Re: [Standards] Proposed XMPP Extension: Remote Authentication

2010-12-02 Thread Waqas Hussain
On Thu, Dec 2, 2010 at 7:54 AM, XMPP Extensions Editor edi...@xmpp.org wrote: The XMPP Extensions Editor has received a proposal for a new XEP. Title: Remote Authentication Abstract: This document defines an XMPP protocol extension that enables entities to use SASL for authentication with

Re: [Standards] Proposed XMPP Extension: Remote Authentication

2010-12-02 Thread Peter Saint-Andre
On 12/2/10 7:50 AM, Waqas Hussain wrote: On Thu, Dec 2, 2010 at 7:54 AM, XMPP Extensions Editor edi...@xmpp.org wrote: The XMPP Extensions Editor has received a proposal for a new XEP. Title: Remote Authentication Abstract: This document defines an XMPP protocol extension that enables

Re: [Standards] Proposed XMPP Extension: Remote Authentication

2010-12-02 Thread Kim Alvefur
On Thu, 2010-12-02 at 07:58 -0700, Peter Saint-Andre wrote: I wonder: can that model be generalized to other extensions? (Think pubsub, gateways, etc.) 4. The error condition is 'sasl-required'. Does this imply that normal MUC password auth should fail, even with a correct password? What

Re: [Standards] Proposed XMPP Extension: Remote Authentication

2010-12-02 Thread Peter Saint-Andre
On 12/2/10 8:12 AM, Kim Alvefur wrote: On Thu, 2010-12-02 at 07:58 -0700, Peter Saint-Andre wrote: I wonder: can that model be generalized to other extensions? (Think pubsub, gateways, etc.) 4. The error condition is 'sasl-required'. Does this imply that normal MUC password auth should

Re: [Standards] Proposed XMPP Extension: Remote Authentication

2010-12-02 Thread Waqas Hussain
On Thu, Dec 2, 2010 at 7:58 PM, Peter Saint-Andre stpe...@stpeter.im wrote: On 12/2/10 7:50 AM, Waqas Hussain wrote: On Thu, Dec 2, 2010 at 7:54 AM, XMPP Extensions Editor edi...@xmpp.org wrote: The XMPP Extensions Editor has received a proposal for a new XEP. Title: Remote Authentication

Re: [Standards] Proposed XMPP Extension: Remote Authentication

2010-12-02 Thread Peter Saint-Andre
On 12/2/10 8:18 AM, Waqas Hussain wrote: On Thu, Dec 2, 2010 at 7:58 PM, Peter Saint-Andre stpe...@stpeter.im wrote: It would also be interesting to use certificate-based authentication. I've been very interested in certificate-based auth for clients lately. S2S poses an issue for normal

Re: [Standards] Proposed XMPP Extension: Remote Authentication

2010-12-02 Thread Kurt Zeilenga
On Dec 2, 2010, at 8:35 AM, Kurt Zeilenga wrote: On Dec 1, 2010, at 6:54 PM, XMPP Extensions Editor wrote: The XMPP Extensions Editor has received a proposal for a new XEP. Title: Remote Authentication Abstract: This document defines an XMPP protocol extension that enables entities to

Re: [Standards] Proposed XMPP Extension: Remote Authentication

2010-12-02 Thread Dave Cridland
On Thu Dec 2 15:47:04 2010, Peter Saint-Andre wrote: Another idea: client auto-generates a cert for me and I register it with my server when I register an account (or after the first login). If you're reliant on the server to vouch for your public key (which is all the certificate is,

Re: [Standards] Proposed XMPP Extension: Remote Authentication

2010-12-02 Thread Kim Alvefur
On Thu, 2010-12-02 at 20:18 +0500, Waqas Hussain wrote: S2S poses an issue for normal EXTERNAL auth for remote clients. Didn't someone mention direct communication with the MUC host over Jingle? Then XTLS! :D -- Kim Alvefur z...@zash.se signature.asc Description: This is a digitally signed

Re: [Standards] Proposed XMPP Extension: Remote Authentication

2010-12-02 Thread Kim Alvefur
On Thu, 2010-12-02 at 17:06 +, Dave Cridland wrote: (FWIW, I wondered for some time about clients generating a CSR and having servers actually be PKIX CAs, but that equally gains nothing, except adding lots more exciting-looking X.509). Of course, if the certificate is signed by a

Re: [Standards] Proposed XMPP Extension: Remote Authentication

2010-12-02 Thread Dave Cridland
On Thu Dec 2 17:16:06 2010, Kim Alvefur wrote: On Thu, 2010-12-02 at 17:06 +, Dave Cridland wrote: (FWIW, I wondered for some time about clients generating a CSR and having servers actually be PKIX CAs, but that equally gains nothing, except adding lots more exciting-looking X.509).

[Standards] Proposed XMPP Extension: Remote Authentication

2010-12-01 Thread XMPP Extensions Editor
The XMPP Extensions Editor has received a proposal for a new XEP. Title: Remote Authentication Abstract: This document defines an XMPP protocol extension that enables entities to use SASL for authentication with remote services (such as Multi-User Chat rooms). URL: