Re: GGF's extensions to GSS in Public Comment
Nicolas Williams <[email protected]> Mon, 5 Apr 2004 19:39:05 -0500
| Newsgroups | gmane.ietf.cat |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Apr 05, 2004 at 01:46:46PM -0500, Von Welch wrote: > > Nico, > > If I can try to summarize your message: > > 1) You seem to accept the use case of wanting to export/store > credentials in stores other than the default and be able to use those > stores in a generic manner. I accept the first part. And I agree that it would be nice to have a generic interface for manipulating what is the "current credential store" view, but I do not agree that it is necessary. I have given examples of how GSS-API applications can manipulate their current credential store view on various platforms. And I've described (but not fully specified) a generic interface for manipulating one's current credential store view. But do note the limiting factor to designing such a generic interface: user context changes cannot now be easily abstracted in a platform-independent way, but user context switching generally implies a change in the current credential store view. > 2) You assert that the proper path to solve this is through extensions > which separate the storing of credentials from the administration of > the credential store. (And this is the crux of your disagreement with > gss_export_cred()?) My disagreement with gss_export_cred() is all about its use of environment variables. I'm about to post separately on this. > 3) Your current draft handles the storing of credentials and you have > a new draft coming that handles credential store administration. Yes. > 4) I think you imply that the the credential store administration can > be done in such a way as to abstract the notion of environment > variables (or any other mechanism-specific details) out of the API yet > still support that functionality. Yes. > Am I with you? Yes. > If so, I'd be interested in seeing your second draft. I think I can > see the benefits of your approach, but need see how the rubber and > road meet. I'll send you a draft draft privately. Please see my next post about the problems with environment variables. Nico -- -++**==--++**==--++**==--++**==--++**==--++**==--++**== This message was posted through the Stanford campus mailing list server. If you wish to unsubscribe from this mailing list, send the message body of "unsubscribe ietf-cat-wg" to [email protected]