SACRED Framework -04
Dale Gustafson <[email protected]> Thu, 25 Apr 2002 11:14:06 -0500
| Newsgroups | gmane.ietf.sacred |
|---|---|
| Message-ID | <[email protected]> |
Hi All, We're ready to start another pass through the SACRED framework document to create draft-04 (final). Before we do that, we need to make sure we've got a fairly complete list of things to do. Things that we think should be included are: 1. Conditional Operations In Framework-03 we updated all primary functions (upload, download, delete) to include an optional Credential-ID that specifies a precondition that is checked by the server before performing the requested operation. The intent is to provide a way to minimize redundant transfers or accidentally overwriting a new credential with an older one, etc. The most recent Protocol draft provides a similar capability but is based on a last-modified date/time. Since there had been quite a bit of list discussion on this topic, I didn't want to arbitrarily change this when we created Framework-03 just prior to the Minneapolis meeting. What do folks think? Do we want to revise the framework document to match the most recent protocol document or leave it as is? 2. User Authentication Right now, the framework assumes that the client and server are mutually authenticated and a session level shared key is negotiated or derived then used to provide the outer encryption layer for credentials that are uploaded or downloaded. Choice of strong password algorithm(s) or equivalent is left to the protocol documents. In light of the recent IPR discussions, is there anything we need to change in this area of the Framework document? 3. Security Considerations At the Minneapolis IETF meeting we asked the group to review the latest security considerations section and suggest additional changes that should be added. Does anyone have suggested changes or additional ideas they'd like to see included in this section? 4. Basic Functions (Upload, Download, Delete) Based on list discussion and a number of discussions at IETF meetings, we focused on three primary credential exchange functions to standardize in SACRED protocols (Upload Credential, Download Credential, and Delete Credential). The latest protocol document only provides two basic functions (e.g., upload of a NULL credential is used to request a Delete operation). When we were drafting Framework-03 we didn't have time to change this part of the document. What does everyone think -- should we leave this as is or change to match the Protocol document? 5. Any Other Changes/Comments? Best Regards, Dale Gustafson