Draft 0 of proposed charter
[email protected] (Sam Hartman) Tue, 11 May 2004 15:37:20 -0400 (EDT)
| Newsgroups | gmane.ietf.cat |
|---|---|
| Message-ID | <[email protected]> |
Here's a proposed charter. I realize that it's too long for a real
charter. For now I'd like to have an exaustive list of all the work
we plan to do so we can evaluate whether our scope is too extensive.
I'd appreciate suggestions on how to actually organize things for a
normal length charter.
Also, feedback is needed on work items. We need to know if any should
be removed or added.
The Generic Security Services API [RFC 2743, RFC 2744] provides an API
for applications to set up security contexts and to use these contexts
for per-message protection services. The Common Authentication
Technology Next Generation Working Group (Kitten) will work on
standardizing extensions and improvements to the GSSAPI that the IETF
believes are necessary based on experience using GSSAPI over the last
10 years. Extensions may be published as separate drafts or
or included in a GSSAPI version 3. While version 2 of the GSSAPI may
be clarified, no backward incompatible changes may be made to this
version of the API.
This working group is chartered to work on the following extensions to
GSSAPI:
- Definitions of channel bindings for TLS, IPSec and other
cryptographic channels based on work started in the NFSV4
working group.
- AN interface to store credentials based on
draft-williams-gss-store-deleg-creds-xx.txt
- Extensions to solve problems posed by the Global Grid Forum's
GSSAPI extensions document.
- Extensions to deal with mechanism-specific extensibility in a
multi-mechanism
environment.
- Clarify the portable use of channel bindings and better specify
channel bindings in a language-independent manner.
- Specify threading requirements for GSSAPI.
- Extend GSSAPI to support mechanisms that do not have a single
canonical name for each authentication identity.
- Extensions to support stackable GSSAPI mechanisms.
In addition to these extensions the following mechanism work is chartered:
- The CCM mechanism
- Revisions to RFC 2748 (SPNEGO) to correct problems that make the
spec unimplementable and to document problems in
widely-deployed attempts to implement this spec.
-++**==--++**==--++**==--++**==--++**==--++**==--++**==
This message was posted through the Stanford campus mailing list
server. If you wish to unsubscribe from this mailing list, send the
message body of "unsubscribe ietf-cat-wg" to [email protected]