Name: draft-torvinen-http-digest-aka-v2-02
Title: Hypertext Transfer Protocol (HTTP) Digest Authentication Using Authentication and Key Agreement (AKA) Version-2
State: Pending
Authors: Vesa Torvinen, Jari Arkko, Mats Naslund
Group: Individual Submissions (none)
Date: 2004-11-15
HTTP Digest as specified in [4] is known to be vulnerable to
man-in-the-middle attacks if the client fails to authenticate the server in
TLS, or if the same passwords are used for authentication in some other
context without TLS. This is a general problem that exist not just with
HTTP Digest but also with other IETF protocols that use tunneled
authentication. This document specifies version 2 of the HTTP Digest AKA
algorithm [6]. This algorithm can be implemented in a way that it is
resistant to the man-in-the-middle attack.
|
|
|