<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.newman-sasl-passdss" target="https://datatracker.ietf.org/doc/html/draft-newman-sasl-passdss-01">
   <front>
      <title>DSS Secured Password Authentication Mechanism</title>
      <author initials="C." surname="Newman" fullname="Chris Newman">
         <organization>Innosoft</organization>
      </author>
      <date month="March" day="5" year="1998" />
      <abstract>
	 <t>     Some system administrators are faced with a choice between
     deploying a new authentication infrastructure or sending
     unencrypted passwords in the clear over the Internet.  Deploying a
     new authentication infrastructure often involves modifying
     operating system services or keeping parallel authentication
     databases up to date and is thus unacceptable to many
     administrators.
 
     Solutions which encrypt the entire session are often crippled with
     weak keys (due to government restrictions) which are unsuitable for
     passwords.  In addition, such solutions often reduce performance of
     the entire session to an unacceptable level.  This specification
     defines a SASL [SASL] mechanism which is compatible with existing
     password-based authentication databases and does not require a
     security layer for the remainder of the session.
 
     [NOTE: Public discussion of this mechanism may take place on the
     ietf-sasl@imc.org mailing list with a subscription address of
     ietf-sasl-request@imc.org.  Private comments may be sent to the
     author].

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-newman-sasl-passdss-01" />
   
</reference>
