[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Document Action: 'Hypertext Transfer Protocol (HTTP) Digest Authentication Using Authentication and Key Agreement (AKA) Version-2' to Informational RFC
The IESG has approved the following document:
- 'Hypertext Transfer Protocol (HTTP) Digest Authentication Using
Authentication and Key Agreement (AKA) Version-2 '
<draft-torvinen-http-digest-aka-v2-02.txt> as an Informational RFC
This document has been reviewed in the IETF but is not the product of an
IETF Working Group.
The IESG contact person is Allison Mankin.
RFC Editor Note
Abstract
OLD:
HTTP Digest as specified in [4] is known to be vulnerable to
man-in-the-middle attacks if the client fails to authenticate the
server in TLS, or if the same passwords are used for authentication
in some other context without TLS. This is a general problem that
exist not just with HTTP Digest but also with other IETF protocols
that use tunneled authentication. This document specifies version 2
of the HTTP Digest AKA algorithm [6]. This algorithm can be
implemented in a way that it is resistant to the man-in-the-middle
attack.
NEW:
HTTP Digest as specified in RFC 2617 is known to be vulnerable to
man-in-the-middle attacks if the client fails to authenticate the
server in TLS, or if the same passwords are used for authentication
in some other context without TLS. This is a general problem that
exist not just with HTTP Digest but also with other IETF protocols
that use tunneled authentication. This document specifies version 2
of the HTTP Digest AKA algorithm (RFC 3310). This algorithm can be
implemented in a way that it is resistant to the man-in-the-middle
attack.
_______________________________________________
IETF-Announce mailing list
IETF-Announce at ietf.org
https://www1.ietf.org/mailman/listinfo/ietf-announce