Draft 0 of proposed charter

[email protected] (Sam Hartman) Tue, 11 May 2004 15:37:20 -0400 (EDT)
Newsgroups gmane.ietf.cat
Message-ID <[email protected]>

Here's a proposed charter.  I realize that it's too long for a real
charter.  For now I'd like to have an exaustive list of all the work
we plan to do so we can evaluate whether our scope is too extensive.
I'd appreciate suggestions on how to actually organize things for a
normal length charter.


Also, feedback is needed on work items.  We need to know if any should
be removed or added.


The Generic Security Services API [RFC 2743, RFC 2744] provides an API
for applications to set up security contexts and to use these contexts
for per-message protection services.  The Common Authentication
Technology Next Generation Working Group (Kitten) will work on
standardizing extensions  and improvements to the GSSAPI that the IETF
believes are necessary based on experience using GSSAPI over the last
10 years.  Extensions may be published as separate drafts or
or included in a GSSAPI version 3.  While version 2 of the GSSAPI may
be clarified, no backward incompatible changes may be made to this
version of the API.

This working group is chartered to work on the following extensions to
GSSAPI:

    - Definitions of channel bindings for TLS, IPSec  and other
      cryptographic  channels based on work started in the NFSV4
      working  group.

    - AN interface to store credentials based on
      draft-williams-gss-store-deleg-creds-xx.txt  

    - Extensions to solve problems posed by the Global Grid Forum's
      GSSAPI extensions document.

    - Extensions to deal with mechanism-specific extensibility  in a
      multi-mechanism
      environment.

    - Clarify the portable use of channel bindings and better specify
      channel bindings in a language-independent manner.

    - Specify threading requirements for GSSAPI.

    - Extend GSSAPI to support mechanisms that do not have a single
      canonical name for each authentication identity.

    - Extensions to support stackable GSSAPI mechanisms.


In addition to these extensions  the following mechanism work  is chartered:


    - The CCM mechanism

    - Revisions to RFC 2748 (SPNEGO) to correct problems that make the
      spec unimplementable and to document problems in
      widely-deployed attempts to implement this spec.
-++**==--++**==--++**==--++**==--++**==--++**==--++**==
This message was posted through the Stanford campus mailing list
server.  If you wish to unsubscribe from this mailing list, send the
message body of "unsubscribe ietf-cat-wg" to [email protected]