From beepwg-admin@lists.beepcore.org  Wed Oct 16 18:06:43 2002
Received: from qawoor.dbc.mtview.ca.us (adsl-64-168-10-251.dsl.scrm01.pacbell.net [64.168.10.251])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA13545
	for <beep-archive@lists.ietf.org>; Wed, 16 Oct 2002 18:06:42 -0400 (EDT)
Received: from qawoor.dbc.mtview.ca.us (localhost [127.0.0.1])
	by qawoor.dbc.mtview.ca.us (8.11.3/8.11.5) with ESMTP id g9GM45L23635;
	Wed, 16 Oct 2002 15:04:05 -0700 (PDT)
Received: from act-of-god.permabit.com (act-of-god.permabit.com [4.36.55.5])
	by qawoor.dbc.mtview.ca.us (8.11.3/8.11.5) with ESMTP id g9GM3nL23623
	for <beepwg@lists.beepcore.org>; Wed, 16 Oct 2002 15:03:50 -0700 (PDT)
Received: from questionably-configured.permabit.com.permabit.com (questionably-configured.permabit.com [10.142.0.92])
	by act-of-god.permabit.com (Postfix) with ESMTP id 9AC2413AA1
	for <beepwg@lists.beepcore.org>; Wed, 16 Oct 2002 18:06:54 -0400 (EDT)
To: <beepwg@lists.beepcore.org>
From: Jered Floyd <jered@permabit.com>
In-Reply-To: <000001c26319$5cfaaea0$8b3b869f@central>
Message-ID: <87n0pef37l.fsf@questionably-configured.permabit.com>
Lines: 19
User-Agent: Gnus/5.0808 (Gnus v5.8.8) XEmacs/21.4 (Common Lisp)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Subject: [BEEPwg] Clarification on RFC 3080, 4.1.3
Sender: beepwg-admin@lists.beepcore.org
Errors-To: beepwg-admin@lists.beepcore.org
X-BeenThere: beepwg@lists.beepcore.org
X-Mailman-Version: 2.0.6
Precedence: bulk
List-Help: <mailto:beepwg-request@lists.beepcore.org?subject=help>
List-Post: <mailto:beepwg@lists.beepcore.org>
List-Subscribe: <http://lists.beepcore.org/mailman/listinfo/beepwg>,
	<mailto:beepwg-request@lists.beepcore.org?subject=subscribe>
List-Id: Mailing list for the IETF's BEEP working group <beepwg.lists.beepcore.org>
List-Unsubscribe: <http://lists.beepcore.org/mailman/listinfo/beepwg>,
	<mailto:beepwg-request@lists.beepcore.org?subject=unsubscribe>
List-Archive: <http://lists.beepcore.org/pipermail/beepwg/>
Date: 16 Oct 2002 18:06:54 -0400


At the end of section 4.1.3 of RFC 3080 (bottom of page 43), SASL's
EXTERNAL mechanism is described.  It ends with:

   if present, the authentication identity must be consistent with the
   credentials provided by the external authentication service (if the
   authentication identity is empty, then an authorization identity is
   automatically derived from the credentials provided by the external
   authentication service).

In the parenthetical comment, is the word "authorization" meant to
be "authentication"?  I believe this sentence is trying to state that
if an authentication identity is provided via SASL EXTERNAL, it must
match the external authentication identity, however if it is not
present the authentication identity is taken from the external
credentials.

--Jered


_______________________________________________
BEEPwg mailing list
BEEPwg@lists.beepcore.org
http://lists.beepcore.org/mailman/listinfo/beepwg


