Re: Federated realms and PAD
Sam Hartman <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
>>>>> "Nico" == Nico Williams <[email protected]> writes: Nico> so that it can get backed into scripts (I know, use $HOME). Nico> And if we could rely on a global namespace, then I'd just drop Nico> the URI thing. But I don't think we can, not in federated Nico> realms that aren't remotely in the same "administrative Nico> domain", which I thought was part of what the PAD was all Nico> about. So, I've been thinking about federated contexts a lot lately mostly for ABFAB but certainly beyond that. When I explain why Kerberos is not federated, one of the biggest things I cite is that Kerberos has assumptions that bind it within one organization. It's my understanding that the PAD has a very permissive trust model. Obviously we haven't written it down yet, so this is still open. However, it doesn't sound to me like the PAD intends to embrace federated cross-organizational contexts. So, I think we can assume a high degree of trust between PAD producers and consumers. That probably influences some of these discussions somewhat. --Sam _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg