Re: Comments on the GGF GSS-API extensions proposal

Nicolas Williams <[email protected]> Fri, 9 Apr 2004 16:23:24 -0500
Newsgroups gmane.ietf.cat
Message-ID <[email protected]>
On Fri, Apr 09, 2004 at 04:14:59PM -0500, Matt Crawford wrote:
> On Apr 7, 2004, at 12:28 PM, Nicolas Williams wrote:
> >2.  I oppose the credential delegation at any time concept.
> >
> >    Basically, I see no reason not to re-authenticate in order to
> >    delegate fresh credentials.
> 
> I know that what the globus people have in mind is the possibility of 
> delegating some credential other than the one that was used to 
> authenticate the sesssion.  For example, to delegate lesser, or 
> different rights to a remote process.

Nothing, I suppose, that couldn't be addressed by the GGF proposal for
credential options, without adding delegation-at-any-time.  But, see
below.

But at least my objections to this are not as strongly held as my
objections to the export-cred-to-env-var thing...

Also, given export-cred-to-token feature and credential options
technically that ought to be enough to implement delegation at any time.
I don't object to the export-cred-to-token feature.  I do object to
addressing authorization data through credentials/context options, but
don't object to other credentials options.

So perhaps I ought not oppose credential-delegation-at-any-time.

Nico
-- 
-++**==--++**==--++**==--++**==--++**==--++**==--++**==
This message was posted through the Stanford campus mailing list
server.  If you wish to unsubscribe from this mailing list, send the
message body of "unsubscribe ietf-cat-wg" to [email protected]