Re: Request for feedback: draft-wibrown-ldapssotoken

ClĂ©ment OUDOT <[email protected]> Mon, 5 Sep 2016 18:00:47 +0200
Newsgroups gmane.ietf.ldapext
Organization Savoir-Faire Linux
Message-ID <[email protected]>

Le 05/09/2016 =E0 00:35, William Brown a =E9crit :
> Hi,
>
> I would like to ask for feedback on the submission
> draft-wibrown-ldapssotoken [0]. Section 5 deals with the ldap components
> of the implementation.
>
> Thank you for your time and advice,
>
> [0] https://datatracker.ietf.org/doc/draft-wibrown-ldapssotoken/
>

Hi,

this draft is really interesting and indeed provides a solution when no =

Kerberos is available.

I was wondering if we could not get quite same behavior with proxy =

authentication and standard single-sign on mechanisms: the user is known =

by the web application trough token (JWT or whatever) and then the web =

application authenticates for this user using LDAP proxy authz.

Other remark, you don't give any hint on how the LDAP server should =

manage its token database. Maybe it is intended as each LDAP server =

should implement its own way, but we may think of standard LDAP objects =

that could be used to manage these tokens directly in LDAP, instead of =

using a separate database?

Regards,

-- =

Cl=E9ment OUDOT
Consultant en logiciels libres, Expert infrastructure et s=E9curit=E9
Savoir-faire Linux