Re: Preliminary minutes of the call on the general-pac draft

Nico Williams <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <CAK3OfOgf9orTp6qET4dPKS2UU8cRB0YKMWtQidjv21591nd3pA@mail.gmail.com>
On Thu, Feb 16, 2012 at 9:23 AM, Sam Hartman <[email protected]> wrote:
> 4. Open issues on the CAMMAC draft:
>  - Consensus is that public key signature (pubkey-signature) need not be
>   specified at this time.
>  - Consensus is that being able to add new types of authentication to
>   the structure is worth discussion.

In light of the discussion of federation today I would say that: a)
public key signatures are likely to be eventually needed, b) if so
perhaps best obtained by reusing SAML, c) nonetheless we should ensure
that CAMMAC is extensible enough w.r.t. new signatures or MACs.

Also, I've a question about the GSS-EAP use of SAML: are signed SAML
objects tightly bound to each security context, such that they cannot
be pulled out and validated without reference to the security context
they were associated with?  This question is relevant to how tightly
the CAMMAC should be bound to the carrying Ticket (see below).

>  - Discussion of the session id / AD-ID-ANCHOR will be moved to the
>   list.
>  - Partial list of concerns (discussion will move to list)
>  - KDCissued uses the session key of the ticket, but the draft uses the
>    service's long-term key

One possible compromise would be to derive a key for CAMMAC from the
Ticket's session key.  This way the sub-key can be passed around with
the CAMMAC but without the Ticket, and still be validated.

> 4. Open issues on the PAD draft:
>  - Containing arbitrary SAML attributes in a PAD is out of scope for
>   this work, but specifying SAML authz data is in-scope for the WG.

Agreed.

>  - Issue of central home directories and PAD-Posix-Homedir will be taken
>   to the list.

I think we have consensus for Jeff's proposal now.

Nico
--
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.