
From scott.c.fitch@lmco.com  Sat Dec  3 18:21:17 2011
Return-Path: <scott.c.fitch@lmco.com>
X-Original-To: plasma@ietfa.amsl.com
Delivered-To: plasma@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A6C901F0C35 for <plasma@ietfa.amsl.com>; Sat,  3 Dec 2011 18:21:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.72
X-Spam-Level: 
X-Spam-Status: No, score=-6.72 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FRT_ROLEX=3.878, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6X2iQJgzXS3E for <plasma@ietfa.amsl.com>; Sat,  3 Dec 2011 18:21:14 -0800 (PST)
Received: from mailfo02.lmco.com (mailfo02.lmco.com [192.35.35.12]) by ietfa.amsl.com (Postfix) with ESMTP id DF8F221F8D10 for <plasma@ietf.org>; Sat,  3 Dec 2011 18:21:13 -0800 (PST)
Received: from emss07g01.ems.lmco.com ([166.29.2.16]) by mailfo02.lmco.com (8.14.3/8.14.3) with ESMTP id pB42L8De002656; Sun, 4 Dec 2011 02:21:08 GMT
Received: from CONVERSION2-DAEMON.lmco.com by lmco.com (PMDF V6.4 #31805) id <0LVN00601QJ5S5@lmco.com>; Sun, 04 Dec 2011 02:21:05 +0000 (GMT)
Received: from HDXHTPN6.us.lmco.com ([158.188.83.13]) by lmco.com (PMDF V6.4 #31805) with ESMTP id <0LVN002NJQJ0M1@lmco.com>; Sun, 04 Dec 2011 02:21:00 +0000 (GMT)
Received: from HDXDSP11.us.lmco.com ([fe80::c04a:c222:3486:3e3]) by HDXHTPN6.us.lmco.com ([fe80::1db3:a00c:a3c9:9df6%14]) with mapi id 14.01.0355.002; Sat, 03 Dec 2011 19:21:00 -0700
Date: Sun, 04 Dec 2011 02:20:58 +0000
From: "Fitch, Scott C" <scott.c.fitch@lmco.com>
In-reply-to: <E545B914D50B2A4B994F198378B1525D42750872@DF-M14-11.exchange.corp.microsoft.com>
X-Originating-IP: [158.188.95.10]
To: Trevor Freeman <trevorf@exchange.microsoft.com>, "plasma@ietf.org" <plasma@ietf.org>
Message-id: <DFE85D7EFA640D4886E9A9141AEBCD2010DAA7CF@HDXDSP11.us.lmco.com>
MIME-version: 1.0
Content-type: multipart/alternative; boundary="Boundary_(ID_uhqKlULc896n1TmotPYXCw)"
Content-language: en-US
Thread-Topic: Delegation scenario
Thread-Index: AcyTPvJuZ6lTqdglQi+54J/v8g5UNQCWpMtQByQ9/MA=
Accept-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
References: <DFE85D7EFA640D4886E9A9141AEBCD200A097B8A@HDXDSP11.us.lmco.com> <E545B914D50B2A4B994F198378B1525D42750872@DF-M14-11.exchange.corp.microsoft.com>
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.5.7110, 1.0.211, 0.0.0000 definitions=2011-12-04_01:2011-12-02, 2011-12-04, 1970-01-01 signatures=0
Subject: Re: [plasma] Delegation scenario
X-BeenThere: plasma@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "The PoLicy Augmented S/Mime \(plasma\) bof discussion list." <plasma.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/plasma>, <mailto:plasma-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/plasma>
List-Post: <mailto:plasma@ietf.org>
List-Help: <mailto:plasma-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/plasma>, <mailto:plasma-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Dec 2011 02:21:17 -0000

--Boundary_(ID_uhqKlULc896n1TmotPYXCw)
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT

Trevor, et al-
                Sorry it took me so long to reply on this. Anyway, I can see two scenarios, and two ways that a Plasma implementation could met the requirements.

The first delegation scenario is a persistent delegation such as between a Boss and an Administrative assistant. In this case, the Admin gets to read (most of) the Boss's email.

The second scenario is temporary delegation, such as assigning a role to an individual while on vacation. In this case, the delegate only has access to the messages while the delegator is on vacation.

As for ways the Plasma addresses this, it can either be done through the access rules (e.g., Boss's assigned Administrative Assistant is allowed to read company proprietary information, but not personal information) or through the assertions provided to the PDP at access request (e.g., Delegate has Role X, which meets the criteria for reading the message).

In both cases, these approaches are greatly preferable to PKI-based S/MIME, which usually involves sharing private keys, removing all granularity for access.

Let me know if that's enough to go on.

                -Scott

Scott Fitch
Cyber Architect
scott.c.fitch@lmco.com

From: Trevor Freeman [mailto:trevorf@exchange.microsoft.com]
Sent: Friday, October 28, 2011 1:48 PM
To: Fitch, Scott C; plasma@ietf.org
Subject: EXTERNAL: RE: Delegation scenario

That is a good observation. If you give a brief outline on how you see a scenario changing for delegation and I will incorporate that into the next version.

From: plasma-bounces@ietf.org<mailto:plasma-bounces@ietf.org> [mailto:plasma-bounces@ietf.org]<mailto:[mailto:plasma-bounces@ietf.org]> On Behalf Of Fitch, Scott C
Sent: Tuesday, October 25, 2011 10:57 AM
To: plasma@ietf.org<mailto:plasma@ietf.org>
Subject: [plasma] Delegation scenario

Plasma also opens up the opportunity to support delegation in a much more sustainable and elegant manner than current PKI-based S/MIME. I'd like to see that called out as a scenario in Section 3. Others have similar thoughts?

                -Scott

--Boundary_(ID_uhqKlULc896n1TmotPYXCw)
Content-type: text/html; charset=us-ascii
Content-transfer-encoding: 7BIT

<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Cambria;
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.EmailStyle17
	{mso-style-type:personal;
	font-family:"Cambria","serif";
	color:windowtext;}
span.EmailStyle18
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#4F6228;
	font-weight:bold;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.EmailStyle21
	{mso-style-type:personal-reply;
	font-family:"Cambria","serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D">Trevor, et al-<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Sorry it took me so long to reply on this. Anyway, I can see two scenarios, and two ways that a Plasma implementation could met the requirements.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D">The first delegation scenario is a persistent delegation such as between a Boss and an Administrative assistant. In this case, the Admin gets to read (most of) the Boss&#8217;s email.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D">The second scenario is temporary delegation, such as assigning a role to an individual while on vacation. In this case, the delegate only has access to the messages while the delegator
 is on vacation.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D">As for ways the Plasma addresses this, it can either be done through the access rules (e.g., Boss&#8217;s assigned Administrative Assistant is allowed to read company proprietary information,
 but not personal information) or through the assertions provided to the PDP at access request (e.g., Delegate has Role X, which meets the criteria for reading the message).<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D">In both cases, these approaches are greatly preferable to PKI-based S/MIME, which usually involves sharing private keys, removing all granularity for access.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D">Let me know if that&#8217;s enough to go on.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -Scott<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<div>
<p class="MsoNormal"><span style="font-size:9.0pt;color:#1F497D">Scott Fitch<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;color:#1F497D">Cyber Architect<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;color:#1F497D">scott.c.fitch@lmco.com<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> Trevor Freeman [mailto:trevorf@exchange.microsoft.com]
<br>
<b>Sent:</b> Friday, October 28, 2011 1:48 PM<br>
<b>To:</b> Fitch, Scott C; plasma@ietf.org<br>
<b>Subject:</b> EXTERNAL: RE: Delegation scenario<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><b><span style="color:#4F6228">That is a good observation. If you give a brief outline on how you see a scenario changing for delegation and I will incorporate that into the next version.
<o:p></o:p></span></b></p>
<p class="MsoNormal"><b><span style="color:#4F6228"><o:p>&nbsp;</o:p></span></b></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">
<a href="mailto:plasma-bounces@ietf.org">plasma-bounces@ietf.org</a> <a href="mailto:[mailto:plasma-bounces@ietf.org]">
[mailto:plasma-bounces@ietf.org]</a> <b>On Behalf Of </b>Fitch, Scott C<br>
<b>Sent:</b> Tuesday, October 25, 2011 10:57 AM<br>
<b>To:</b> <a href="mailto:plasma@ietf.org">plasma@ietf.org</a><br>
<b>Subject:</b> [plasma] Delegation scenario<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;">Plasma also opens up the opportunity to support delegation in a much more sustainable and elegant manner than current PKI-based S/MIME. I&#8217;d like to see that called out as a scenario in Section
 3. Others have similar thoughts?<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-family:&quot;Cambria&quot;,&quot;serif&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -Scott<o:p></o:p></span></p>
</div>
</body>
</html>

--Boundary_(ID_uhqKlULc896n1TmotPYXCw)--

From Richard.Skedd@baesystems.com  Tue Dec  6 05:56:08 2011
Return-Path: <Richard.Skedd@baesystems.com>
X-Original-To: plasma@ietfa.amsl.com
Delivered-To: plasma@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8110A21F8B3F for <plasma@ietfa.amsl.com>; Tue,  6 Dec 2011 05:56:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.48
X-Spam-Level: 
X-Spam-Status: No, score=0.48 tagged_above=-999 required=5 tests=[BAYES_50=0.001, FRT_ROLEX=3.878, HTML_MESSAGE=0.001, J_CHICKENPOX_21=0.6, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7TPsFmH0v5lp for <plasma@ietfa.amsl.com>; Tue,  6 Dec 2011 05:56:05 -0800 (PST)
Received: from ukmta3.baesystems.com (ukmta3.baesystems.com [20.133.40.55]) by ietfa.amsl.com (Postfix) with ESMTP id 8706B21F8B3D for <plasma@ietf.org>; Tue,  6 Dec 2011 05:56:04 -0800 (PST)
X-IronPort-AV: E=Sophos;i="4.71,306,1320624000";  d="scan'208,217";a="174797255"
Received: from unknown (HELO baemasodc004.greenlnk.net) ([10.108.36.11]) by Baemasodc001ir.sharelnk.net with ESMTP; 06 Dec 2011 13:56:03 +0000
Received: from glkms1102.GREENLNK.NET (glkms1102.greenlnk.net [10.108.36.193]) by baemasodc004.greenlnk.net (Switch-3.4.4/Switch-3.4.4) with ESMTP id pB6Du26M015812; Tue, 6 Dec 2011 13:56:03 GMT
Received: from GLKMS2105.GREENLNK.NET ([10.15.184.96]) by glkms1102.GREENLNK.NET with Microsoft SMTPSVC(6.0.3790.4675);  Tue, 6 Dec 2011 13:56:02 +0000
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01CCB41E.CA6893E4"
X-MimeOLE: Produced By Microsoft Exchange V6.5
Date: Tue, 6 Dec 2011 13:56:02 -0000
Message-ID: <CB55784F96DEBE4B972015A2587A1DA002D2DA2B@GLKMS2105.GREENLNK.NET>
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
Thread-Topic: Delegation scenario
thread-index: AcyTPvJuZ6lTqdglQi+54J/v8g5UNQCWpMtQByQ9/MAAe836IA==
From: "Skedd, Richard (UK)" <Richard.Skedd@baesystems.com>
To: "Fitch, Scott C" <scott.c.fitch@lmco.com>, "Trevor Freeman" <trevorf@exchange.microsoft.com>, <plasma@ietf.org>
X-OriginalArrivalTime: 06 Dec 2011 13:56:02.0804 (UTC) FILETIME=[CA9A7340:01CCB41E]
Subject: Re: [plasma] Delegation scenario
X-BeenThere: plasma@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "The PoLicy Augmented S/Mime \(plasma\) bof discussion list." <plasma.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/plasma>, <mailto:plasma-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/plasma>
List-Post: <mailto:plasma@ietf.org>
List-Help: <mailto:plasma-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/plasma>, <mailto:plasma-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Dec 2011 13:56:08 -0000

------_=_NextPart_001_01CCB41E.CA6893E4
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit

Plasma certainly provides an opportunity to take an approach that would
be preferable to that which we end up doing today.  A few thoughts to
add to Scott's:

 

Although we typically describe this as a delegation scenario, I would
describe it as one case of a shared mailbox scenario.  There are a
number of these but I don't think that the relationships between the
members of the team using the shared mailbox are important for plasma.
This could equally apply to members of a design team, a family or a
medical practice.  Messages will arrive in the mailbox.  Access to an
individual message is dependent upon the sensitivity of the message and
the privileges of the user accessing the mailbox.  Privileges are
assigned for a period which may itself be dependent on certain
conditions.

 

There are many examples:

 

-       Executive - has an assistant that is authorised for company
proprietary whilst she holds her position but not personal 

-       Manager - has a colleague that is authorised for project x
information whilst the worker is on vacation but not project y

-       Engineer - is one of five on the team that are authorised for
proprietary information from company a whilst they hold their positions
but not company b

-       Father - has two daughters that are authorised for notices about
school events whilst they are students at the school but not an
appointment with a doctor

-       Doctor - has a number of nurses that are authorised for messages
about the doctor's patients whilst they are on duty and assigned to work
with the doctor but not practice management information 

 

The impact of this capability on how we choose to establish and manage
e-mail addresses is another thread of discussion ...

 

Regards

 

Richard Skedd

Strategy Manager - Office of the CIO

T:    +44 117 918 8034 (vnet 7658 8034)

M:    +44 780 171 8260 (vnet 777118260)

 

BAE Systems plc

Registered Office: 6 Carlton Gardens, London, SW1Y 5AD, UK

Registered in England & Wales No: 1470151

 

From: plasma-bounces@ietf.org [mailto:plasma-bounces@ietf.org] On Behalf
Of Fitch, Scott C
Sent: 04 December 2011 02:21
To: Trevor Freeman; plasma@ietf.org
Subject: Re: [plasma] Delegation scenario

 

                    *** WARNING ***

  This message has originated outside your organisation,
  either from an external partner or the Global Internet. 
      Keep this in mind if you answer this message.

Trevor, et al-

                Sorry it took me so long to reply on this. Anyway, I can
see two scenarios, and two ways that a Plasma implementation could met
the requirements.

 

The first delegation scenario is a persistent delegation such as between
a Boss and an Administrative assistant. In this case, the Admin gets to
read (most of) the Boss's email.

 

The second scenario is temporary delegation, such as assigning a role to
an individual while on vacation. In this case, the delegate only has
access to the messages while the delegator is on vacation.

 

As for ways the Plasma addresses this, it can either be done through the
access rules (e.g., Boss's assigned Administrative Assistant is allowed
to read company proprietary information, but not personal information)
or through the assertions provided to the PDP at access request (e.g.,
Delegate has Role X, which meets the criteria for reading the message).

 

In both cases, these approaches are greatly preferable to PKI-based
S/MIME, which usually involves sharing private keys, removing all
granularity for access.

 

Let me know if that's enough to go on.

 

                -Scott

 

Scott Fitch

Cyber Architect

scott.c.fitch@lmco.com

 

From: Trevor Freeman [mailto:trevorf@exchange.microsoft.com] 
Sent: Friday, October 28, 2011 1:48 PM
To: Fitch, Scott C; plasma@ietf.org
Subject: EXTERNAL: RE: Delegation scenario

 

That is a good observation. If you give a brief outline on how you see a
scenario changing for delegation and I will incorporate that into the
next version. 

 

From: plasma-bounces@ietf.org [mailto:plasma-bounces@ietf.org] On Behalf
Of Fitch, Scott C
Sent: Tuesday, October 25, 2011 10:57 AM
To: plasma@ietf.org
Subject: [plasma] Delegation scenario

 

Plasma also opens up the opportunity to support delegation in a much
more sustainable and elegant manner than current PKI-based S/MIME. I'd
like to see that called out as a scenario in Section 3. Others have
similar thoughts?

 

                -Scott


********************************************************************
This email and any attachments are confidential to the intended
recipient and may also be privileged. If you are not the intended
recipient please delete it from your system and notify the sender.
You should not copy it or use it for any purpose nor disclose or
distribute its contents to any other person.
********************************************************************


