Request to create KITTEN (daughter of CAT) BOF at IETF 60
Jeffrey Altman <[email protected]> Mon, 12 Jul 2004 11:22:03 -0400
| Newsgroups | gmane.ietf.cat |
|---|---|
| Organization | No Longer Affiliated with Columbia University in the City of New York |
| Message-ID | <[email protected]> |
This is a cryptographically signed message in MIME format.
--------------ms060809020100010900050203
Content-Type: text/html; charset=windows-1251
Content-Transfer-Encoding: 8bit
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta content="text/html;charset=windows-1251"
http-equiv="Content-Type">
<title></title>
</head>
<body bgcolor="#ffffff" text="#000000">
<meta content="text/html;charset=windows-1251" http-equiv="Content-Type">
<title></title>
[NOTE: Most of this e-mail is the same text as was sent on May 24th.
The changes are in the subject "Request for BOF" instead of "Request
for Working Group"; the addition of a new draft on GSSAPI Naming to the
Charter; the addition of a BOF Agenda section; the addition of a BOF
scheduling preferences section.]<br>
<br>
Russ and Steve:<br>
<br>
During the years since the Security Area's Common Authentication
Technology working group closed its doors there has been significant
new experience gained by those designing applications which utilize
GSSAPI v2 update 1 and the GSSAPI v2 C Language Bindings. This
experience has demonstrated several areas within the existing RFCs
(2743 and 2744) which are less than well-defined and/or lacking in
functionality.<br>
<br>
Attempts to address these deficiencies have resulted in discussions
taking place in many inappropriate forums. Some attempts have
occurred within existing IETF working groups which have rejected the
work as being outside the existing charter. Other attempts have
been pursued by third party organizations such as Global Grid Forum
which have chosen to extend IETF standards on their own due to an
inability to find a forum within IETF to pursue their work.<br>
<br>
The discussions on the IETF-CAT mailing list over the last several
months have been quite contentious not to mention fun to read.
The fruits of these discussions are the following:<br>
<ul>
<li>There are a number of interested parties who would like to
produce an new and improved GSSAPI specification be created to address
issues related to credentials management; thread safety; channel
binding usability (as discussed at IETF Minneapolis SAAG); C Language
usage; ABI stability; mechanism specific extensibility; and support for
mechanisms which do not provide a single canonical name.</li>
<li>There is an apparent consensus that the existing GSSAPI v2 RFCs
should be revised to include improved language to clarify areas which
have resulted in confusion for GSS mechanism implementors and
application developers. There should be new text describing the
lack of thread safety in GSSAPI v2 as well as descriptions of how to
support IPv6 in the existing channel bindings. However, these
revisions must not change the specification in any way which would
affect backward interoperability with either existing implementations
