From kaml-bounces@ietf.org Wed Aug 22 09:54:21 2007
Return-path: <kaml-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1INqf7-0004oB-Ju; Wed, 22 Aug 2007 09:54:21 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43) id 1INqf6-0004o4-5W
	for kaml@ietf.org; Wed, 22 Aug 2007 09:54:20 -0400
Received: from brmea-mail-2.sun.com ([192.18.98.43])
	by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1INqf5-0003yq-Rw
	for kaml@ietf.org; Wed, 22 Aug 2007 09:54:20 -0400
Received: from fe-amer-04.sun.com ([192.18.108.178])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id
	l7MDsJMi025672 for <kaml@ietf.org>; Wed, 22 Aug 2007 13:54:19 GMT
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
	(Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
	id <0JN600K01H4DG600@mail-amer.sun.com> (original mail from
	beuchelt@sun.com)
	for kaml@ietf.org; Wed, 22 Aug 2007 07:54:19 -0600 (MDT)
Received: from [192.168.0.16] ([209.150.59.40])
	by mail-amer.sun.com (Sun Java System Messaging Server 6.2-6.01 (built
	Apr 3 2006)) with ESMTPSA id <0JN600D18HAIEJA7@mail-amer.sun.com> for
	kaml@ietf.org; Wed, 22 Aug 2007 07:54:19 -0600 (MDT)
Date: Wed, 22 Aug 2007 09:54:05 -0400
From: Gerald Beuchelt <beuchelt@sun.com>
To: kaml@ietf.org
Message-id: <46CC3FFD.8090109@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
User-Agent: Thunderbird 2.0.0.6 (Windows/20070728)
X-Spam-Score: 2.5 (++)
X-Scan-Signature: 7aefe408d50e9c7c47615841cb314bed
Subject: [KAML] KAML
X-BeenThere: kaml@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussions about SAML and Kerberos intersections <kaml.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/kaml>
List-Post: <mailto:kaml@ietf.org>
List-Help: <mailto:kaml-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=subscribe>
Errors-To: kaml-bounces@ietf.org

Hi there -

Is there any initial draft or paper on what you are planning on doing?

Thanks,

Gerald

_______________________________________________
KAML mailing list
KAML@ietf.org
https://www1.ietf.org/mailman/listinfo/kaml



From kaml-bounces@ietf.org Wed Aug 22 13:03:26 2007
Return-path: <kaml-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1INtc6-00055p-Ke; Wed, 22 Aug 2007 13:03:26 -0400
Received: from [10.90.34.44] (helo=chiedprmail1.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43) id 1INtc6-00055k-4p
	for kaml@ietf.org; Wed, 22 Aug 2007 13:03:26 -0400
Received: from smtp3.su.se ([130.237.93.228])
	by chiedprmail1.ietf.org with esmtp (Exim 4.43) id 1INtc5-00064T-Qx
	for kaml@ietf.org; Wed, 22 Aug 2007 13:03:26 -0400
Received: from localhost (localhost [127.0.0.1])
	by smtp3.su.se (Postfix) with ESMTP id 8FE303BE6B;
	Wed, 22 Aug 2007 19:03:24 +0200 (CEST)
Received: from smtp3.su.se ([127.0.0.1])
	by localhost (smtp3.su.se [127.0.0.1]) (amavisd-new,
	port 10024) with LMTP
	id 03491-02-18; Wed, 22 Aug 2007 19:03:24 +0200 (CEST)
Received: from [10.0.0.11] (ua-83-227-179-169.cust.bredbandsbolaget.se
	[83.227.179.169])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by smtp3.su.se (Postfix) with ESMTP id F3D443BE5E;
	Wed, 22 Aug 2007 19:03:23 +0200 (CEST)
Message-ID: <46CC6C6F.1030908@it.su.se>
Date: Wed, 22 Aug 2007 19:03:43 +0200
From: Leif Johansson <leifj@it.su.se>
User-Agent: Thunderbird 1.5.0.12 (X11/20070604)
MIME-Version: 1.0
To: Gerald Beuchelt <beuchelt@sun.com>
Subject: Re: [KAML] KAML
References: <46CC3FFD.8090109@sun.com>
In-Reply-To: <46CC3FFD.8090109@sun.com>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: by amavisd-new at smtp.su.se
X-Spam-Status: No, hits=-2.267 tagged_above=-99 required=7 tests=[AWL=0.045,
	BAYES_00=-2.312]
X-Spam-Level: 
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 08170828343bcf1325e4a0fb4584481c
Cc: kaml@ietf.org
X-BeenThere: kaml@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussions about SAML and Kerberos intersections <kaml.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/kaml>
List-Post: <mailto:kaml@ietf.org>
List-Help: <mailto:kaml-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=subscribe>
Errors-To: kaml-bounces@ietf.org

Gerald Beuchelt wrote:
> Hi there -
>
> Is there any initial draft or paper on what you are planning on doing?
>
> Thanks,
>
> Gerald
>
>
My plan is to summarize the discussions from Chicago and elsewhere
first, then possibly talk about a draft describing the use-cases.

    Cheers Leif


_______________________________________________
KAML mailing list
KAML@ietf.org
https://www1.ietf.org/mailman/listinfo/kaml



From kaml-bounces@ietf.org Wed Aug 22 16:10:16 2007
Return-path: <kaml-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1INwWt-0001Fq-So; Wed, 22 Aug 2007 16:10:15 -0400
Received: from [10.90.34.44] (helo=chiedprmail1.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43) id 1INwWs-0001Fl-N2
	for kaml@ietf.org; Wed, 22 Aug 2007 16:10:14 -0400
Received: from smtp3.su.se ([130.237.93.228])
	by chiedprmail1.ietf.org with esmtp (Exim 4.43) id 1INwWr-00015X-Os
	for kaml@ietf.org; Wed, 22 Aug 2007 16:10:14 -0400
Received: from localhost (localhost [127.0.0.1])
	by smtp3.su.se (Postfix) with ESMTP id 786CD3BFC3
	for <kaml@ietf.org>; Wed, 22 Aug 2007 22:10:12 +0200 (CEST)
Received: from smtp3.su.se ([127.0.0.1])
	by localhost (smtp3.su.se [127.0.0.1]) (amavisd-new,
	port 10024) with LMTP id 15390-03-47 for <kaml@ietf.org>;
	Wed, 22 Aug 2007 22:10:12 +0200 (CEST)
Received: from [10.0.0.11] (ua-83-227-179-169.cust.bredbandsbolaget.se
	[83.227.179.169])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by smtp3.su.se (Postfix) with ESMTP id 05D5F3BF47
	for <kaml@ietf.org>; Wed, 22 Aug 2007 22:10:11 +0200 (CEST)
Message-ID: <46CC9837.5090305@it.su.se>
Date: Wed, 22 Aug 2007 22:10:31 +0200
From: Leif Johansson <leifj@it.su.se>
User-Agent: Thunderbird 1.5.0.12 (X11/20070604)
MIME-Version: 1.0
To: kaml@ietf.org
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: by amavisd-new at smtp.su.se
X-Spam-Status: No, hits=-2.268 tagged_above=-99 required=7 tests=[AWL=0.044,
	BAYES_00=-2.312]
X-Spam-Level: 
X-Spam-Score: -4.0 (----)
X-Scan-Signature: 3e15cc4fdc61d7bce84032741d11c8e5
Subject: [KAML] Chicago bar-BOF summary
X-BeenThere: kaml@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussions about SAML and Kerberos intersections <kaml.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/kaml>
List-Post: <mailto:kaml@ietf.org>
List-Help: <mailto:kaml-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=subscribe>
Errors-To: kaml-bounces@ietf.org


Hello and welcome to the kaml list. This list is the result of a bar-BOF
at the last IETF meeting in Chicago were a few SAMListas and well-
known members of the kerberos wg met and tried to come up with a
list of use-cases which might involve both SAML and kerberos.

Let me first say that we are clearly talking about several rather
loosely connected use-cases. This is probably not a complete
list of things we discussed in Chicago and I hope everyone will
contribute stuff of their own.

The use-cases:

1. Was a smart-card used?

This is my interpretation of problems posed by Douglas Engert
of ANL and Henry Hotz of Nasa.

The problem is to determine exactly how authentication was done
at a relying party, for instance if pkinit with a smart-card was used.
In general the RP may be at the end of a chain of (say) clients using
a gssapi-based protocol with credentials delegation, for instance a
SOAP-based service  sitting behind a web-application, both using
NTLM/Negotiate for authentication. In this case the RP has no way
to make decisions about how the initial authentication was done.

In SAML parlance this may be framed both in terms of the concept
of Level of Assurance and the SAML Authentication Context.

It seems clear that any analysis of this use-case would need to span
both Kerberos and GSS-API. In kitten there has been discussion
about how to represent authz-data. This would clearly be related.

2. The standarized PAC

An AD domain controller includes data about the groups a user is
a member of in the PA-DATA field of the KDC-REP. A generalization
of this concept might be to include a SAML authentication response
in the PA-DATA. This could be used together with anonymous
kerberos to control which identity information is made available
to the RP.

3. WebSSO kerberos n-tier.

A web-application using the SAML Web SSO profile needs a kerberos
ticket for accessing kerberized backend services. This kerberos ticket
needs to be produced by the Identity Provider and made available to
the Relying Party (or Service Provider).

Hope this is enough to get things started. I know the smart-card use-
case was discussed on the heimdal list (although possibly not in the
generality I presented above). Other use-cases have been discussed
on other lists.

       Cheers Leif

_______________________________________________
KAML mailing list
KAML@ietf.org
https://www1.ietf.org/mailman/listinfo/kaml



From kaml-bounces@ietf.org Fri Aug 24 07:00:12 2007
Return-path: <kaml-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1IOWtg-0000Sd-9J; Fri, 24 Aug 2007 07:00:12 -0400
Received: from [10.90.34.44] (helo=chiedprmail1.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43) id 1IOWtf-0000SN-G5
	for kaml@ietf.org; Fri, 24 Aug 2007 07:00:11 -0400
Received: from umhost1.ukerna.ac.uk ([193.62.83.67])
	by chiedprmail1.ietf.org with esmtp (Exim 4.43) id 1IOWte-0007kJ-VO
	for kaml@ietf.org; Fri, 24 Aug 2007 07:00:11 -0400
Received: from uxsrvr20.ukerna.ac.uk ([193.62.83.209]
	helo=uxsrvr20.atlas.ukerna.ac.uk)
	by umhost1.ukerna.ac.uk with esmtp (Exim 4.50)
	id 1IOWtY-0004LD-Lw; Fri, 24 Aug 2007 12:00:04 +0100
X-MimeOLE: Produced By Microsoft Exchange V6.5.7226.0
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Subject: RE: [KAML] Chicago bar-BOF summary
Date: Fri, 24 Aug 2007 11:59:56 +0100
Message-ID: <6ED388AA006C454BA35B0098396B9BFB028F5423@uxsrvr20.atlas.ukerna.ac.uk>
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
Thread-Topic: [KAML] Chicago bar-BOF summary
Thread-Index: Acfk+KQUdsMM3V+PROWEr5ye/tNYZwBQDVPQ
From: "Josh Howlett" <Josh.Howlett@ja.net>
To: "Leif Johansson" <leifj@it.su.se>,
	<kaml@ietf.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: e1e48a527f609d1be2bc8d8a70eb76cb
Cc: Josh Howlett <Josh.Howlett@ja.net>
X-BeenThere: kaml@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussions about SAML and Kerberos intersections <kaml.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/kaml>
List-Post: <mailto:kaml@ietf.org>
List-Help: <mailto:kaml-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=subscribe>
Errors-To: kaml-bounces@ietf.org

> The use-cases:
>=20
> 1. Was a smart-card used?

Just to clarify; is this use-case describing 1) "LoA" for Kerberos or 2)
extending SAML LoA to permit richer expressions?
=20
> 2. The standarized PAC
>=20
> An AD domain controller includes data about the groups a user=20
> is a member of in the PA-DATA field of the KDC-REP. A=20
> generalization of this concept might be to include a SAML=20
> authentication response in the PA-DATA.

...presumably this could be further generalised to allow assertions in
general, or even lower-level constructs such as an artifact (pointing to
an assertion)?

> Hope this is enough to get things started. I know the
> smart-card use- case was discussed on the heimdal=20
> list (although possibly not in the generality I=20
> presented above). Other use-cases have been discussed
> on other lists.

I'm curious whether we can use SAML, and the trust fabrics that are
realised through SAML federation metadata, to support some kind of
cross-realm Kerberos operation - perhaps using a SAML-based profile for
inter-KDC communication (following PKCROSS' example)?

The use-case would be a visitor requiring access to some local
Kerberos-protected network resource, but no local credentials.

However, such a profile might also provide a way to avoid using the Web
SSO Profile (in a browser context, obviously) and therefore side-step
the associated IdP "discovery problem". The browser could authenticate
using Negotiate (anonymously/pseudonymously) to the SP; authorisation
could subsequently be performed using the familiar SAML-based
mechanisms; perhaps boot-strapped through an artifact returned in the
PAC (which is used as the discovery 'cue').

best regards, josh.

_______________________________________________
KAML mailing list
KAML@ietf.org
https://www1.ietf.org/mailman/listinfo/kaml



From kaml-bounces@ietf.org Mon Aug 27 04:39:32 2007
Return-path: <kaml-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1IPa8C-0006xJ-4a; Mon, 27 Aug 2007 04:39:32 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43) id 1IPa8A-0006x8-Ix
	for kaml@ietf.org; Mon, 27 Aug 2007 04:39:30 -0400
Received: from smtp3.su.se ([130.237.93.228])
	by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1IPa88-0003KI-Ol
	for kaml@ietf.org; Mon, 27 Aug 2007 04:39:30 -0400
Received: from localhost (localhost [127.0.0.1])
	by smtp3.su.se (Postfix) with ESMTP id 9F3B53BF6D;
	Mon, 27 Aug 2007 10:39:23 +0200 (CEST)
Received: from smtp3.su.se ([127.0.0.1])
	by localhost (smtp3.su.se [127.0.0.1]) (amavisd-new,
	port 10024) with LMTP
	id 23927-01-20; Mon, 27 Aug 2007 10:39:23 +0200 (CEST)
Received: from [130.237.95.183] (dhcp-183.it.su.se [130.237.95.183])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by smtp3.su.se (Postfix) with ESMTP id 338A53BF04;
	Mon, 27 Aug 2007 10:39:23 +0200 (CEST)
Message-ID: <46D28DD1.5060809@it.su.se>
Date: Mon, 27 Aug 2007 10:39:45 +0200
From: Leif Johansson <leifj@it.su.se>
User-Agent: Thunderbird 1.5.0.13 (X11/20070824)
MIME-Version: 1.0
To: Josh Howlett <Josh.Howlett@ja.net>
Subject: Re: [KAML] Chicago bar-BOF summary
References: <6ED388AA006C454BA35B0098396B9BFB028F5423@uxsrvr20.atlas.ukerna.ac.uk>
In-Reply-To: <6ED388AA006C454BA35B0098396B9BFB028F5423@uxsrvr20.atlas.ukerna.ac.uk>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: by amavisd-new at smtp.su.se
X-Spam-Status: No, hits=-1.901 tagged_above=-99 required=7 tests=[AWL=0.411,
	BAYES_00=-2.312]
X-Spam-Level: 
X-Spam-Score: -4.0 (----)
X-Scan-Signature: e8a67952aa972b528dd04570d58ad8fe
Cc: kaml@ietf.org
X-BeenThere: kaml@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussions about SAML and Kerberos intersections <kaml.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/kaml>
List-Post: <mailto:kaml@ietf.org>
List-Help: <mailto:kaml-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=subscribe>
Errors-To: kaml-bounces@ietf.org

Josh Howlett wrote:
>> The use-cases:
>>
>> 1. Was a smart-card used?
>>     
>
> Just to clarify; is this use-case describing 1) "LoA" for Kerberos or 2)
> extending SAML LoA to permit richer expressions?
>   
If you're asking about expressing LoA as attributes or in the
SAML authentication context I guess it depends on who is
consuming the LoA.
>  
>   
>> 2. The standarized PAC
>>
>> An AD domain controller includes data about the groups a user 
>> is a member of in the PA-DATA field of the KDC-REP. A 
>> generalization of this concept might be to include a SAML 
>> authentication response in the PA-DATA.
>>     
>
> ...presumably this could be further generalised to allow assertions in
> general, or even lower-level constructs such as an artifact (pointing to
> an assertion)?
>   
That would be my hope too.
>   
>> Hope this is enough to get things started. I know the
>> smart-card use- case was discussed on the heimdal 
>> list (although possibly not in the generality I 
>> presented above). Other use-cases have been discussed
>> on other lists.
>>     
>
> I'm curious whether we can use SAML, and the trust fabrics that are
> realised through SAML federation metadata, to support some kind of
> cross-realm Kerberos operation - perhaps using a SAML-based profile for
> inter-KDC communication (following PKCROSS' example)?
>
> The use-case would be a visitor requiring access to some local
> Kerberos-protected network resource, but no local credentials.
>   
Did you read draft-sakane-krb-cross-problem-statement? It looks
like you may be describing something related to 5.6 (in version 03)
> However, such a profile might also provide a way to avoid using the Web
> SSO Profile (in a browser context, obviously) and therefore side-step
> the associated IdP "discovery problem". The browser could authenticate
> using Negotiate (anonymously/pseudonymously) to the SP; authorisation
> could subsequently be performed using the familiar SAML-based
> mechanisms; perhaps boot-strapped through an artifact returned in the
> PAC (which is used as the discovery 'cue').
>
> best regards, josh.
>   
I guess its not so much side-stepping IdP discovery as it is using
the IdP discovery which has already happened. When the user
logs into the workstation she typically has to pick a realm to
authenticate to which is a form of IdP discovery - the metadata
beeing the DNS SRV records pointing to the KDC.

    Cheers Leif


_______________________________________________
KAML mailing list
KAML@ietf.org
https://www1.ietf.org/mailman/listinfo/kaml



From kaml-bounces@ietf.org Wed Aug 29 03:23:26 2007
Return-path: <kaml-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1IQHte-0004WZ-B1; Wed, 29 Aug 2007 03:23:26 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43) id 1IQHtd-0004T0-9H
	for kaml@ietf.org; Wed, 29 Aug 2007 03:23:25 -0400
Received: from umhost1.ukerna.ac.uk ([193.62.83.67])
	by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1IQHta-0007Qp-VG
	for kaml@ietf.org; Wed, 29 Aug 2007 03:23:25 -0400
Received: from uxsrvr20.ukerna.ac.uk ([193.62.83.209]
	helo=uxsrvr20.atlas.ukerna.ac.uk)
	by umhost1.ukerna.ac.uk with esmtp (Exim 4.50)
	id 1IQHtZ-0005xU-T6; Wed, 29 Aug 2007 08:23:21 +0100
X-MimeOLE: Produced By Microsoft Exchange V6.5.7226.0
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Subject: RE: [KAML] Chicago bar-BOF summary
Date: Wed, 29 Aug 2007 08:22:35 +0100
Message-ID: <6ED388AA006C454BA35B0098396B9BFB028F553C@uxsrvr20.atlas.ukerna.ac.uk>
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
Thread-Topic: [KAML] Chicago bar-BOF summary
Thread-Index: Acfohj+lDOftCYMrRsqmJvAOv9WsngBgxwAg
From: "Josh Howlett" <Josh.Howlett@ja.net>
To: "Leif Johansson" <leifj@it.su.se>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: e1e48a527f609d1be2bc8d8a70eb76cb
Cc: Josh Howlett <Josh.Howlett@ja.net>, kaml@ietf.org
X-BeenThere: kaml@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussions about SAML and Kerberos intersections <kaml.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/kaml>
List-Post: <mailto:kaml@ietf.org>
List-Help: <mailto:kaml-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=subscribe>
Errors-To: kaml-bounces@ietf.org

Leif Johansson wrote:
> Josh Howlett wrote:
> > I'm curious whether we can use SAML, and the trust fabrics that are
> > realised through SAML federation metadata, to support some kind of
> > cross-realm Kerberos operation - perhaps using a SAML-based=20
> profile for
> > inter-KDC communication (following PKCROSS' example)?
> >
> > The use-case would be a visitor requiring access to some local
> > Kerberos-protected network resource, but no local credentials.
> >  =20
> Did you read draft-sakane-krb-cross-problem-statement? It looks
> like you may be describing something related to 5.6 (in version 03)

Not quite - I'm assuming that the user has contacted his KDC. A better
description is 5.3 'Scalability of the direct trust model'.

> > However, such a profile might also provide a way to avoid=20
> using the Web
> > SSO Profile (in a browser context, obviously) and therefore=20
> side-step
> > the associated IdP "discovery problem". The browser could=20
> authenticate
> > using Negotiate (anonymously/pseudonymously) to the SP;=20
> authorisation
> > could subsequently be performed using the familiar SAML-based
> > mechanisms; perhaps boot-strapped through an artifact=20
> returned in the
> > PAC (which is used as the discovery 'cue').
> >
> > best regards, josh.
> >  =20
> I guess its not so much side-stepping IdP discovery as it is using
> the IdP discovery which has already happened.

Yes, that's a better description.

FWIW, I think this is just a generalisation of the "WebSSO kerberos
n-tier problem" in a cross-realm context. Does that make sense? :-)

josh.

_______________________________________________
KAML mailing list
KAML@ietf.org
https://www1.ietf.org/mailman/listinfo/kaml



From kaml-bounces@ietf.org Wed Aug 29 14:40:46 2007
Return-path: <kaml-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1IQST6-0005wi-JW; Wed, 29 Aug 2007 14:40:44 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43) id 1IQST1-0005wU-SL
	for kaml@ietf.org; Wed, 29 Aug 2007 14:40:40 -0400
Received: from smtp1.su.se ([130.237.162.112])
	by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1IQST0-0001sf-DT
	for kaml@ietf.org; Wed, 29 Aug 2007 14:40:39 -0400
Received: from localhost (localhost [127.0.0.1])
	by smtp1.su.se (Postfix) with ESMTP id 7B5C97407D;
	Wed, 29 Aug 2007 20:40:37 +0200 (CEST)
Received: from smtp1.su.se ([127.0.0.1])
	by localhost (smtp1.su.se [127.0.0.1]) (amavisd-new,
	port 10024) with LMTP
	id 12861-02-44; Wed, 29 Aug 2007 20:40:37 +0200 (CEST)
Received: from [10.0.0.11] (ua-83-227-179-169.cust.bredbandsbolaget.se
	[83.227.179.169])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by smtp1.su.se (Postfix) with ESMTP id ECAFC74160;
	Wed, 29 Aug 2007 20:40:36 +0200 (CEST)
Message-ID: <46D5BDBB.8020202@it.su.se>
Date: Wed, 29 Aug 2007 20:40:59 +0200
From: Leif Johansson <leifj@it.su.se>
User-Agent: Thunderbird 1.5.0.13 (X11/20070824)
MIME-Version: 1.0
To: Josh Howlett <Josh.Howlett@ja.net>
Subject: Re: [KAML] Chicago bar-BOF summary
References: <6ED388AA006C454BA35B0098396B9BFB028F553C@uxsrvr20.atlas.ukerna.ac.uk>
In-Reply-To: <6ED388AA006C454BA35B0098396B9BFB028F553C@uxsrvr20.atlas.ukerna.ac.uk>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: by amavisd-new at smtp.su.se
X-Spam-Status: No, hits=-2.267 tagged_above=-99 required=7 tests=[AWL=0.045,
	BAYES_00=-2.312]
X-Spam-Level: 
X-Spam-Score: -4.0 (----)
X-Scan-Signature: d17f825e43c9aed4fd65b7edddddec89
Cc: kaml@ietf.org
X-BeenThere: kaml@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussions about SAML and Kerberos intersections <kaml.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/kaml>
List-Post: <mailto:kaml@ietf.org>
List-Help: <mailto:kaml-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=subscribe>
Errors-To: kaml-bounces@ietf.org


> Yes, that's a better description.
>
> FWIW, I think this is just a generalisation of the "WebSSO kerberos
> n-tier problem" in a cross-realm context. Does that make sense? :-)
>
> josh.
>   
To me it does but then again that may not be a good sign ;-)

    Cheers Leif

_______________________________________________
KAML mailing list
KAML@ietf.org
https://www1.ietf.org/mailman/listinfo/kaml



From kaml-bounces@ietf.org Wed Aug 29 14:44:28 2007
Return-path: <kaml-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1IQSWi-0004FT-J5; Wed, 29 Aug 2007 14:44:28 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43) id 1IQSWe-0004FI-D6
	for kaml@ietf.org; Wed, 29 Aug 2007 14:44:24 -0400
Received: from smtp3.su.se ([130.237.93.228])
	by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1IQSWc-0001xI-VL
	for kaml@ietf.org; Wed, 29 Aug 2007 14:44:24 -0400
Received: from localhost (localhost [127.0.0.1])
	by smtp3.su.se (Postfix) with ESMTP id 0E3503BEE7
	for <kaml@ietf.org>; Wed, 29 Aug 2007 20:44:22 +0200 (CEST)
Received: from smtp3.su.se ([127.0.0.1])
	by localhost (smtp3.su.se [127.0.0.1]) (amavisd-new,
	port 10024) with LMTP id 19365-01-33 for <kaml@ietf.org>;
	Wed, 29 Aug 2007 20:44:21 +0200 (CEST)
Received: from [10.0.0.11] (ua-83-227-179-169.cust.bredbandsbolaget.se
	[83.227.179.169])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by smtp3.su.se (Postfix) with ESMTP id C1A323BE9C
	for <kaml@ietf.org>; Wed, 29 Aug 2007 20:44:21 +0200 (CEST)
Message-ID: <46D5BE9C.7000302@it.su.se>
Date: Wed, 29 Aug 2007 20:44:44 +0200
From: Leif Johansson <leifj@it.su.se>
User-Agent: Thunderbird 1.5.0.13 (X11/20070824)
MIME-Version: 1.0
To: kaml@ietf.org
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: by amavisd-new at smtp.su.se
X-Spam-Status: No, hits=-2.269 tagged_above=-99 required=7 tests=[AWL=0.043,
	BAYES_00=-2.312]
X-Spam-Level: 
X-Spam-Score: -4.0 (----)
X-Scan-Signature: 2870a44b67ee17965ce5ad0177e150f4
Subject: [KAML] more uc?
X-BeenThere: kaml@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussions about SAML and Kerberos intersections <kaml.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/kaml>
List-Post: <mailto:kaml@ietf.org>
List-Help: <mailto:kaml-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/kaml>,
	<mailto:kaml-request@ietf.org?subject=subscribe>
Errors-To: kaml-bounces@ietf.org


Surely my list wasn't complete!

    Cheers Leif

_______________________________________________
KAML mailing list
KAML@ietf.org
https://www1.ietf.org/mailman/listinfo/kaml



