Re: Comments on the GGF GSS-API extensions proposal

Sam Hartman <[email protected]> Fri, 09 Apr 2004 18:10:58 -0400
Newsgroups gmane.ietf.cat
Message-ID <[email protected]>
>>>>> "Nicolas" == Nicolas Williams <[email protected]> writes:

    Nicolas> But at least my objections to this are not as strongly
    Nicolas> held as my objections to the export-cred-to-env-var
    Nicolas> thing...

My objections to delegate cred at any time are somewhat stronger than
my objections to the export to env var thing.  Both are fairly strong
though.


    Nicolas> Also, given export-cred-to-token feature and credential
    Nicolas> options technically that ought to be enough to implement
    Nicolas> delegation at any time.  I don't object to the
    Nicolas> export-cred-to-token feature.  I do object to addressing
    Nicolas> authorization data through credentials/context options,
    Nicolas> but don't object to other credentials options.

EXport to token is useful only on a single system/implementation as
export context.

I actually think credentials options are the right place for things
actually having to do with negative authorization.  For example, a
time range restriction belongs on a credential.  But really we're getting more into this discussion than I want to have now.




-++**==--++**==--++**==--++**==--++**==--++**==--++**==
This message was posted through the Stanford campus mailing list
server.  If you wish to unsubscribe from this mailing list, send the
message body of "unsubscribe ietf-cat-wg" to [email protected]