Re: Comments on the GGF GSS-API extensions proposal
Nicolas Williams <[email protected]> Fri, 9 Apr 2004 16:23:24 -0500
| Newsgroups | gmane.ietf.cat |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Apr 09, 2004 at 04:14:59PM -0500, Matt Crawford wrote: > On Apr 7, 2004, at 12:28 PM, Nicolas Williams wrote: > >2. I oppose the credential delegation at any time concept. > > > > Basically, I see no reason not to re-authenticate in order to > > delegate fresh credentials. > > I know that what the globus people have in mind is the possibility of > delegating some credential other than the one that was used to > authenticate the sesssion. For example, to delegate lesser, or > different rights to a remote process. Nothing, I suppose, that couldn't be addressed by the GGF proposal for credential options, without adding delegation-at-any-time. But, see below. But at least my objections to this are not as strongly held as my objections to the export-cred-to-env-var thing... Also, given export-cred-to-token feature and credential options technically that ought to be enough to implement delegation at any time. I don't object to the export-cred-to-token feature. I do object to addressing authorization data through credentials/context options, but don't object to other credentials options. So perhaps I ought not oppose credential-delegation-at-any-time. Nico -- -++**==--++**==--++**==--++**==--++**==--++**==--++**== This message was posted through the Stanford campus mailing list server. If you wish to unsubscribe from this mailing list, send the message body of "unsubscribe ietf-cat-wg" to [email protected]