Re: GGF's extensions to GSS in Public Comment

Nicolas Williams <[email protected]> Mon, 5 Apr 2004 19:39:05 -0500
Newsgroups gmane.ietf.cat
Message-ID <[email protected]>
On Mon, Apr 05, 2004 at 01:46:46PM -0500, Von Welch wrote:
> 
> Nico,
> 
> If I can try to summarize your message:
> 
> 1) You seem to accept the use case of wanting to export/store
> credentials in stores other than the default and be able to use those
> stores in a generic manner.

I accept the first part.  And I agree that it would be nice to have a
generic interface for manipulating what is the "current credential
store" view, but I do not agree that it is necessary.

I have given examples of how GSS-API applications can manipulate their
current credential store view on various platforms.

And I've described (but not fully specified) a generic interface for
manipulating one's current credential store view.  But do note the
limiting factor to designing such a generic interface:  user context
changes cannot now be easily abstracted in a platform-independent way,
but user context switching generally implies a change in the current
credential store view.

> 2) You assert that the proper path to solve this is through extensions
> which separate the storing of credentials from the administration of
> the credential store. (And this is the crux of your disagreement with
> gss_export_cred()?)

My disagreement with gss_export_cred() is all about its use of
environment variables.  I'm about to post separately on this.

> 3) Your current draft handles the storing of credentials and you have
> a new draft coming that handles credential store administration.

Yes.

> 4) I think you imply that the the credential store administration can
> be done in such a way as to abstract the notion of environment
> variables (or any other mechanism-specific details) out of the API yet
> still support that functionality.

Yes.

> Am I with you?

Yes.

> If so, I'd be interested in seeing your second draft. I think I can
> see the benefits of your approach, but need see how the rubber and
> road meet.

I'll send you a draft draft privately.

Please see my next post about the problems with environment variables.

Nico
-- 
-++**==--++**==--++**==--++**==--++**==--++**==--++**==
This message was posted through the Stanford campus mailing list
server.  If you wish to unsubscribe from this mailing list, send the
message body of "unsubscribe ietf-cat-wg" to [email protected]