Re: Comments on the GGF GSS-API extensions proposal
Nicolas Williams <[email protected]> Thu, 8 Apr 2004 12:59:16 -0500
| Newsgroups | gmane.ietf.cat |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Apr 08, 2004 at 01:48:40PM -0400, Sam Hartman wrote: > >>>>> "Nicolas" == Nicolas Williams <[email protected]> writes: > > Nicolas> 3. Can you explain again why the > Nicolas> GSS_PROTECTION_FAIL_ON_CONTEXT_EXPIRATION option is > Nicolas> needed, why the per-msg token functions shouldn't always > Nicolas> fail when the context is expired, period? > > > I think this basically boils down to making application protocols > simpler. It's particularly true for SASL that having contexts expire > is mostly unacceptable in practice. > > > AN argument could be made that the SASL GSSAPI mechanism (or all SASL > applications) should support rekeying. Honestly, for most > applications I just don't think it is worth the complexity. ANd the > designers of these protocols tend to agree with me. Things like FTP, > many proprietary GSSAPI applications, etc do not support rekeying. > There is of course the notable exception of SAP. Additional exceptions: SSHv2, ONC RPC w/ RPCSEC_GSS. So what's exceptional here? SASL and FTP? Or SAP, SSHv2 and RPCSEC_GSS? Nico -- -++**==--++**==--++**==--++**==--++**==--++**==--++**== This message was posted through the Stanford campus mailing list server. If you wish to unsubscribe from this mailing list, send the message body of "unsubscribe ietf-cat-wg" to [email protected]