Re: Comments on the GGF GSS-API extensions proposal

Sam Hartman <[email protected]> Thu, 08 Apr 2004 13:48:40 -0400
Newsgroups gmane.ietf.cat
Message-ID <[email protected]>
>>>>> "Nicolas" == Nicolas Williams <[email protected]> writes:

    Nicolas> 3.  Can you explain again why the
    Nicolas> GSS_PROTECTION_FAIL_ON_CONTEXT_EXPIRATION option is
    Nicolas> needed, why the per-msg token functions shouldn't always
    Nicolas> fail when the context is expired, period?


I think this basically boils down to making application protocols
simpler.  It's particularly true for SASL that having contexts expire
is mostly unacceptable in practice.


AN argument could be made that the SASL GSSAPI mechanism (or all SASL
applications) should support rekeying.  Honestly, for most
applications I just don't think it is worth the complexity.  ANd the
designers of these protocols tend to agree with me.  Things like FTP,
many proprietary GSSAPI applications, etc do not support rekeying.
There is of course the notable exception of SAP.



Especially as we start talking about AES and 128-bit blocks, the
lifetime of many keys may be significantly longer than the lifetime of
the credentials.  And even for moderate traffic contexts, a DES key
may usefully be used longer than the context credentials last.

--Sam

-++**==--++**==--++**==--++**==--++**==--++**==--++**==
This message was posted through the Stanford campus mailing list
server.  If you wish to unsubscribe from this mailing list, send the
message body of "unsubscribe ietf-cat-wg" to [email protected]