Re: Request for feedback: draft-wibrown-ldapssotoken
Clément OUDOT <[email protected]> Mon, 5 Sep 2016 18:00:47 +0200
| Newsgroups | gmane.ietf.ldapext |
|---|---|
| Organization | Savoir-Faire Linux |
| Message-ID | <[email protected]> |
Le 05/09/2016 =E0 00:35, William Brown a =E9crit : > Hi, > > I would like to ask for feedback on the submission > draft-wibrown-ldapssotoken [0]. Section 5 deals with the ldap components > of the implementation. > > Thank you for your time and advice, > > [0] https://datatracker.ietf.org/doc/draft-wibrown-ldapssotoken/ > Hi, this draft is really interesting and indeed provides a solution when no = Kerberos is available. I was wondering if we could not get quite same behavior with proxy = authentication and standard single-sign on mechanisms: the user is known = by the web application trough token (JWT or whatever) and then the web = application authenticates for this user using LDAP proxy authz. Other remark, you don't give any hint on how the LDAP server should = manage its token database. Maybe it is intended as each LDAP server = should implement its own way, but we may think of standard LDAP objects = that could be used to manage these tokens directly in LDAP, instead of = using a separate database? Regards, -- = Cl=E9ment OUDOT Consultant en logiciels libres, Expert infrastructure et s=E9curit=E9 Savoir-faire Linux