IPP Mail Archive: IPP> Re: Area Directors' comments on IPP

IPP> Re: Area Directors' comments on IPP

Keith Moore (moore@cs.utk.edu)
Mon, 08 Dec 1997 13:22:48 -0500

> 1) Support for SSL3 in TLS. Harald and Keith wanted to make sure that our
> specs say that we MUST support the mandatory features that are minimum
> requirements for TLS, such as the cypher suite.

1. IESG has not allowed other groups to reference SSL, and it unlikely
that an exception would be made for IPP. If IPP uses SSL-like
technology, the reference should be to the TLS RFC.

2. If IPP specifies TLS authentication, IPP must either implicitly use
the mandatory ciphersuite from the TLS spec, or specify at least one
mandatory TLS ciphersuite.

3. It will be very difficult for IPP to convince IESG to accept any
mandatory TLS ciphersuite that uses encumbered algorithms, especially
given that adequate unencumbered algorithms seem to be available.

Suggestion: specify MUST implement ciphersuite
TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA, and MAY (or SHOULD?) implement one
or more of the ciphersuites commonly used with SSL3.

Keith