coComments on draft-ietf-krb-wg-pad-01

Sam Hartman <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>

The motivation seems kind of tortured.  I don't really care because the
motivation is obvious to me. The motivation jumps very quickly to
involving directories, which seems a bit tortured.
I do not particularly request changes though; I'm fine if the motivation
is a bit complex.

Section 4.1:

The realm is the name of the realm that authorization applies tto.
Is that the client's realm or the service's realm?

What am I supposed to do with the dns domain name?
This fits in with Leif's issue about significant lack of semantics for
these attributes.


Does having a completely opaque UDID actually allow us to do the things
we want for Windows interop? This is mostly directed at Nico.


The discussion of mapped attributes is confusing; I cannot follow them
at all.



Discussion of anchor:

I realize I've raised this before but it seems like we need to right
down why we're using ticket expiration time to tie to the ticket rather
than say session key.
Also, the optional session ID in the anchor is overly vague.
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.