SACRED Framework -04

Dale Gustafson <[email protected]> Thu, 25 Apr 2002 11:14:06 -0500
Newsgroups gmane.ietf.sacred
Message-ID <[email protected]>
Hi All,

We're ready to start another pass through the SACRED framework document to
create draft-04 (final).  Before we do that, we need to make sure we've got a
fairly complete list of things to do.

Things that we think should be included are:


1. Conditional Operations

In Framework-03 we updated all primary functions (upload, download, delete) to
include an optional Credential-ID that specifies a precondition that is checked
by the server before performing the requested operation.  The intent is to
provide a way to minimize redundant transfers or accidentally overwriting a new
credential with an older one, etc.

The most recent Protocol draft provides a similar capability but is based on a
last-modified date/time.  Since there had been quite a bit of list discussion on
this topic, I didn't want to arbitrarily change this when we created
Framework-03 just prior to the Minneapolis meeting.

What do folks think?  Do we want to revise the framework document to match the
most recent protocol document or leave it as is?


2. User Authentication

Right now, the framework assumes that the client and server are mutually
authenticated and a session level shared key is negotiated or derived then used
to provide the outer encryption layer for credentials that are uploaded or
downloaded.  Choice of strong password algorithm(s) or equivalent is left to the
protocol documents.

In light of the recent IPR discussions, is there anything we need to change in
this area of the Framework document?


3. Security Considerations

At the Minneapolis IETF meeting we asked the group to review the latest security
considerations section and suggest additional changes that should be added.

Does anyone have suggested changes or additional ideas they'd like to see
included in this section?


4. Basic Functions (Upload, Download, Delete)

Based on list discussion and a number of discussions at IETF meetings, we
focused on three primary credential exchange functions to standardize in SACRED
protocols (Upload Credential, Download Credential, and Delete Credential).  The
latest protocol document only provides two basic functions (e.g., upload of a
NULL credential is used to request a Delete operation).  When we were drafting
Framework-03 we didn't have time to change this part of the document.

What does everyone think -- should we leave this as is or change to match the
Protocol document?


5. Any Other Changes/Comments?


Best Regards,

Dale Gustafson