.at/pipermail/ach/attachments/20131220/867abe7f/attachment.html>


More information about the Ach mailing list