of GSSAPI v2 or even GSSAPI v1.</li>
<li>There is an apparent consensus that a new GSSAPI v3 specification
be created to support the extended functionality that is required.</li>
<li>There is rough consensus that work should proceed to develop new
forms of non-address based channel bindings which may be used to bind
GSS to TLS, IPSec, SSH, and other cryptographic channels.</li>
<li>There are also proposals that a new mechansism for negotiating
and properly using channel bindings (CCM) should be
defined and that SPNEGO (RFC 2748) be updated to correct flaws in its
design and specification.</li>
</ul>
The current participants of the IETF-CAT mailing list believe the time
is right to form the Common Authentication Technology Next Generation
working group (aka Kitten) to address these work areas. As such
we would like permission from the IESG to form the working group
at San Diego or if necessary to hold a BOF to discuss the need for the
working group
and the scope of its charter. What follows is a proposed charter
for the Kitten Working Group.<br>
<br>
<span style="text-decoration: underline;">Proposed Charter</span><br>
<br>
The Generic Security Services API [RFC 2743, RFC 2744] provides an API
for applications to set up security contexts and to use these contexts
for per-message protection services. The Common Authentication
Technology Next Generation Working Group (Kitten) will work on
standardizing extensions and improvements to the GSSAPI that the
IETF believes are necessary based on experience using GSSAPI over the
last 10 years. Extensions may be published as separate drafts or
included in a GSSAPI version 3. While version 2 of the GSSAPI
may be clarified, no backward incompatible changes will be made to this
version of the API.<br>
<br>
This working group is chartered to revise the GSSAPI v2 RFCs for the
purpose of clarifying areas of ambiguity:<br>
<ul>
<li>Use of channel bindings</li>
<li>Thread safety restrictions</li>
<li>C Language utilization</li>
<ul>
<li>use of const</li>
<li>utilization of gss types by the application</li>
<li>gss name space</li>
<li>improve recommendations for implementation specific types
(e.g., use pointers to incomplete structs)<br>
</li>
</ul>
<li>Guidelines for GSS-API mechanism designers</li>
<li>Guidelines for GSS-API application protocol designers</li>
</ul>
This working group is chartered to specify a non-backward compatible
GSSAPI v3 to support the following extensions:<br>
<ul>
<li>Clarify the portable use of channel bindings and better specify
channel bindings in a language-independent manner.</li>
<li>Specify thread safety extensions to allow multi-threaded
applications to use GSSAPI</li>
<li>Definitions of channel bindings for TLS, IPSec, SSH and other
cryptographic channels based on work started in the NFSV4
working group.</li>
<li>Defined a GSSAPI extension to allow applications to store
credentials. Discussions to be started based upon:</li>
<ul>
<li>draft-williams-gss-store-deleg-creds-xx.txt</li>
</ul>
<li>Extensions to solve problems posed by the Global Grid Forum's
GSSAPI extensions document.</li>