------_=_NextPart_001_01CCB41E.CA6893E4
Content-Type: text/html; charset=US-ASCII
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40"><head><meta http-equiv=3DContent-Type content=
=3D"text/html; charset=3Dus-ascii"><meta name=3DGenerator content=3D"Micros=
oft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
=09{font-family:Wingdings;
=09panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
=09{font-family:Wingdings;
=09panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
=09{font-family:Cambria;
=09panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
=09{font-family:Calibri;
=09panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
=09{font-family:Tahoma;
=09panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
=09{margin:0cm;
=09margin-bottom:.0001pt;
=09font-size:11.0pt;
=09font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
=09{mso-style-priority:99;
=09color:blue;
=09text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
=09{mso-style-priority:99;
=09color:purple;
=09text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
=09{mso-style-priority:99;
=09mso-style-link:"Balloon Text Char";
=09margin:0cm;
=09margin-bottom:.0001pt;
=09font-size:8.0pt;
=09font-family:"Tahoma","sans-serif";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
=09{mso-style-priority:34;
=09margin-top:0cm;
=09margin-right:0cm;
=09margin-bottom:0cm;
=09margin-left:36.0pt;
=09margin-bottom:.0001pt;
=09font-size:11.0pt;
=09font-family:"Calibri","sans-serif";}
span.BalloonTextChar
=09{mso-style-name:"Balloon Text Char";
=09mso-style-priority:99;
=09mso-style-link:"Balloon Text";
=09font-family:"Tahoma","sans-serif";}
span.EmailStyle19
=09{mso-style-type:personal;
=09font-family:"Cambria","serif";
=09color:windowtext;}
span.EmailStyle20
=09{mso-style-type:personal;
=09font-family:"Calibri","sans-serif";
=09color:#4F6228;
=09font-weight:bold;}
span.EmailStyle21
=09{mso-style-type:personal;
=09font-family:"Cambria","serif";
=09color:#1F497D;}
span.EmailStyle22
=09{mso-style-type:personal-reply;
=09font-family:"Arial","sans-serif";
=09color:#1F497D;}
.MsoChpDefault
=09{mso-style-type:export-only;
=09font-size:10.0pt;}
@page WordSection1
=09{size:612.0pt 792.0pt;
=09margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
=09{page:WordSection1;}
/* List Definitions */
@list l0
=09{mso-list-id:1570648520;
=09mso-list-type:hybrid;
=09mso-list-template-ids:934963446 1492142344 134807555 134807557 134807553=
 134807555 134807557 134807553 134807555 134807557;}
@list l0:level1
=09{mso-level-start-at:0;
=09mso-level-number-format:bullet;
=09mso-level-text:-;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:"Arial","sans-serif";
=09mso-fareast-font-family:Calibri;}
@list l0:level2
=09{mso-level-number-format:bullet;
=09mso-level-text:o;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:"Courier New";}
@list l0:level3
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Wingdings;}
@list l0:level4
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Symbol;}
@list l0:level5
=09{mso-level-number-format:bullet;
=09mso-level-text:o;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:"Courier New";}
@list l0:level6
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Wingdings;}
@list l0:level7
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Symbol;}
@list l0:level8
=09{mso-level-number-format:bullet;
=09mso-level-text:o;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:"Courier New";}
@list l0:level9
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Wingdings;}
@list l1
=09{mso-list-id:1649507227;
=09mso-list-type:hybrid;
=09mso-list-template-ids:-1745321878 -2060054338 134807555 134807557 134807=
553 134807555 134807557 134807553 134807555 134807557;}
@list l1:level1
=09{mso-level-start-at:0;
=09mso-level-number-format:bullet;
=09mso-level-text:-;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:"Arial","sans-serif";
=09mso-fareast-font-family:Calibri;}
@list l1:level2
=09{mso-level-number-format:bullet;
=09mso-level-text:o;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:"Courier New";}
@list l1:level3
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Wingdings;}
@list l1:level4
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Symbol;}
@list l1:level5
=09{mso-level-number-format:bullet;
=09mso-level-text:o;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:"Courier New";}
@list l1:level6
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Wingdings;}
@list l1:level7
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Symbol;}
@list l1:level8
=09{mso-level-number-format:bullet;
=09mso-level-text:o;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:"Courier New";}
@list l1:level9
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Wingdings;}
@list l2
=09{mso-list-id:1826820063;
=09mso-list-type:hybrid;
=09mso-list-template-ids:-716960182 1653499528 134807555 134807557 13480755=
3 134807555 134807557 134807553 134807555 134807557;}
@list l2:level1
=09{mso-level-start-at:0;
=09mso-level-number-format:bullet;
=09mso-level-text:-;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:"Arial","sans-serif";
=09mso-fareast-font-family:Calibri;}
@list l2:level2
=09{mso-level-number-format:bullet;
=09mso-level-text:o;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:"Courier New";}
@list l2:level3
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Wingdings;}
@list l2:level4
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Symbol;}
@list l2:level5
=09{mso-level-number-format:bullet;
=09mso-level-text:o;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:"Courier New";}
@list l2:level6
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Wingdings;}
@list l2:level7
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0B7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Symbol;}
@list l2:level8
=09{mso-level-number-format:bullet;
=09mso-level-text:o;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:"Courier New";}
@list l2:level9
=09{mso-level-number-format:bullet;
=09mso-level-text:\F0A7;
=09mso-level-tab-stop:none;
=09mso-level-number-position:left;
=09text-indent:-18.0pt;
=09font-family:Wingdings;}
ol
=09{margin-bottom:0cm;}
ul
=09{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-GB link=3Dblue vli=
nk=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span style=3D'f=
ont-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'>Plasma cert=
ainly provides an opportunity to take an approach that would be preferable =
to that which we end up doing today.&nbsp; A few thoughts to add to Scott&#=
8217;s:<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:=
10.0pt;font-family:"Arial","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></s=
pan></p><p class=3DMsoNormal><span style=3D'font-size:10.0pt;font-family:"A=
rial","sans-serif";color:#1F497D'>Although we typically describe this as a =
delegation scenario, I would describe it as one case of a shared mailbox sc=
enario.&nbsp; There are a number of these but I don&#8217;t think that the =
relationships between the members of the team using the shared mailbox are =
important for plasma.&nbsp; This could equally apply to members of a design=
 team, a family or a medical practice.&nbsp; Messages will arrive in the ma=
ilbox.&nbsp; Access to an individual message is dependent upon the sensitiv=
ity of the message and the privileges of the user accessing the mailbox.&nb=
sp; Privileges are assigned for a period which may itself be dependent on c=
ertain conditions.<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D=
'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'><o:p>&nbs=
p;</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:10.0pt;fon=
t-family:"Arial","sans-serif";color:#1F497D'>There are many examples:<o:p><=
/o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:10.0pt;font-f=
amily:"Arial","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p cl=
ass=3DMsoListParagraph style=3D'text-indent:-18.0pt;mso-list:l1 level1 lfo3=
'><![if !supportLists]><span style=3D'font-size:10.0pt;font-family:"Arial",=
"sans-serif";color:#1F497D'><span style=3D'mso-list:Ignore'>-<span style=3D=
'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>=
</span></span><![endif]><span style=3D'font-size:10.0pt;font-family:"Arial"=
,"sans-serif";color:#1F497D'>Executive &#8211; has an assistant that is aut=
horised for company proprietary whilst she holds her position but not perso=
nal <o:p></o:p></span></p><p class=3DMsoListParagraph style=3D'text-indent:=
-18.0pt;mso-list:l1 level1 lfo3'><![if !supportLists]><span style=3D'font-s=
ize:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'><span style=3D'm=
so-list:Ignore'>-<span style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><![endif]><span style=3D'font-=
size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'>Manager &#8211;=
 has a colleague that is authorised for project x information whilst the wo=
rker is on vacation but not project y<o:p></o:p></span></p><p class=3DMsoLi=
stParagraph style=3D'text-indent:-18.0pt;mso-list:l1 level1 lfo3'><![if !su=
pportLists]><span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif=
";color:#1F497D'><span style=3D'mso-list:Ignore'>-<span style=3D'font:7.0pt=
 "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></sp=
an><![endif]><span style=3D'font-size:10.0pt;font-family:"Arial","sans-seri=
f";color:#1F497D'>Engineer &#8211; is one of five on the team that are auth=
orised for proprietary information from company a whilst they hold their po=
sitions but not company b<o:p></o:p></span></p><p class=3DMsoListParagraph =
style=3D'text-indent:-18.0pt;mso-list:l1 level1 lfo3'><![if !supportLists]>=
<span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F4=
97D'><span style=3D'mso-list:Ignore'>-<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><![endif]=
><span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F=
497D'>Father &#8211; has two daughters that are authorised for notices abou=
t school events whilst they are students at the school but not an appointme=
nt with a doctor<o:p></o:p></span></p><p class=3DMsoListParagraph style=3D'=
text-indent:-18.0pt;mso-list:l1 level1 lfo3'><![if !supportLists]><span sty=
le=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'><spa=
n style=3D'mso-list:Ignore'>-<span style=3D'font:7.0pt "Times New Roman"'>&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span></span><![endif]><span st=
yle=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'>Doc=
tor &#8211; has a number of nurses that are authorised for messages about t=
he doctor&#8217;s patients whilst they are on duty and assigned to work wit=
h the doctor but not practice management information <o:p></o:p></span></p>=
<p class=3DMsoNormal><span style=3D'font-size:10.0pt;font-family:"Arial","s=
ans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal>=
<span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F4=
97D'>The impact of this capability on how we choose to establish and manage=
 e-mail addresses is another thread of discussion &#8230;<o:p></o:p></span>=
</p><p class=3DMsoNormal><span style=3D'font-size:10.0pt;font-family:"Arial=
","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><div><p class=3DM=
soNormal><span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";c=
olor:#1F497D'>Regards<o:p></o:p></span></p><p class=3DMsoNormal><span style=
=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'><o:p>&=
nbsp;</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:10.0pt;=
font-family:"Arial","sans-serif";color:#1F497D'>Richard Skedd<o:p></o:p></s=
pan></p><p class=3DMsoNormal><span style=3D'font-size:10.0pt;font-family:"A=
rial","sans-serif";color:#1F497D'>Strategy Manager - Office of the CIO<o:p>=
</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:10.0pt;font-=
family:"Arial","sans-serif";color:#1F497D'>T:&nbsp;&nbsp;&nbsp; +44 117 918=
 8034 (vnet 7658 8034)<o:p></o:p></span></p><p class=3DMsoNormal><span styl=
e=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'>M:&nb=
sp;&nbsp;&nbsp; +44 780 171 8260 (vnet 777118260)<o:p></o:p></span></p><p c=
lass=3DMsoNormal><span style=3D'font-size:10.0pt;font-family:"Arial","sans-=
serif";color:#1F497D'>&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal><spa=
n style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>BAE Systems plc<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'f=
ont-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'>Registered =
Office: 6 Carlton Gardens, London, SW1Y 5AD, UK<o:p></o:p></span></p><p cla=
ss=3DMsoNormal><span style=3D'font-size:10.0pt;font-family:"Arial","sans-se=
rif";color:#1F497D'>Registered in England &amp; Wales No: 1470151</span><sp=
an style=3D'font-family:"Arial","sans-serif";color:#1F497D'><o:p></o:p></sp=
an></p></div><p class=3DMsoNormal><span style=3D'font-size:10.0pt;font-fami=
ly:"Arial","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><div><di=
v style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm=
 0cm'><p class=3DMsoNormal><b><span lang=3DEN-US style=3D'font-size:10.0pt;=
font-family:"Tahoma","sans-serif"'>From:</span></b><span lang=3DEN-US style=
=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> plasma-bounces@iet=
f.org [mailto:plasma-bounces@ietf.org] <b>On Behalf Of </b>Fitch, Scott C<b=
r><b>Sent:</b> 04 December 2011 02:21<br><b>To:</b> Trevor Freeman; plasma@=
ietf.org<br><b>Subject:</b> Re: [plasma] Delegation scenario<o:p></o:p></sp=
an></p></div></div><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMso=
Normal><span lang=3DEN-US style=3D'font-size:12.0pt;font-family:"Courier Ne=
w"'>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; *=
** WARNING ***<br><br>&nbsp; This message has originated outside your organ=
isation,<br>&nbsp; either from an external partner or the Global Internet. =
<br>&nbsp; &nbsp; &nbsp; Keep this in mind if you answer this message.</spa=
n><span lang=3DEN-US style=3D'font-size:12.0pt;font-family:"Times New Roman=
","serif"'><o:p></o:p></span></p><p class=3DMsoNormal><span lang=3DEN-US st=
yle=3D'font-family:"Cambria","serif";color:#1F497D'>Trevor, et al-<o:p></o:=
p></span></p><p class=3DMsoNormal><span lang=3DEN-US style=3D'font-family:"=
Cambria","serif";color:#1F497D'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Sorry it took me so long to=
 reply on this. Anyway, I can see two scenarios, and two ways that a Plasma=
 implementation could met the requirements.<o:p></o:p></span></p><p class=
=3DMsoNormal><span lang=3DEN-US style=3D'font-family:"Cambria","serif";colo=
r:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span lang=3DEN=
-US style=3D'font-family:"Cambria","serif";color:#1F497D'>The first delegat=
ion scenario is a persistent delegation such as between a Boss and an Admin=
istrative assistant. In this case, the Admin gets to read (most of) the Bos=
s&#8217;s email.<o:p></o:p></span></p><p class=3DMsoNormal><span lang=3DEN-=
US style=3D'font-family:"Cambria","serif";color:#1F497D'><o:p>&nbsp;</o:p><=
/span></p><p class=3DMsoNormal><span lang=3DEN-US style=3D'font-family:"Cam=
bria","serif";color:#1F497D'>The second scenario is temporary delegation, s=
uch as assigning a role to an individual while on vacation. In this case, t=
he delegate only has access to the messages while the delegator is on vacat=
ion.<o:p></o:p></span></p><p class=3DMsoNormal><span lang=3DEN-US style=3D'=
font-family:"Cambria","serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p=
 class=3DMsoNormal><span lang=3DEN-US style=3D'font-family:"Cambria","serif=
";color:#1F497D'>As for ways the Plasma addresses this, it can either be do=
ne through the access rules (e.g., Boss&#8217;s assigned Administrative Ass=
istant is allowed to read company proprietary information, but not personal=
 information) or through the assertions provided to the PDP at access reque=
st (e.g., Delegate has Role X, which meets the criteria for reading the mes=
sage).<o:p></o:p></span></p><p class=3DMsoNormal><span lang=3DEN-US style=
=3D'font-family:"Cambria","serif";color:#1F497D'><o:p>&nbsp;</o:p></span></=
p><p class=3DMsoNormal><span lang=3DEN-US style=3D'font-family:"Cambria","s=
erif";color:#1F497D'>In both cases, these approaches are greatly preferable=
 to PKI-based S/MIME, which usually involves sharing private keys, removing=
 all granularity for access.<o:p></o:p></span></p><p class=3DMsoNormal><spa=
n lang=3DEN-US style=3D'font-family:"Cambria","serif";color:#1F497D'><o:p>&=
nbsp;</o:p></span></p><p class=3DMsoNormal><span lang=3DEN-US style=3D'font=
-family:"Cambria","serif";color:#1F497D'>Let me know if that&#8217;s enough=
 to go on.<o:p></o:p></span></p><p class=3DMsoNormal><span lang=3DEN-US sty=
le=3D'font-family:"Cambria","serif";color:#1F497D'><o:p>&nbsp;</o:p></span>=
</p><p class=3DMsoNormal><span lang=3DEN-US style=3D'font-family:"Cambria",=
"serif";color:#1F497D'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -Scott<o:p></o:p></span></p><p class=
=3DMsoNormal><span lang=3DEN-US style=3D'font-family:"Cambria","serif";colo=
r:#1F497D'><o:p>&nbsp;</o:p></span></p><div><p class=3DMsoNormal><span lang=
=3DEN-US style=3D'font-size:9.0pt;color:#1F497D'>Scott Fitch<o:p></o:p></sp=
an></p><p class=3DMsoNormal><span lang=3DEN-US style=3D'font-size:9.0pt;col=
or:#1F497D'>Cyber Architect<o:p></o:p></span></p><p class=3DMsoNormal><span=
 lang=3DEN-US style=3D'font-size:9.0pt;color:#1F497D'><a href=3D"mailto:sco=
tt.c.fitch@lmco.com">scott.c.fitch@lmco.com</a><o:p></o:p></span></p></div>=
<p class=3DMsoNormal><span lang=3DEN-US style=3D'font-family:"Cambria","ser=
if";color:#1F497D'><o:p>&nbsp;</o:p></span></p><div><div style=3D'border:no=
ne;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm'><p class=3DMso=
Normal><b><span lang=3DEN-US style=3D'font-size:10.0pt;font-family:"Tahoma"=
,"sans-serif"'>From:</span></b><span lang=3DEN-US style=3D'font-size:10.0pt=
;font-family:"Tahoma","sans-serif"'> Trevor Freeman [mailto:trevorf@exchang=
e.microsoft.com] <br><b>Sent:</b> Friday, October 28, 2011 1:48 PM<br><b>To=
:</b> Fitch, Scott C; plasma@ietf.org<br><b>Subject:</b> EXTERNAL: RE: Dele=
gation scenario<o:p></o:p></span></p></div></div><p class=3DMsoNormal><span=
 lang=3DEN-US><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><b><span lan=
g=3DEN-US style=3D'color:#4F6228'>That is a good observation. If you give a=
 brief outline on how you see a scenario changing for delegation and I will=
 incorporate that into the next version. <o:p></o:p></span></b></p><p class=
=3DMsoNormal><b><span lang=3DEN-US style=3D'color:#4F6228'><o:p>&nbsp;</o:p=
></span></b></p><div><div style=3D'border:none;border-top:solid #B5C4DF 1.0=
pt;padding:3.0pt 0cm 0cm 0cm'><p class=3DMsoNormal><b><span lang=3DEN-US st=
yle=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b>=
<span lang=3DEN-US style=3D'font-size:10.0pt;font-family:"Tahoma","sans-ser=
if"'> <a href=3D"mailto:plasma-bounces@ietf.org">plasma-bounces@ietf.org</a=
> <a href=3D"mailto:[mailto:plasma-bounces@ietf.org]">[mailto:plasma-bounce=
s@ietf.org]</a> <b>On Behalf Of </b>Fitch, Scott C<br><b>Sent:</b> Tuesday,=
 October 25, 2011 10:57 AM<br><b>To:</b> <a href=3D"mailto:plasma@ietf.org"=
>plasma@ietf.org</a><br><b>Subject:</b> [plasma] Delegation scenario<o:p></=
o:p></span></p></div></div><p class=3DMsoNormal><span lang=3DEN-US><o:p>&nb=
sp;</o:p></span></p><p class=3DMsoNormal><span lang=3DEN-US style=3D'font-f=
amily:"Cambria","serif"'>Plasma also opens up the opportunity to support de=
legation in a much more sustainable and elegant manner than current PKI-bas=
ed S/MIME. I&#8217;d like to see that called out as a scenario in Section 3=
. Others have similar thoughts?<o:p></o:p></span></p><p class=3DMsoNormal><=
span lang=3DEN-US style=3D'font-family:"Cambria","serif"'><o:p>&nbsp;</o:p>=
</span></p><p class=3DMsoNormal><span lang=3DEN-US style=3D'font-family:"Ca=
mbria","serif"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -Scott<o:p></o:p></span></p></div> <br>
********************************************************************<br>
This email and any attachments are confidential to the intended<br>
recipient and may also be privileged. If you are not the intended<br>
recipient please delete it from your system and notify the sender.<br>
You should not copy it or use it for any purpose nor disclose or<br>
distribute its contents to any other person.<br>
********************************************************************<br>
<br>
</body></html>
------_=_NextPart_001_01CCB41E.CA6893E4--

From jimsch@nwlink.com  Tue Dec  6 18:51:18 2011
Return-Path: <jimsch@nwlink.com>
X-Original-To: plasma@ietfa.amsl.com
Delivered-To: plasma@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BC68721F8BBE for <plasma@ietfa.amsl.com>; Tue,  6 Dec 2011 18:51:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level: 
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 83Egl6N8xyzI for <plasma@ietfa.amsl.com>; Tue,  6 Dec 2011 18:51:18 -0800 (PST)
Received: from smtp3.pacifier.net (smtp3.pacifier.net [64.255.237.177]) by ietfa.amsl.com (Postfix) with ESMTP id 45D2821F8BBB for <plasma@ietf.org>; Tue,  6 Dec 2011 18:51:18 -0800 (PST)
Received: from Tobias (exodus.augustcellars.com [207.202.179.27]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: jimsch@nwlink.com) by smtp3.pacifier.net (Postfix) with ESMTPSA id A778B38EA6; Tue,  6 Dec 2011 18:50:34 -0800 (PST)
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Fitch, Scott C'" <scott.c.fitch@lmco.com>, <plasma@ietf.org>
References: <DFE85D7EFA640D4886E9A9141AEBCD200A097C08@HDXDSP11.us.lmco.com>
In-Reply-To: <DFE85D7EFA640D4886E9A9141AEBCD200A097C08@HDXDSP11.us.lmco.com>
Date: Tue, 6 Dec 2011 18:50:00 -0800
Message-ID: <000101ccb48b$06819070$1384b150$@nwlink.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQG7xHPKDhsfd7m54voQYQhsijmmXpXxeaAg
Content-Language: en-us
Subject: Re: [plasma] S/MIME Capabilities
X-BeenThere: plasma@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "The PoLicy Augmented S/Mime \(plasma\) bof discussion list." <plasma.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/plasma>, <mailto:plasma-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/plasma>
List-Post: <mailto:plasma@ietf.org>
List-Help: <mailto:plasma-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/plasma>, <mailto:plasma-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Dec 2011 02:51:18 -0000

Just to be clear, you are suggesting that an attribute defined by which a
sender says "I understand Plasma" just like there is one which says I
understand inner binary.  Recipients could then store this attribute as part
of the senders capabilities.  

This is totally trivial and yes we should do it.  I assume that this would
just be a "binary" value - I do or do not support it.  If a new version of
Plasma ever comes into existence then a new attribute with a different OID
value would be created.  There is no need to talk about algorithms or
advance vs basic here.

Jim


> -----Original Message-----
> From: plasma-bounces@ietf.org [mailto:plasma-bounces@ietf.org] On
> Behalf Of Fitch, Scott C
> Sent: Tuesday, October 25, 2011 12:00 PM
> To: plasma@ietf.org
> Subject: [plasma] S/MIME Capabilities
> 
> Section 5.2.1 notes the backwards compatibility requirement with existing
> S/MIME where a sender can create recipient info structures for recipients
it
> can discover keys for.
> 
> Should there be an equivalent mechanism to indicate a sender's support for
> plasma, similar to the way that S/MIME indicates current capabilities?
This
> could be helpful, particularly when sending messages with Advanced
Policies.
> 
> 	-Scott
> _______________________________________________
> plasma mailing list
> plasma@ietf.org
> https://www.ietf.org/mailman/listinfo/plasma



From scott.c.fitch@lmco.com  Wed Dec  7 05:31:49 2011
Return-Path: <scott.c.fitch@lmco.com>
X-Original-To: plasma@ietfa.amsl.com
Delivered-To: plasma@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AB13221F8B11 for <plasma@ietfa.amsl.com>; Wed,  7 Dec 2011 05:31:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -8.659
X-Spam-Level: 
X-Spam-Status: No, score=-8.659 tagged_above=-999 required=5 tests=[AWL=1.940,  BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tCRhMBelltdK for <plasma@ietfa.amsl.com>; Wed,  7 Dec 2011 05:31:49 -0800 (PST)
Received: from mailfo02.lmco.com (mailfo02.lmco.com [192.35.35.12]) by ietfa.amsl.com (Postfix) with ESMTP id 1431821F8B02 for <plasma@ietf.org>; Wed,  7 Dec 2011 05:31:48 -0800 (PST)
Received: from emss07g01.ems.lmco.com ([166.29.2.16]) by mailfo02.lmco.com (8.14.3/8.14.3) with ESMTP id pB7DVlZS009346; Wed, 7 Dec 2011 13:31:47 GMT
Received: from CONVERSION2-DAEMON.lmco.com by lmco.com (PMDF V6.4 #31805) id <0LVU00H015KWIV@lmco.com>; Wed, 07 Dec 2011 13:31:44 +0000 (GMT)
Received: from HDXHTPN7.us.lmco.com ([158.188.83.14]) by lmco.com (PMDF V6.4 #31805) with ESMTP id <0LVU00H1Q5KR4F@lmco.com>; Wed, 07 Dec 2011 13:31:39 +0000 (GMT)
Received: from HDXDSP11.us.lmco.com ([fe80::c04a:c222:3486:3e3]) by HDXHTPN7.us.lmco.com ([fe80::f1:ff4b:90a4:695%14]) with mapi id 14.01.0355.002; Wed, 07 Dec 2011 06:31:39 -0700
Date: Wed, 07 Dec 2011 13:31:38 +0000
From: "Fitch, Scott C" <scott.c.fitch@lmco.com>
In-reply-to: <000101ccb48b$06819070$1384b150$@nwlink.com>
X-Originating-IP: [158.188.95.10]
To: Jim Schaad <jimsch@nwlink.com>, "plasma@ietf.org" <plasma@ietf.org>
Message-id: <DFE85D7EFA640D4886E9A9141AEBCD2010DAD680@HDXDSP11.us.lmco.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-language: en-US
Content-transfer-encoding: 7BIT
Thread-Topic: EXTERNAL: RE: [plasma] S/MIME Capabilities
Thread-Index: AcyTR93+zP+wCizmT46LHSpiVqxaJghfbe0AAAe1A/A=
Accept-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
References: <DFE85D7EFA640D4886E9A9141AEBCD200A097C08@HDXDSP11.us.lmco.com> <000101ccb48b$06819070$1384b150$@nwlink.com>
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.5.7110, 1.0.211, 0.0.0000 definitions=2011-12-07_05:2011-12-07, 2011-12-07, 1970-01-01 signatures=0
Subject: Re: [plasma] EXTERNAL: RE:  S/MIME Capabilities
X-BeenThere: plasma@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "The PoLicy Augmented S/Mime \(plasma\) bof discussion list." <plasma.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/plasma>, <mailto:plasma-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/plasma>
List-Post: <mailto:plasma@ietf.org>
List-Help: <mailto:plasma-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/plasma>, <mailto:plasma-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Dec 2011 13:31:49 -0000

Exactly. That will help us operate in the hybrid (No S/MIME, PKI S/MIME, Plasma) world we're destined to be in for a long time.

Scott Fitch
Cyber Architect
scott.c.fitch@lmco.com

-----Original Message-----
From: Jim Schaad [mailto:jimsch@nwlink.com] 
Sent: Tuesday, December 06, 2011 9:50 PM
To: Fitch, Scott C; plasma@ietf.org
Subject: EXTERNAL: RE: [plasma] S/MIME Capabilities

Just to be clear, you are suggesting that an attribute defined by which a sender says "I understand Plasma" just like there is one which says I understand inner binary.  Recipients could then store this attribute as part of the senders capabilities.  

This is totally trivial and yes we should do it.  I assume that this would just be a "binary" value - I do or do not support it.  If a new version of Plasma ever comes into existence then a new attribute with a different OID value would be created.  There is no need to talk about algorithms or advance vs basic here.

Jim


> -----Original Message-----
> From: plasma-bounces@ietf.org [mailto:plasma-bounces@ietf.org] On 
> Behalf Of Fitch, Scott C
> Sent: Tuesday, October 25, 2011 12:00 PM
> To: plasma@ietf.org
> Subject: [plasma] S/MIME Capabilities
> 
> Section 5.2.1 notes the backwards compatibility requirement with 
> existing S/MIME where a sender can create recipient info structures 
> for recipients
it
> can discover keys for.
> 
> Should there be an equivalent mechanism to indicate a sender's support 
> for plasma, similar to the way that S/MIME indicates current capabilities?
This
> could be helpful, particularly when sending messages with Advanced
Policies.
> 
> 	-Scott
> _______________________________________________
> plasma mailing list
> plasma@ietf.org
> https://www.ietf.org/mailman/listinfo/plasma



From jimsch@nwlink.com  Thu Dec  8 14:07:59 2011
Return-Path: <jimsch@nwlink.com>
X-Original-To: plasma@ietfa.amsl.com
Delivered-To: plasma@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 02BAF21F8ADE for <plasma@ietfa.amsl.com>; Thu,  8 Dec 2011 14:07:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level: 
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UnCRIMGx8EBv for <plasma@ietfa.amsl.com>; Thu,  8 Dec 2011 14:07:58 -0800 (PST)
Received: from smtp4.pacifier.net (smtp4.pacifier.net [64.255.237.176]) by ietfa.amsl.com (Postfix) with ESMTP id 0AE3621F8AF5 for <plasma@ietf.org>; Thu,  8 Dec 2011 14:07:58 -0800 (PST)
Received: from Tobias (exodus.augustcellars.com [207.202.179.27]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: jimsch@nwlink.com) by smtp4.pacifier.net (Postfix) with ESMTPSA id A91F738E6A for <plasma@ietf.org>; Thu,  8 Dec 2011 14:07:57 -0800 (PST)
From: "Jim Schaad" <jimsch@nwlink.com>
To: <plasma@ietf.org>
Date: Thu, 8 Dec 2011 14:07:27 -0800
Message-ID: <004401ccb5f5$c679d570$536d8050$@nwlink.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: Acy18pICuzH8Oic9Q1CxM894eCe30w==
Content-Language: en-us
Subject: [plasma] Where is the PEP?
X-BeenThere: plasma@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "The PoLicy Augmented S/Mime \(plasma\) bof discussion list." <plasma.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/plasma>, <mailto:plasma-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/plasma>
List-Post: <mailto:plasma@ietf.org>
List-Help: <mailto:plasma-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/plasma>, <mailto:plasma-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Dec 2011 22:07:59 -0000

At the last IETF meeting, Trevor and I got together to try and hammer out
the skeleton of what the XML protocols would look like for the plasma work.
During this process we found that the WS-Trust work did not appear to have a
good way of returning error information for such items as "missing
attribute".  However the XACML documents did have this type of structure and
are designed for working between the PEP and PDP so they seemed to be a good
place to base some of the work from.

In the process of doing this, one of the things that was going to be highly
desired was to be able to carry a SAML Assertion as part of the request from
the PEP to the PDP.  I found the follow document "SAML 2.0 Profile of XACML,
v2.0"
http://docs.oasis-open.org/xacml/3.0/xacml-profile-saml2.0-v2-spec-cs-01-en.
pdf which game a "simple" method of mapping the attributes of a SAML
statement onto a XACML request.  The expectation is that this would be done
by the PEP (or some entity between the PEP and the PDP) that is highly
trusted as it does the mapping and validates the signatures on the SAML
assertion.  

This expectation of trust does not map well onto the current Plasma mode and
got me thinking about the question of where the PEP and PDP boundaries
really lie.  I think there may be some level of confusion in the future that
we should at least consider today.  The problem as I see it is that there
are two different things that access is being granted to and this is not
explicitly spelled out in the model.

Access is being granted to the E-Mail message: This is where we are thinking
of the PEP as living today.  That is we are trying to get access to the
e-mail message.

Access is being granted to the KEK:  This is where the real PEP/PDP are
living.  In this case the PEP is not a fully trusted entity and does not
actually grant or deny access to the KEK value.  For our purposes the PEP to
get access to the KEK value is actually living with (or near) the PDP and is
the plasma server itself.  This is the think that gets a grant statement and
then send the resource back to the e-mail client's PDP.  

The dichotomy is of issue mostly in terms of how trusted the PEP is and
therefore what things can be done.  The issue in this case is what level of
trust can we place in the entity we are calling the PEP (none) and therefore
what level of validation of attributes needs to be setup for the items that
would normally be placed in the XACML Attribute structures.  The PEP would
normally be permitted to assert that an attribute was correct.  In our case
this is not a true statement.  This will affect how we look at using both
XACML and SAML.  I.e. we probably don't want to use the mapping specified
above, but we may want to look at creating a new way to place an entire SAML
Assertion in an XACML Attribute and leave the PDP to re-distribute it
around.

Comments?

Jim



From trevorf@exchange.microsoft.com  Mon Dec 12 15:13:46 2011
Return-Path: <trevorf@exchange.microsoft.com>
X-Original-To: plasma@ietfa.amsl.com
Delivered-To: plasma@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E2D221F84FB for <plasma@ietfa.amsl.com>; Mon, 12 Dec 2011 15:13:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -110.599
X-Spam-Level: 
X-Spam-Status: No, score=-110.599 tagged_above=-999 required=5 tests=[AWL=-0.000, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-8, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3bLfB8A3DHDh for <plasma@ietfa.amsl.com>; Mon, 12 Dec 2011 15:13:43 -0800 (PST)
Received: from mail.exchange.microsoft.com (mail1.exchange.microsoft.com [131.107.1.17]) by ietfa.amsl.com (Postfix) with ESMTP id DE2A221F84E5 for <plasma@ietf.org>; Mon, 12 Dec 2011 15:13:42 -0800 (PST)
Received: from df-h14-02.exchange.corp.microsoft.com (157.54.78.140) by DF-G14-01.exchange.corp.microsoft.com (157.54.87.87) with Microsoft SMTP Server (TLS) id 14.3.5.0; Mon, 12 Dec 2011 15:13:42 -0800
Received: from PIO-MLT-05.exchange.corp.microsoft.com (157.54.94.22) by DF-H14-02.exchange.corp.microsoft.com (157.54.78.140) with Microsoft SMTP Server (TLS) id 14.3.5.1; Mon, 12 Dec 2011 15:13:42 -0800
Received: from DF-M14-12.exchange.corp.microsoft.com ([fe80::7c94:4036:120:c95f]) by PIO-MLT-05.exchange.corp.microsoft.com ([fe80::d940:e316:1daa:5e6a%10]) with mapi id 14.03.0005.000; Mon, 12 Dec 2011 15:13:41 -0800
From: Trevor Freeman <trevorf@exchange.microsoft.com>
To: Jim Schaad <jimsch@nwlink.com>, "plasma@ietf.org" <plasma@ietf.org>
Thread-Topic: [plasma] Where is the PEP?
Thread-Index: Acy18pICuzH8Oic9Q1CxM894eCe30wDLOwlg
Date: Mon, 12 Dec 2011 23:13:41 +0000
Message-ID: <E545B914D50B2A4B994F198378B1525D42882443@DF-M14-12.exchange.corp.microsoft.com>
References: <004401ccb5f5$c679d570$536d8050$@nwlink.com>
In-Reply-To: <004401ccb5f5$c679d570$536d8050$@nwlink.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [157.54.51.104]
Content-Type: multipart/alternative; boundary="_000_E545B914D50B2A4B994F198378B1525D42882443DFM1412exchange_"
MIME-Version: 1.0
Subject: Re: [plasma] Where is the PEP?
X-BeenThere: plasma@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "The PoLicy Augmented S/Mime \(plasma\) bof discussion list." <plasma.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/plasma>, <mailto:plasma-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/plasma>
List-Post: <mailto:plasma@ietf.org>
List-Help: <mailto:plasma-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/plasma>, <mailto:plasma-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 12 Dec 2011 23:13:46 -0000

--_000_E545B914D50B2A4B994F198378B1525D42882443DFM1412exchange_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi Jim,



Here is my take.



There does not seem consensus over the exact role of a PEP, and maybe that =
is by design.



If you look at XACML v3 core it cites rfc3189 as a normative reference. Bot=
h XACML and 3198 define the PEP role yet the definitions are not completely=
 aligned. 3198 defies a PEP as:-



Policy enforcement:  The execution of a policy decision.

Policy Enforcement Point (PEP): A logical entity that enforces policy decis=
ions (See also "policy enforcement")



You can merge the two statements to be more concise i.e. A PEP is a logical=
 entity responsible for the execution of policy decisions. This s a fairly =
general purpose, any policy model.



XACML is more restrictive. It defines PEP as:-



The system entity that performs access control by making decision requests =
and enforcing authorization decisions.



This is very much an access control policy model definition. It also implie=
s a trust model.





The policy decision requested by both the Plasma and XACML PEP is "can the =
client\user access the specified message/data".



In order to execute the permitted decision in a Plasma PEP, we need both th=
e encrypted data and the decryption key. This is distinct from an XACML PEP=
 which has access to the clear text data and can simply relase the data. Th=
e critical difference between the two is the trust model. In Plasma we do n=
ot unconditionally trust the PEP with the clear txt data; plasma performs a=
n access check first, and then releases the clear text data to the PEP. XAC=
ML trusts the PEP with all clear text data regardless of any access check.



The decision request is the same for both PEPs, but the execution of the de=
cision is different because of the different trust models.



Trevor





-----Original Message-----
From: plasma-bounces@ietf.org [mailto:plasma-bounces@ietf.org] On Behalf Of=
 Jim Schaad
Sent: Thursday, December 08, 2011 2:07 PM
To: plasma@ietf.org
Subject: [plasma] Where is the PEP?



At the last IETF meeting, Trevor and I got together to try and hammer out t=
he skeleton of what the XML protocols would look like for the plasma work.

During this process we found that the WS-Trust work did not appear to have =
a good way of returning error information for such items as "missing attrib=
ute".  However the XACML documents did have this type of structure and are =
designed for working between the PEP and PDP so they seemed to be a good pl=
ace to base some of the work from.



In the process of doing this, one of the things that was going to be highly=
 desired was to be able to carry a SAML Assertion as part of the request fr=
om the PEP to the PDP.  I found the follow document "SAML 2.0 Profile of XA=
CML, v2.0"

http://docs.oasis-open.org/xacml/3.0/xacml-profile-saml2.0-v2-spec-cs-01-en=
.

pdf which game a "simple" method of mapping the attributes of a SAML statem=
ent onto a XACML request.  The expectation is that this would be done by th=
e PEP (or some entity between the PEP and the PDP) that is highly trusted a=
s it does the mapping and validates the signatures on the SAML assertion.



This expectation of trust does not map well onto the current Plasma mode an=
d got me thinking about the question of where the PEP and PDP boundaries re=
ally lie.  I think there may be some level of confusion in the future that =
we should at least consider today.  The problem as I see it is that there a=
re two different things that access is being granted to and this is not exp=
licitly spelled out in the model.



Access is being granted to the E-Mail message: This is where we are thinkin=
g of the PEP as living today.  That is we are trying to get access to the e=
-mail message.



Access is being granted to the KEK:  This is where the real PEP/PDP are liv=
ing.  In this case the PEP is not a fully trusted entity and does not actua=
lly grant or deny access to the KEK value.  For our purposes the PEP to get=
 access to the KEK value is actually living with (or near) the PDP and is t=
he plasma server itself.  This is the think that gets a grant statement and=
 then send the resource back to the e-mail client's PDP.



The dichotomy is of issue mostly in terms of how trusted the PEP is and the=
refore what things can be done.  The issue in this case is what level of tr=
ust can we place in the entity we are calling the PEP (none) and therefore =
what level of validation of attributes needs to be setup for the items that=
 would normally be placed in the XACML Attribute structures.  The PEP would=
 normally be permitted to assert that an attribute was correct.  In our cas=
e this is not a true statement.  This will affect how we look at using both=
 XACML and SAML.  I.e. we probably don't want to use the mapping specified =
above, but we may want to look at creating a new way to place an entire SAM=
L Assertion in an XACML Attribute and leave the PDP to re-distribute it aro=
und.



Comments?



Jim





_______________________________________________

plasma mailing list

plasma@ietf.org<mailto:plasma@ietf.org>

https://www.ietf.org/mailman/listinfo/plasma

--_000_E545B914D50B2A4B994F198378B1525D42882443DFM1412exchange_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"ProgId" content=3D"Word.Document">
<meta name=3D"Generator" content=3D"Microsoft Word 14">
<meta name=3D"Originator" content=3D"Microsoft Word 14">
<link rel=3D"File-List" href=3D"cid:filelist.xml@01CCB8E0.A11E14B0"><!--[if=
 gte mso 9]><xml>
<o:OfficeDocumentSettings>
<o:AllowPNG/>
</o:OfficeDocumentSettings>
</xml><![endif]--><!--[if gte mso 9]><xml>
<w:WordDocument>
<w:SpellingState>Clean</w:SpellingState>
<w:GrammarState>Clean</w:GrammarState>
<w:TrackMoves/>
<w:TrackFormatting/>
<w:EnvelopeVis/>
<w:PunctuationKerning/>
<w:ValidateAgainstSchemas/>
<w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
<w:IgnoreMixedContent>false</w:IgnoreMixedContent>
<w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
<w:DoNotPromoteQF/>
<w:LidThemeOther>EN-US</w:LidThemeOther>
<w:LidThemeAsian>X-NONE</w:LidThemeAsian>
<w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript>
<w:Compatibility>
<w:BreakWrappedTables/>
<w:SnapToGridInCell/>
<w:WrapTextWithPunct/>
<w:UseAsianBreakRules/>
<w:DontGrowAutofit/>
<w:SplitPgBreakAndParaMark/>
<w:EnableOpenTypeKerning/>
<w:DontFlipMirrorIndents/>
<w:OverrideTableStyleHps/>
</w:Compatibility>
<m:mathPr>
<m:mathFont m:val=3D"Cambria Math"/>
<m:brkBin m:val=3D"before"/>
<m:brkBinSub m:val=3D"&#45;-"/>
<m:smallFrac m:val=3D"off"/>
<m:dispDef/>
<m:lMargin m:val=3D"0"/>
<m:rMargin m:val=3D"0"/>
<m:defJc m:val=3D"centerGroup"/>
<m:wrapIndent m:val=3D"1440"/>
<m:intLim m:val=3D"subSup"/>
<m:naryLim m:val=3D"undOvr"/>
</m:mathPr></w:WordDocument>
</xml><![endif]--><!--[if gte mso 9]><xml>
<w:LatentStyles DefLockedState=3D"false" DefUnhideWhenUsed=3D"true" DefSemi=
Hidden=3D"true" DefQFormat=3D"false" DefPriority=3D"99" LatentStyleCount=3D=
"267">
<w:LsdException Locked=3D"false" Priority=3D"0" SemiHidden=3D"false" Unhide=
WhenUsed=3D"false" QFormat=3D"true" Name=3D"Normal"/>
<w:LsdException Locked=3D"false" Priority=3D"9" SemiHidden=3D"false" Unhide=
WhenUsed=3D"false" QFormat=3D"true" Name=3D"heading 1"/>
<w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"he=
ading 2"/>
<w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"he=
ading 3"/>
<w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"he=
ading 4"/>
<w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"he=
ading 5"/>
<w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"he=
ading 6"/>
<w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"he=
ading 7"/>
<w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"he=
ading 8"/>
<w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"he=
ading 9"/>
<w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 1"/>
<w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 2"/>
<w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 3"/>
<w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 4"/>
<w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 5"/>
<w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 6"/>
<w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 7"/>
<w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 8"/>
<w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 9"/>
<w:LsdException Locked=3D"false" Priority=3D"35" QFormat=3D"true" Name=3D"c=
aption"/>
<w:LsdException Locked=3D"false" Priority=3D"10" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" QFormat=3D"true" Name=3D"Title"/>
<w:LsdException Locked=3D"false" Priority=3D"1" Name=3D"Default Paragraph F=
ont"/>
<w:LsdException Locked=3D"false" Priority=3D"11" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" QFormat=3D"true" Name=3D"Subtitle"/>
<w:LsdException Locked=3D"false" Priority=3D"22" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" QFormat=3D"true" Name=3D"Strong"/>
<w:LsdException Locked=3D"false" Priority=3D"20" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" QFormat=3D"true" Name=3D"Emphasis"/>
<w:LsdException Locked=3D"false" Priority=3D"59" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Table Grid"/>
<w:LsdException Locked=3D"false" UnhideWhenUsed=3D"false" Name=3D"Placehold=
er Text"/>
<w:LsdException Locked=3D"false" Priority=3D"1" SemiHidden=3D"false" Unhide=
WhenUsed=3D"false" QFormat=3D"true" Name=3D"No Spacing"/>
<w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Shading"/>
<w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light List"/>
<w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Grid"/>
<w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 1"/>
<w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 2"/>
<w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 1"/>
<w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 2"/>
<w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 1"/>
<w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 2"/>
<w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 3"/>
<w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Dark List"/>
<w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Shading"/>
<w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful List"/>
<w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Grid"/>
<w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Shading Accent 1"/>
<w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light List Accent 1"/>
<w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Grid Accent 1"/>
<w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 1 Accent 1"/>
<w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 2 Accent 1"/>
<w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 1 Accent 1"/>
<w:LsdException Locked=3D"false" UnhideWhenUsed=3D"false" Name=3D"Revision"=
/>
<w:LsdException Locked=3D"false" Priority=3D"34" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" QFormat=3D"true" Name=3D"List Paragraph"/>
<w:LsdException Locked=3D"false" Priority=3D"29" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" QFormat=3D"true" Name=3D"Quote"/>
<w:LsdException Locked=3D"false" Priority=3D"30" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" QFormat=3D"true" Name=3D"Intense Quote"/>
<w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 2 Accent 1"/>
<w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 1 Accent 1"/>
<w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 2 Accent 1"/>
<w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 3 Accent 1"/>
<w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Dark List Accent 1"/>
<w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Shading Accent 1"/>
<w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful List Accent 1"/>
<w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Grid Accent 1"/>
<w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Shading Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light List Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Grid Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 1 Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 2 Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 1 Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 2 Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 1 Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 2 Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 3 Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Dark List Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Shading Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful List Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Grid Accent 2"/>
<w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Shading Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light List Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Grid Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 1 Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 2 Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 1 Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 2 Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 1 Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 2 Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 3 Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Dark List Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Shading Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful List Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Grid Accent 3"/>
<w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Shading Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light List Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Grid Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 1 Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 2 Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 1 Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 2 Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 1 Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 2 Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 3 Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Dark List Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Shading Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful List Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Grid Accent 4"/>
<w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Shading Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light List Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Grid Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 1 Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 2 Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 1 Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 2 Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 1 Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 2 Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 3 Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Dark List Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Shading Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful List Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Grid Accent 5"/>
<w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Shading Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light List Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Light Grid Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 1 Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Shading 2 Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 1 Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium List 2 Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 1 Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 2 Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Medium Grid 3 Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Dark List Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Shading Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful List Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" Name=3D"Colorful Grid Accent 6"/>
<w:LsdException Locked=3D"false" Priority=3D"19" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" QFormat=3D"true" Name=3D"Subtle Emphasis"/>
<w:LsdException Locked=3D"false" Priority=3D"21" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" QFormat=3D"true" Name=3D"Intense Emphasis"/>
<w:LsdException Locked=3D"false" Priority=3D"31" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" QFormat=3D"true" Name=3D"Subtle Reference"/>
<w:LsdException Locked=3D"false" Priority=3D"32" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" QFormat=3D"true" Name=3D"Intense Reference"/>
<w:LsdException Locked=3D"false" Priority=3D"33" SemiHidden=3D"false" Unhid=
eWhenUsed=3D"false" QFormat=3D"true" Name=3D"Book Title"/>
<w:LsdException Locked=3D"false" Priority=3D"37" Name=3D"Bibliography"/>
<w:LsdException Locked=3D"false" Priority=3D"39" QFormat=3D"true" Name=3D"T=
OC Heading"/>
</w:LatentStyles>
</xml><![endif]--><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;
	mso-font-charset:1;
	mso-generic-font-family:roman;
	mso-font-format:other;
	mso-font-pitch:variable;
	mso-font-signature:0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:-520092929 1073786111 9 0 415 0;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-parent:"";
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-fareast-font-family:Calibri;
	mso-hansi-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;
	text-underline:single;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-noshow:yes;
	mso-style-priority:99;
	color:purple;
	text-decoration:underline;
	text-underline:single;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
	{mso-style-priority:99;
	mso-style-link:"Plain Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	mso-bidi-font-size:10.5pt;
	font-family:"Calibri","sans-serif";
	mso-fareast-font-family:"Times New Roman";
	mso-bidi-font-family:"Times New Roman";}
span.PlainTextChar
	{mso-style-name:"Plain Text Char";
	mso-style-priority:99;
	mso-style-unhide:no;
	mso-style-locked:yes;
	mso-style-link:"Plain Text";
	mso-bidi-font-size:10.5pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-fareast-font-family:"Times New Roman";
	mso-hansi-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
span.SpellE
	{mso-style-name:"";
	mso-spl-e:yes;}
span.GramE
	{mso-style-name:"";
	mso-gram-e:yes;}
.MsoChpDefault
	{mso-style-type:export-only;
	mso-default-props:yes;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-fareast-font-family:Calibri;
	mso-hansi-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-paper-source:0;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 10]><style>/* Style Definitions */
table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-hansi-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
</style><![endif]--><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple" style=3D"tab-interval:.=
5in">
<div class=3D"WordSection1">
<p class=3D"MsoPlainText">Hi Jim,<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">Here is my take.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">There does not seem consensus over the exact role=
 of <span class=3D"GramE">
a PEP</span>, and maybe that is by design.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">If you look at XACML v3 core it cites rfc3189 as =
a normative reference. Both XACML and 3198 define the PEP role yet the defi=
nitions are not completely aligned. 3198 defies
<span class=3D"GramE">a PEP</span> as:-<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><i style=3D"mso-bidi-font-style:normal">Policy en=
forcement:
<span style=3D"mso-spacerun:yes">&nbsp;</span>The execution of a policy dec=
ision.<o:p></o:p></i></p>
<p class=3D"MsoPlainText"><i style=3D"mso-bidi-font-style:normal">Policy En=
forcement Point (PEP): A logical entity that enforces policy decisions (See=
 also &quot;policy enforcement&quot;)<o:p></o:p></i></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">You can merge the two statements to be more conci=
se i.e. A PEP is a logical entity responsible for the execution of policy d=
ecisions.
<span class=3D"GramE">This s a fairly general purpose, any policy model.</s=
pan> <o:p>
</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">XACML is more restrictive. It defines PEP as:-<o:=
p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><span class=3D"GramE"><i style=3D"mso-bidi-font-s=
tyle:normal">The system entity that performs access control by making decis=
ion requests and enforcing authorization decisions.</i></span><i style=3D"m=
so-bidi-font-style:normal">
<o:p></o:p></i></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">This is very much an access control policy model =
definition. It also implies a trust model.
<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">The policy decision requested by both the Plasma =
and XACML PEP is &#8220;can the client\user access the specified message/da=
ta&#8221;.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">In order to execute the permitted decision in a P=
lasma PEP, we need both the encrypted data and the decryption key. This is =
distinct from an XACML PEP which has access to the clear text data and can =
simply
<span class=3D"GramE">relase</span> the data. The critical difference betwe=
en the two is the trust model. In Plasma we do not unconditionally trust th=
e PEP with the clear txt data; plasma performs an access check first, and t=
hen releases the clear text data to
 the PEP. XACML trusts the PEP with all clear text data regardless of any a=
ccess check.
<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">The decision request is the same for both PEPs, b=
ut the execution of the decision is different because of the different trus=
t
<span class=3D"GramE">models.</span><o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">Trevor<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">-----Original Message-----<br>
From: plasma-bounces@ietf.org [mailto:plasma-bounces@ietf.org] On Behalf <s=
pan class=3D"GramE">
Of</span> Jim Schaad<br>
Sent: Thursday, December 08, 2011 2:07 PM<br>
To: plasma@ietf.org<br>
Subject: [plasma] Where is the PEP?</p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">At the last IETF meeting, Trevor and I got togeth=
er to try and hammer out the skeleton of what the XML protocols would look =
like for the plasma work.<o:p></o:p></p>
<p class=3D"MsoPlainText">During this process we found that the WS-Trust wo=
rk did not appear to have a good way of returning error information for suc=
h items as &quot;missing attribute&quot;.<span style=3D"mso-spacerun:yes">&=
nbsp;
</span>However the XACML documents did have this type of structure and are =
designed for working between the PEP and PDP so they seemed to be a good pl=
ace to base some of the work from.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">In the process of doing this, one of the things t=
hat was going to be highly desired was to be able to carry a SAML Assertion=
 as part of the request from the PEP to the PDP.<span style=3D"mso-spacerun=
:yes">&nbsp;
</span>I found the follow document &quot;SAML 2.0 Profile of XACML, v2.0&qu=
ot;<o:p></o:p></p>
<p class=3D"MsoPlainText"><a href=3D"http://docs.oasis-open.org/xacml/3.0/x=
acml-profile-saml2.0-v2-spec-cs-01-en"><span style=3D"color:windowtext;text=
-decoration:none;text-underline:none">http://docs.oasis-open.org/xacml/3.0/=
xacml-profile-saml2.0-v2-spec-cs-01-en</span></a>.<o:p></o:p></p>
<p class=3D"MsoPlainText">pdf which game a &quot;simple&quot; method of map=
ping the attributes of a SAML statement onto a XACML request.<span style=3D=
"mso-spacerun:yes">&nbsp;
</span>The expectation is that this would be done by the PEP (or some entit=
y between the PEP and the PDP) that is highly trusted as it does the mappin=
g and validates the signatures on the SAML assertion.<span style=3D"mso-spa=
cerun:yes">&nbsp;
</span><o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">This expectation of trust does not map well onto =
the current Plasma mode and got me thinking about the question of where the=
 PEP and PDP boundaries really lie.<span style=3D"mso-spacerun:yes">&nbsp;
</span>I think there may be some level of confusion in the future that we s=
hould at least consider today.<span style=3D"mso-spacerun:yes">&nbsp;
</span>The problem as I see it is that there are two different things that =
access is being granted to and this is not explicitly spelled out in the mo=
del.<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">Access is being granted to the E-Mail message: Th=
is is where we are thinking of the PEP as living today.<span style=3D"mso-s=
pacerun:yes">&nbsp;
</span>That is we are trying to get access to the e-mail message.<o:p></o:p=
></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">Access is being granted to the KEK:<span style=3D=
"mso-spacerun:yes">&nbsp;
</span>This is where the real PEP/PDP are living.<span style=3D"mso-spaceru=
n:yes">&nbsp;
</span>In this case the PEP is not a fully trusted entity and does not actu=
ally grant or deny access to the KEK value.<span style=3D"mso-spacerun:yes"=
>&nbsp;
</span>For our purposes the PEP to get access to the KEK value is actually =
living with (or near) the PDP and is the plasma server itself.<span style=
=3D"mso-spacerun:yes">&nbsp;
</span>This is the think that gets a grant statement and then send the reso=
urce back to the e-mail client's PDP.<span style=3D"mso-spacerun:yes">&nbsp=
;
</span><o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">The dichotomy is of issue mostly in terms of how =
trusted the PEP is and therefore what things can be done.<span style=3D"mso=
-spacerun:yes">&nbsp;
</span>The issue in this case is what level of trust can we place in the en=
tity we are calling the PEP (none) and therefore what level of validation o=
f attributes needs to be setup for the items that would normally be placed =
in the XACML Attribute structures.<span style=3D"mso-spacerun:yes">&nbsp;
</span>The PEP would normally be permitted to assert that an attribute was =
correct.<span style=3D"mso-spacerun:yes">&nbsp;
</span>In our case this is not a true statement.<span style=3D"mso-spacerun=
:yes">&nbsp; </span>
This will affect how we look at using both XACML and SAML.<span style=3D"ms=
o-spacerun:yes">&nbsp;
</span>I.e. we probably don't want to use the mapping specified above, but =
we may want to look at creating a new way to place an entire SAML Assertion=
 in an XACML Attribute and leave the PDP to re-distribute it around.<o:p></=
o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">Comments?<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">Jim<o:p></o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoPlainText">_______________________________________________<o=
:p></o:p></p>
<p class=3D"MsoPlainText">plasma mailing list<o:p></o:p></p>
<p class=3D"MsoPlainText"><a href=3D"mailto:plasma@ietf.org"><span style=3D=
"color:windowtext;text-decoration:none;text-underline:none">plasma@ietf.org=
</span></a><o:p></o:p></p>
<p class=3D"MsoPlainText"><a href=3D"https://www.ietf.org/mailman/listinfo/=
plasma"><span style=3D"color:windowtext;text-decoration:none;text-underline=
:none">https://www.ietf.org/mailman/listinfo/plasma</span></a><o:p></o:p></=
p>
</div>
</body>
</html>

--_000_E545B914D50B2A4B994F198378B1525D42882443DFM1412exchange_--
