[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: draft-ietf-msdp-spec-19



Russ,

>    I accept that Keyed MD5 as specified in RFC 2385 is the current
> practice.  The security considerations ought to be updated to encourage a 
> more robust authentication mechanism, preferably HMAC-SHA1.

It would be ok for us to get back to the WG with this if the spec was
going STD track.

In this case, the WG is ready to disband and the spec documents what's
been implemented and deployed, yet is only an interim step. Given
this, it seems that investing more effort into it is not worthwhile
or maybe even relevant (few implementations do even MD5 today.)

Can we let this one go?

Alex