<li>Extensions to deal with mechanism-specific extensibility in a
multi-mechanism environment.</li>
<li>Extend GSSAPI to support mechanisms that do not have a single
canonical name for each authentication identity.</li>
<li>Extensions to support stackable GSSAPI mechanisms.</li>
</ul>
<br>
This working group is chartered to perform the following GSSAPI
mechanism specification work:<br>
<ul>
<li>Specify a GSSAPI v2/v3 Channel Conjunction Mechanism</li>
<li>Revise RFC 2748 (SPNEGO) to correct problems that make the
specification unimplementable and to document the problems found in
widely-deployed attempts to implement this spec.</li>
</ul>
<span style="text-decoration: underline;">End of Proposed Charter</span><br>
<br>
<br>
The participants of the IETF-CAT mailing list realize the quantity of
work which we desire to undertake is quite ambitious in scope. This is
simply an indication of how much work has accumulated over the last few
years since the CAT working group disbanded. We believe that we
can accomplish the stated work items in 18 months.<br>
<br>
<span style="text-decoration: underline;">Milestones</span><br>
<ul>
<li>Clarifications to GSSAPIv2 (six months to IESG) <br>
Informational<br>
[editor: Jeffrey Altman]</li>
<li>The Channel Conjunction Mechanism (CCM) for the GSSAPI (six
months to IESG) <br>
Proposed Standard<br>
[editors: Nicolas Williams/Mike Eisler]</li>
<li>On the Use of Channel Bindings to Secure Channels (six months to
IESG) <br>
Proposed Standard<br>
[editor: Nicolas Williams]<br>
draft-ietf-nfsv4-channel-bindings-01.txt<br>
</li>
<li>GSSAPIv3 (18 months to IESG)<br>
Proposed Standard<br>
[editor: to be determined]<br>
</li>
<li>Stackable Generic Security Service Pseudo-mechanisms<br>
Proposed Standard or to be folded into GSSAPIv3 <br>
[editor: Nicolas Williams]<br>
draft-williams-gssapi-stackable-pseudo-mechs-00.txt<br>
</li>
<li>GSS-APIv2 Extension for Storing Delegated Credentials<br>
</li>
Proposed Standard or to be folded into GSSAPIv3<br>
[editor: Nicolas Williams]<br>
draft-williams-gssapi-store-deleg-creds-00.txt<br>
<li>GSSAPI Mechanisms without a Single Canonical Name (12 months to
IESG)<br>
to be folded into GSSAPIv3<br>
[editor: Sam Hartman]<br>
draft-hartman-gss-naming-00.txt</li>
<li>SPNEGO (RFC
2478) Revisions (18 months to IESG)<br>
Proposed Standard<br>
[editor: to be determined]</li>
<br>
</ul>
<span style="text-decoration: underline;">End of Milestones</span><br>
<br>
<span style="text-decoration: underline;">Chairperson</span><br>
The proposed chairperson for the Kitten WG is Jeffrey Altman.<br>
<br>
<span style="text-decoration: underline;">Mailing List</span><br>
The current mailing list for discussions is
<a class="moz-txt-link-abbreviated"
href="mailto:[email protected]">[email protected]</a>.<br>
Due to the facts that no one at Stanford is actively involved in the <br>
discussions and the mailing list software is quite old, the working
group<br>
when formed will switch to a new mailing list. <br>
<br>
<u>Kitten BOF Agenda for IETF 60</u><br>
<br>
The following charter is proposed for the Kitten BOF. The BOF will
require a 2 hour time slot.<br>
<br>
* Introduction and Welcome [5 minutes] - Jeffrey Altman<br>
* Discussion of the Global Grid Forum GSS requirements [15 minutes] -
To Be Determined<br>
* Discussion of channel bindings portability issues (C struct et all)
[10 minutes] - Sam Hartman<br>
* Discussion of GSSAPI naming
[15 minutes] - Sam Hartman<br>
* Discussion of need for cryptographic channel bindings and CCM
[10 minutes] - Nicolas Williams<br>
* Discussion of specific channel bindings
[10 to 15 minutes] - To Be Determined<br>
* Discussion of Stackable Psuedo Mechanisms
[10 minutes] - Nicolas Williams<br>
* Discussion of the SPNEGO issues
[10 minutes] - Wyllys Ingersol<br>
* Charter discussion [15 minutes] - Jeffrey Altman<br>
<br>
<u>Kitten BOF Scheduling Requests</u><br>
<br>
Please do not schedule on Friday as it is known that two of the
speakers will not<br>
be able to attend due to scheduling conflicts with other events<br>
<br>
Presenters at the Kitten BOF are also active draft authors or working
group chairs in<br>
the following groups: NFSv4, KRB-WG or SASL<br>
<br>
Please attempt to avoid scheduling opposite other Security Area working
groups<br>
<br>
<br>
<br>
Sincerely, <br>
<br>
Jeffrey Altman (for the participants of the ietf-cat-wg mailing list)<br>
<br>
</body>
</html>
--------------ms060809020100010900050203
Content-Type: application/x-pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature
MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIJPzCC
AvowggJjoAMCAQICAwxk8TANBgkqhkiG9w0BAQQFADBiMQswCQYDVQQGEwJaQTElMCMGA1UE
ChMcVGhhd3RlIENvbnN1bHRpbmcgKFB0eSkgTHRkLjEsMCoGA1UEAxMjVGhhd3RlIFBlcnNv
bmFsIEZyZWVtYWlsIElzc3VpbmcgQ0EwHhcNMDQwNTI3MTc1ODU4WhcNMDUwNTI3MTc1ODU4
WjBrMQ8wDQYDVQQEEwZBbHRtYW4xFTATBgNVBCoTDEplZmZyZXkgRXJpYzEcMBoGA1UEAxMT
SmVmZnJleSBFcmljIEFsdG1hbjEjMCEGCSqGSIb3DQEJARYUamFsdG1hbkBjb2x1bWJpYS5l
ZHUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDc3JqO5AsZrozd+mJ2mPuCTYo2
+nJ9Qq6jtUYtp7YTMW4d2Q6GLhNaHb1l9m74SxuY4f5vP6JtZjr6p9+LCCxD0w0NVLKRgUDp
z+tKFitbkJe9BSCxCURRvY3vdWA71gSCUvZAN3346hHb4oGVqgdpmfFJXYAHWpC46wiL72N9
WxySzY17/0eU0c8+r9dNoLpPQeL43O66O80jCl1qnXMaXaakZPsfm+5W90MYXhpQ1WIQpv02
lBn3BH5YE8xwbsNrw5AF4v7pjMuW85GI6FrDmfbpJX473Rpl5rmv3TpXkJ+7UsIIO1puyS8r
1o7kjDZ5EUYJxxglTGR6XL/RNzqHAgMBAAGjMTAvMB8GA1UdEQQYMBaBFGphbHRtYW5AY29s
dW1iaWEuZWR1MAwGA1UdEwEB/wQCMAAwDQYJKoZIhvcNAQEEBQADgYEAZYeVFCMP0iV+UVa0
eFoXkzMVl61CNAVY2YQ9/QQazO3G4qNiif35ArrnjPRDRj5M7WTeOCFqPVuvCttyJRiDKsEe
L4Yah22mRA3mR7x52j2FquPYZ9qCr1IhrNGzsMk+gopX5G0fTHZb6+uDu5SeMPNNcIznGA7M
CMpXAJ2PcKgwggL6MIICY6ADAgECAgMMZPEwDQYJKoZIhvcNAQEEBQAwYjELMAkGA1UEBhMC
WkExJTAjBgNVBAoTHFRoYXd0ZSBDb25zdWx0aW5nIChQdHkpIEx0ZC4xLDAqBgNVBAMTI1Ro
YXd0ZSBQZXJzb25hbCBGcmVlbWFpbCBJc3N1aW5nIENBMB4XDTA0MDUyNzE3NTg1OFoXDTA1
MDUyNzE3NTg1OFowazEPMA0GA1UEBBMGQWx0bWFuMRUwEwYDVQQqEwxKZWZmcmV5IEVyaWMx
HDAaBgNVBAMTE0plZmZyZXkgRXJpYyBBbHRtYW4xIzAhBgkqhkiG9w0BCQEWFGphbHRtYW5A
Y29sdW1iaWEuZWR1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3NyajuQLGa6M
3fpidpj7gk2KNvpyfUKuo7VGLae2EzFuHdkOhi4TWh29ZfZu+EsbmOH+bz+ibWY6+qffiwgs
Q9MNDVSykYFA6c/rShYrW5CXvQUgsQlEUb2N73VgO9YEglL2QDd9+OoR2+KBlaoHaZnxSV2A
B1qQuOsIi+9jfVscks2Ne/9HlNHPPq/XTaC6T0Hi+NzuujvNIwpdap1zGl2mpGT7H5vuVvdD
GF4aUNViEKb9NpQZ9wR+WBPMcG7Da8OQBeL+6YzLlvORiOhaw5n26SV+O90aZea5r906V5Cf
u1LCCDtabskvK9aO5Iw2eRFGCccYJUxkely/0Tc6hwIDAQABozEwLzAfBgNVHREEGDAWgRRq
YWx0bWFuQGNvbHVtYmlhLmVkdTAMBgNVHRMBAf8EAjAAMA0GCSqGSIb3DQEBBAUAA4GBAGWH
lRQjD9IlflFWtHhaF5MzFZetQjQFWNmEPf0EGsztxuKjYon9+QK654z0Q0Y+TO1k3jghaj1b
rwrbciUYgyrBHi+GGodtpkQN5ke8edo9harj2Gfagq9SIazRs7DJPoKKV+RtH0x2W+vrg7uU
njDzTXCM5xgOzAjKVwCdj3CoMIIDPzCCAqigAwIBAgIBDTANBgkqhkiG9w0BAQUFADCB0TEL
MAkGA1UEBhMCWkExFTATBgNVBAgTDFdlc3Rlcm4gQ2FwZTESMBAGA1UEBxMJQ2FwZSBUb3du
MRowGAYDVQQKExFUaGF3dGUgQ29uc3VsdGluZzEoMCYGA1UECxMfQ2VydGlmaWNhdGlvbiBT
ZXJ2aWNlcyBEaXZpc2lvbjEkMCIGA1UEAxMbVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIENB
MSswKQYJKoZIhvcNAQkBFhxwZXJzb25hbC1mcmVlbWFpbEB0aGF3dGUuY29tMB4XDTAzMDcx
NzAwMDAwMFoXDTEzMDcxNjIzNTk1OVowYjELMAkGA1UEBhMCWkExJTAjBgNVBAoTHFRoYXd0
ZSBDb25zdWx0aW5nIChQdHkpIEx0ZC4xLDAqBgNVBAMTI1RoYXd0ZSBQZXJzb25hbCBGcmVl
bWFpbCBJc3N1aW5nIENBMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDEpjxVc1X7TrnK
mVoeaMB1BHCd3+n/ox7svc31W/Iadr1/DDph8r9RzgHU5VAKMNcCY1osiRVwjt3J8CuFWqo/
cVbLrzwLB+fxH5E2JCoTzyvV84J3PQO+K/67GD4Hv0CAAmTXp6a7n2XRxSpUhQ9IBH+nttE8
YQRAHmQZcmC3+wIDAQABo4GUMIGRMBIGA1UdEwEB/wQIMAYBAf8CAQAwQwYDVR0fBDwwOjA4
oDagNIYyaHR0cDovL2NybC50aGF3dGUuY29tL1RoYXd0ZVBlcnNvbmFsRnJlZW1haWxDQS5j
cmwwCwYDVR0PBAQDAgEGMCkGA1UdEQQiMCCkHjAcMRowGAYDVQQDExFQcml2YXRlTGFiZWwy
LTEzODANBgkqhkiG9w0BAQUFAAOBgQBIjNFQg+oLLswNo2asZw9/r6y+whehQ5aUnX9MIbj4
Nh+qLZ82L8D0HFAgk3A8/a3hYWLD2ToZfoSxmRsAxRoLgnSeJVCUYsfbJ3FXJY3dqZw5jowg
T2Vfldr394fWxghOrvbqNOUQGls1TXfjViF4gtwhGTXeJLHTHUb/XV9lTzGCAzswggM3AgEB
MGkwYjELMAkGA1UEBhMCWkExJTAjBgNVBAoTHFRoYXd0ZSBDb25zdWx0aW5nIChQdHkpIEx0
ZC4xLDAqBgNVBAMTI1RoYXd0ZSBQZXJzb25hbCBGcmVlbWFpbCBJc3N1aW5nIENBAgMMZPEw
CQYFKw4DAhoFAKCCAacwGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0BCQUx
DxcNMDQwNzEyMTUyMjAzWjAjBgkqhkiG9w0BCQQxFgQUu65MN1O71WWuKv9+DTHkgwkvmukw
UgYJKoZIhvcNAQkPMUUwQzAKBggqhkiG9w0DBzAOBggqhkiG9w0DAgICAIAwDQYIKoZIhvcN
AwICAUAwBwYFKw4DAgcwDQYIKoZIhvcNAwICASgweAYJKwYBBAGCNxAEMWswaTBiMQswCQYD
VQQGEwJaQTElMCMGA1UEChMcVGhhd3RlIENvbnN1bHRpbmcgKFB0eSkgTHRkLjEsMCoGA1UE
AxMjVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIElzc3VpbmcgQ0ECAwxk8TB6BgsqhkiG9w0B
CRACCzFroGkwYjELMAkGA1UEBhMCWkExJTAjBgNVBAoTHFRoYXd0ZSBDb25zdWx0aW5nIChQ
dHkpIEx0ZC4xLDAqBgNVBAMTI1RoYXd0ZSBQZXJzb25hbCBGcmVlbWFpbCBJc3N1aW5nIENB
AgMMZPEwDQYJKoZIhvcNAQEBBQAEggEAQrssFaDBBOGG3l2To8IOHs3vZ9FFLP77/6Dpp+ma
vUlo29w1r/eZagyrhxRIXiKjGL8N3kH06EJG+8cpuwEIN6YlbFm8wFqyb6ZNhG9Nak/LWWor
doPNREqUdHHjsCnMQzWrwDsD+xm5t66v/mWyzQGc+soBxmVcCmws6mPTLL3MJfvFHu4Vbrag
Ux0HtXs6wdpbiYnqgwb6WTXs+m2nk1ln9xqhfCVW1Kxn9MsBwxNZELanSoW9B1XLpq5W3/Qo
D8EBuVh+ucMccnlxanDxc58uAz3WX2n7Ph8J4a8QVCeXZW6uLQ5uq++2t/7SC6CDOoMTIzTz
nUKj5NLl7bIumQAAAAAAAA==
--------------ms060809020100010900050203--
-++**==--++**==--++**==--++**==--++**==--++**==--++**==
This message was posted through the Stanford campus mailing list
server. If you wish to unsubscribe from this mailing list, send the
message body of "unsubscribe ietf-cat-wg" to [email protected]