RE: [security-services] Proposal to add new AuthenticationMethod

From
Jahan Moreh <>
Date
2002-04-04T17:30:27+00:00
ID
000001c1dbfd$e6166240$b98ef5d1@JMOREH
Thread
RE: [security-services] Proposal to add new AuthenticationMethod
Title: Message

Thank you Hal.

 

Phil -

Assuming there are no objections, could we please consider this for 
inclusion in Core-31?

 

Thanks,

Jahan

 

---------------------------
Jahan Moreh
Chief Security 
Architect
tel: 310.286.3070
fax: 310.286.3076

  

  
-----Original Message-----
From: Hal Lockhart 
  [mailto:] 
Sent: Thursday, April 04, 2002 
  8:34 AM
To: ''; 
  
Subject: RE: 
  [security-services] Proposal to add new 
  AuthenticationMethod

  
I agree with this, but the URI: should be consistent with 
  current scheme for things defined in RFCs. See below. 

  
> With this email I'd like to propose that we add an 
  identifier 
> for Secure 
> Remote Password (SRP) protocol (specified in RFC 2945) to the list 
  of 
> AuthhenticationMethods. Brifely, SRP is based 
  on Diffie-Hellman and 
> provides a more secure way 
  of authenticating based on a 
> password (or 
  for 
> that matter any number of secrets).  The 
  proposed change 
> would be to add 
> the following to section 7.1 of Core: 
> 
  
> Secure Remote Passowrd (SRP) 
> URI: urn:oasis:names:tc:SAML:1.0:am:SRP 

  
For consitency this should be: 

  
URI: urn:ietf:rfc:2945 

  
> The authentication was performed by means of Secure 
  Remote Password 
> protocol as specified in RFC 
  2945 

  
Hal