From beepwg-admin@lists.beepcore.org  Fri Oct 18 17:53:36 2002
Received: from qawoor.dbc.mtview.ca.us (adsl-64-168-10-251.dsl.scrm01.pacbell.net [64.168.10.251])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA10983
	for <beep-archive@lists.ietf.org>; Fri, 18 Oct 2002 17:53:34 -0400 (EDT)
Received: from qawoor.dbc.mtview.ca.us (localhost [127.0.0.1])
	by qawoor.dbc.mtview.ca.us (8.11.3/8.11.5) with ESMTP id g9ILpCL13964;
	Fri, 18 Oct 2002 14:51:12 -0700 (PDT)
Received: from mxout5.cac.washington.edu (mxout5.cac.washington.edu [140.142.32.21])
	by qawoor.dbc.mtview.ca.us (8.11.3/8.11.5) with ESMTP id g9IKsrL13624
	for <beepwg@lists.beepcore.org>; Fri, 18 Oct 2002 13:54:54 -0700 (PDT)
Received: from mailscan-out2.cac.washington.edu (mailscan-out2.cac.washington.edu [140.142.33.17])
	by mxout5.cac.washington.edu (8.12.1+UW01.12/8.12.1+UW02.09) with SMTP id g9IKwHDx022817
	for <beepwg@lists.beepcore.org>; Fri, 18 Oct 2002 13:58:18 -0700
Received: FROM smtp.washington.edu BY mailscan-out2.cac.washington.edu ; Fri Oct 18 13:58:17 2002 -0700
Received: from D-140-142-21-60.dhcp4.washington.edu (D-140-142-21-60.dhcp4.washington.edu [140.142.21.60])
	(authenticated bits=0)
	by smtp.washington.edu (8.12.1+UW01.12/8.12.1+UW02.08) with ESMTP id g9IKwHpK014375
	(version=TLSv1/SSLv3 cipher=EDH-RSA-DES-CBC3-SHA bits=168 verify=NOT);
	Fri, 18 Oct 2002 13:58:17 -0700
From: "RL 'Bob' Morgan" <rlmorgan@washington.edu>
X-X-Sender: rlmorgan@localhost.localdomain
To: Jered Floyd <jered@permabit.com>
cc: beepwg@lists.beepcore.org
Subject: Re: [BEEPwg] Clarification on RFC 3080, 4.1.3
In-Reply-To: <87n0pef37l.fsf@questionably-configured.permabit.com>
Message-ID: <Pine.LNX.4.44.0210181335020.7775-100000@localhost.localdomain>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: beepwg-admin@lists.beepcore.org
Errors-To: beepwg-admin@lists.beepcore.org
X-BeenThere: beepwg@lists.beepcore.org
X-Mailman-Version: 2.0.6
Precedence: bulk
List-Help: <mailto:beepwg-request@lists.beepcore.org?subject=help>
List-Post: <mailto:beepwg@lists.beepcore.org>
List-Subscribe: <http://lists.beepcore.org/mailman/listinfo/beepwg>,
	<mailto:beepwg-request@lists.beepcore.org?subject=subscribe>
List-Id: Mailing list for the IETF's BEEP working group <beepwg.lists.beepcore.org>
List-Unsubscribe: <http://lists.beepcore.org/mailman/listinfo/beepwg>,
	<mailto:beepwg-request@lists.beepcore.org?subject=unsubscribe>
List-Archive: <http://lists.beepcore.org/pipermail/beepwg/>
Date: Fri, 18 Oct 2002 13:58:32 -0700 (PDT)


On 16 Oct 2002, Jered Floyd wrote:

> At the end of section 4.1.3 of RFC 3080 (bottom of page 43), SASL's
> EXTERNAL mechanism is described.  It ends with:
>
>    if present, the authentication identity must be consistent with the
>    credentials provided by the external authentication service (if the
>    authentication identity is empty, then an authorization identity is
>    automatically derived from the credentials provided by the external
>    authentication service).
>
> In the parenthetical comment, is the word "authorization" meant to
> be "authentication"?  I believe this sentence is trying to state that
> if an authentication identity is provided via SASL EXTERNAL, it must
> match the external authentication identity, however if it is not
> present the authentication identity is taken from the external
> credentials.

Actually, I believe the paragraph in RFC 3080 should be written as:

   o  if present, the authorization identity must be consistent with
      the credentials provided by the external authentication service
      (if the authorization identity is empty, then an authorization
      identity is automatically derived from the credentials provided by
      the external authentication service).

(Sorry if I messed this up when I supplied that text, Marshall.)

RFC 2222 specifies that a SASL profile of a security mechanism should
provide the ability for the client to assert an "authorization identity",
which tells the server what identity the client would like to have used
for authorization purposes, regardless of any identity provided or implied
by the authentication mechanism.  Of course, the server should have policy
about which authenticated entities can assume which authorization
identities.  This SASL feature is best understood as supporting proxy or
3-tier authentication, where an intermediate service authenticates to a
backend service as itself, but says "please treat these requests as coming
from user <foo>".  But it can be used in other ways too.  So the above
paragraph is explaining what to do with the authorization identity, if
supplied, and what to do if not.

See section 3 of RFC 2829 for some general discussion of this.  There has
also been lots of discussion of the subtleties of authorization ids on the
ietf-sasl@imc.org list.  We're hoping that the revision to RFC 2222
(currently draft-myers-saslrev-02.txt) will clear up some common
questions about this.

 - RL "Bob"


_______________________________________________
BEEPwg mailing list
BEEPwg@lists.beepcore.org
http://lists.beepcore.org/mailman/listinfo/beepwg


From beepwg-admin@lists.beepcore.org  Wed Oct 23 22:43:52 2002
Received: from qawoor.dbc.mtview.ca.us (adsl-64-168-10-251.dsl.scrm01.pacbell.net [64.168.10.251])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA14574
	for <beep-archive@lists.ietf.org>; Wed, 23 Oct 2002 22:43:51 -0400 (EDT)
Received: from qawoor.dbc.mtview.ca.us (localhost [127.0.0.1])
	by qawoor.dbc.mtview.ca.us (8.11.3/8.11.5) with ESMTP id g9O2f8e17966;
	Wed, 23 Oct 2002 19:41:08 -0700 (PDT)
Received: from xomi.pair.com (xomi.pair.com [209.68.2.14])
	by qawoor.dbc.mtview.ca.us (8.11.3/8.11.5) with SMTP id g9O2ehe17954
	for <beepwg@lists.beepcore.org>; Wed, 23 Oct 2002 19:40:43 -0700 (PDT)
Received: (qmail 16106 invoked by uid 3039); 24 Oct 2002 02:44:51 -0000
Received: from localhost (sendmail-bs@127.0.0.1)
  by localhost with SMTP; 24 Oct 2002 02:44:51 -0000
From: Gabe Wachob <gwachob@wachob.com>
X-X-Sender: gwachob@xomi.pair.com
To: beepwg@lists.beepcore.org
Message-ID: <Pine.BSF.4.44.0210231944230.61222-100000@xomi.pair.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Subject: [BEEPwg] beepbuilders activity
Sender: beepwg-admin@lists.beepcore.org
Errors-To: beepwg-admin@lists.beepcore.org
X-BeenThere: beepwg@lists.beepcore.org
X-Mailman-Version: 2.0.6
Precedence: bulk
List-Help: <mailto:beepwg-request@lists.beepcore.org?subject=help>
List-Post: <mailto:beepwg@lists.beepcore.org>
List-Subscribe: <http://lists.beepcore.org/mailman/listinfo/beepwg>,
	<mailto:beepwg-request@lists.beepcore.org?subject=subscribe>
List-Id: Mailing list for the IETF's BEEP working group <beepwg.lists.beepcore.org>
List-Unsubscribe: <http://lists.beepcore.org/mailman/listinfo/beepwg>,
	<mailto:beepwg-request@lists.beepcore.org?subject=unsubscribe>
List-Archive: <http://lists.beepcore.org/pipermail/beepwg/>
Date: Wed, 23 Oct 2002 19:44:51 -0700 (PDT)

For those who aren't on the beepbuilders list, I've created a sourceforge
project for managing and publishing interoperability tests and test code
for beep library interoperability testing.

http://beepbuilders.sf.net

Please see
http://xml.resource.org/pipermail/beepbuilders/2002-October/000012.html
for more info.

Still looking for input on the best way to move forward in
interoperability testing.

        -Gabe


-- 
Gabe Wachob                       gwachob@wachob.com
Personal                       http://www.wachob.com
Founder, WiredObjects    http://www.wiredobjects.com

_______________________________________________
BEEPwg mailing list
BEEPwg@lists.beepcore.org
http://lists.beepcore.org/mailman/listinfo/beepwg


