Re: Federated realms and PAD

Sam Hartman <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
>>>>> "Nico" == Nico Williams <[email protected]> writes:

    Nico> so that it can get backed into scripts (I know, use $HOME).
    Nico> And if we could rely on a global namespace, then I'd just drop
    Nico> the URI thing.  But I don't think we can, not in federated
    Nico> realms that aren't remotely in the same "administrative
    Nico> domain", which I thought was part of what the PAD was all
    Nico> about.


So, I've been thinking about federated contexts a lot lately mostly for
ABFAB but certainly beyond that.  When I explain why Kerberos is not
federated, one of the biggest things I cite is that Kerberos has
assumptions that bind it within one organization.

It's my understanding that the PAD has a very permissive trust
model. Obviously we haven't written it down yet, so this is still open.
However, it doesn't sound to me like the PAD intends to embrace
federated cross-organizational contexts.  So, I think we can assume a
high degree of trust between PAD producers and consumers.  That probably
influences some of these discussions somewhat.

--Sam
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.