coComments on draft-ietf-krb-wg-pad-01
Sam Hartman <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
The motivation seems kind of tortured. I don't really care because the motivation is obvious to me. The motivation jumps very quickly to involving directories, which seems a bit tortured. I do not particularly request changes though; I'm fine if the motivation is a bit complex. Section 4.1: The realm is the name of the realm that authorization applies tto. Is that the client's realm or the service's realm? What am I supposed to do with the dns domain name? This fits in with Leif's issue about significant lack of semantics for these attributes. Does having a completely opaque UDID actually allow us to do the things we want for Windows interop? This is mostly directed at Nico. The discussion of mapped attributes is confusing; I cannot follow them at all. Discussion of anchor: I realize I've raised this before but it seems like we need to right down why we're using ticket expiration time to tie to the ticket rather than say session key. Also, the optional session ID in the anchor is overly vague. _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg