IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

core draft issue resolution



Proposed core issue resolutions from today's meeting:

If anyone objects to these resolutions, or thinks I mis-summarized the
discussion, please speak up.

ticket 440, 441, 450: close, edits complete.

ticket 453: WG chair to identify stable reference for sshv1
	(sent to list recently)

ticket 454: explicitly grandfather 3DES
	Editor to insert text equivalent to:

	NOTE: There is a known attack on 3-key 3DES involving
	2^112 space and 2^56 time; however, for the purposes of this
	requirement 3DES is considered to be strong enough.

ticket 461 (implicit server auth): 
	Editor to dig up clarification from list archives, 
	insert into document.

ticket 462: different algs in each direction
	proposal: allow but discourage; Editor to supply text.

ticket 463: login timeout
	proposal: no change to document

	rationale:
	- 10 minutes is shorter than typical SMTP listener idle timeout
	- user interaction is covered in this timeout (entering
	passwords, etc.,; as a result there may be accessibility requirements
	for slow typers..)
	- implementations will likely have knobs to adjust this

ticket 464: utf8:
	utf8 requires input canonicalization; stringprep of usernames
	and passwords was previously solved by SASL in
	draft-ietf-sasl-saslprep-10.txt (in RFC Editor Queue, EDIT state)

	Rather than reinvent the wheel, just cite it.

ticket 465: close.  was request for consulting

ticket 474: x509: remove x509-related text.  joe galbraith to supply
	followup I-D documenting what they do for x509

ticket 460, 601:  no consensus on list.
	flipped coin, heads for "group2", tails for "group14", 
	came up tails

	will stick with diffie-hellman-group14-sha1





Home | Main Index | Thread Index | Old Index