IETF-SSH archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
core draft issue resolution
Proposed core issue resolutions from today's meeting:
If anyone objects to these resolutions, or thinks I mis-summarized the
discussion, please speak up.
ticket 440, 441, 450: close, edits complete.
ticket 453: WG chair to identify stable reference for sshv1
(sent to list recently)
ticket 454: explicitly grandfather 3DES
Editor to insert text equivalent to:
NOTE: There is a known attack on 3-key 3DES involving
2^112 space and 2^56 time; however, for the purposes of this
requirement 3DES is considered to be strong enough.
ticket 461 (implicit server auth):
Editor to dig up clarification from list archives,
insert into document.
ticket 462: different algs in each direction
proposal: allow but discourage; Editor to supply text.
ticket 463: login timeout
proposal: no change to document
rationale:
- 10 minutes is shorter than typical SMTP listener idle timeout
- user interaction is covered in this timeout (entering
passwords, etc.,; as a result there may be accessibility requirements
for slow typers..)
- implementations will likely have knobs to adjust this
ticket 464: utf8:
utf8 requires input canonicalization; stringprep of usernames
and passwords was previously solved by SASL in
draft-ietf-sasl-saslprep-10.txt (in RFC Editor Queue, EDIT state)
Rather than reinvent the wheel, just cite it.
ticket 465: close. was request for consulting
ticket 474: x509: remove x509-related text. joe galbraith to supply
followup I-D documenting what they do for x509
ticket 460, 601: no consensus on list.
flipped coin, heads for "group2", tails for "group14",
came up tails
will stick with diffie-hellman-group14-sha1
Home |
Main Index |
Thread Index |
Old Index