From secmech-bounces@lists.ietf.org Tue Jun 21 11:05:52 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DkkK0-0007mh-E0; Tue, 21 Jun 2005 11:05:52 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1DkkJz-0007mZ-1e
	for secmech@megatron.ietf.org; Tue, 21 Jun 2005 11:05:51 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA28590
	for <secmech@ietf.org>; Tue, 21 Jun 2005 11:05:48 -0400 (EDT)
Received: from sj-iport-1-in.cisco.com ([171.71.176.70]
	helo=sj-iport-1.cisco.com) by ietf-mx.ietf.org with esmtp (Exim 4.33)
	id 1Dkkhv-0007qu-HW
	for secmech@ietf.org; Tue, 21 Jun 2005 11:30:35 -0400
Received: from sj-core-5.cisco.com (171.71.177.238)
	by sj-iport-1.cisco.com with ESMTP; 21 Jun 2005 08:05:42 -0700
X-IronPort-AV: i="3.93,218,1115017200"; 
	d="scan'208"; a="644893183:sNHT24114406"
Received: from E2K-SEA-XCH2.sea-alpha.cisco.com (e2k-sea-xch2.cisco.com
	[10.93.132.68])
	by sj-core-5.cisco.com (8.12.10/8.12.6) with ESMTP id j5LF5Zqi017047
	for <secmech@ietf.org>; Tue, 21 Jun 2005 08:05:36 -0700 (PDT)
X-MimeOLE: Produced By Microsoft Exchange V6.0.6249.0
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="US-ASCII"
Content-Transfer-Encoding: quoted-printable
Date: Tue, 21 Jun 2005 08:09:47 -0700
Message-ID: <7210B31550AC934A8637D6619739CE6905668714@e2k-sea-xch2.sea-alpha.cisco.com>
Thread-Topic: Testing 1 2 3
Thread-Index: AcV2cqjQsmI14a1ERwm8/QvOtOtzig==
From: "Salowey, Joe" <jsalowey@cisco.com>
To: <secmech@ietf.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: bb8eae9af85e4fcfe76f325e38493bf4
Content-Transfer-Encoding: quoted-printable
Cc: 
Subject: [SECMECH] Testing 1 2 3
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Sender: secmech-bounces@lists.ietf.org
Errors-To: secmech-bounces@lists.ietf.org

This is a test.=20

_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Thu Jun 23 14:33:55 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DlWWR-00081P-Aq; Thu, 23 Jun 2005 14:33:55 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1DlWWQ-00081K-3p
	for secmech@megatron.ietf.org; Thu, 23 Jun 2005 14:33:54 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA14100
	for <secmech@ietf.org>; Thu, 23 Jun 2005 14:33:51 -0400 (EDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
	by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1DlWuf-0002qy-Gm
	for secmech@ietf.org; Thu, 23 Jun 2005 14:59:04 -0400
Received: from centralmail1brm.Central.Sun.COM ([129.147.62.1])
	by brmea-mail-4.sun.com (8.12.10/8.12.9) with ESMTP id j5NIXbqg019976
	for <secmech@ietf.org>; Thu, 23 Jun 2005 12:33:41 -0600 (MDT)
Received: from binky.Central.Sun.COM (binky.Central.Sun.COM [129.153.128.104])
	by centralmail1brm.Central.Sun.COM (8.12.10+Sun/8.12.10/ENSMAIL,
	v2.2) with ESMTP id j5NIXZ3X028755
	for <secmech@ietf.org>; Thu, 23 Jun 2005 12:33:36 -0600 (MDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.13.3+Sun/8.13.3) with ESMTP id
	j5NIXWrb009543
	for <secmech@ietf.org>; Thu, 23 Jun 2005 13:33:32 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.13.3+Sun/8.13.3/Submit) id j5NIXTZ4009542
	for secmech@ietf.org; Thu, 23 Jun 2005 13:33:29 -0500 (CDT)
Date: Thu, 23 Jun 2005 13:33:29 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: secmech@ietf.org
Message-ID: <20050623183329.GQ16670@binky.Central.Sun.COM>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.5.7i
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 2870a44b67ee17965ce5ad0177e150f4
Cc: 
Subject: [SECMECH] GUAM I-D?
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Sender: secmech-bounces@lists.ietf.org
Errors-To: secmech-bounces@lists.ietf.org

Has it been submitted?

Nico
-- 

_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Fri Jun 24 06:07:19 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1Dll5j-0008LG-2w; Fri, 24 Jun 2005 06:07:19 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1Dll5h-0008LB-JK
	for secmech@megatron.ietf.org; Fri, 24 Jun 2005 06:07:17 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA23410
	for <secmech@ietf.org>; Fri, 24 Jun 2005 06:07:15 -0400 (EDT)
Received: from dirg.bris.ac.uk ([137.222.10.102])
	by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1DllUC-0000om-NL
	for secmech@ietf.org; Fri, 24 Jun 2005 06:32:37 -0400
Received: from shark.cse.bris.ac.uk ([137.222.12.110])
	by dirg.bris.ac.uk with esmtp (Exim 4.51) id 1Dll5A-0004mL-5l
	for secmech@ietf.org; Fri, 24 Jun 2005 11:06:50 +0100
Received: from localhost (localhost [127.0.0.1])
	by shark.cse.bris.ac.uk (8.11.7-20030918/8.11.6) with ESMTP id
	j5OA5Yn16591
	for <secmech@ietf.org>; Fri, 24 Jun 2005 11:05:34 +0100 (BST)
Date: Fri, 24 Jun 2005 11:05:34 +0100 (BST)
From: Josh Howlett <Josh.Howlett@bristol.ac.uk>
X-X-Sender: bujfxh@shark.cse.bris.ac.uk
To: secmech@ietf.org
Message-ID: <Pine.GSO.4.44.0506232014570.2267-100000@shark.cse.bris.ac.uk>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Spam-Score: -2.8
X-Spam-Level: --
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 52e1467c2184c31006318542db5614d5
Cc: 
Subject: [SECMECH] AAA requirement for middleware
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Sender: secmech-bounces@lists.ietf.org
Errors-To: secmech-bounces@lists.ietf.org

Cross-realm AAA over RADIUS is growing extremely rapidly in my
environment (UK & European academic networking); for example, see
http://www.eduroam.org. This is being driven by an inter-Campus national
and international roaming requirement.

There is growing interest in re-using this infrastructure for
cross-realm Middleware functionality for other applications (thereby
providing similiar functionality to M/W architectures such as
Shibboleth).

However, there are no available means to provide an equivalent degree
of security as that provided by tunnelled EAP methods over EAPOL.

To a naive observer, it seems that what is required is a means of
encapsulating EAP in-band over TCP for application protocols. There is
a proposal from Funk et al (TLS/IA) to implement this within the TLS
handshake. Something of this ilk - perhaps ideally an EAP over SASL
mechanism - would be very welcome.

best regards, josh.

------------------------------------------------------------
Josh Howlett, Networking & Digital Communications,
Information Systems & Computing, University of Bristol, U.K.
'phone: 0117 928 7850 email: josh.howlett@bris.ac.uk
------------------------------------------------------------











_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Sun Jun 26 16:06:08 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DmdOK-0004rr-IG; Sun, 26 Jun 2005 16:06:08 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1DmdOI-0004pK-Vv
	for secmech@megatron.ietf.org; Sun, 26 Jun 2005 16:06:07 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA09461
	for <secmech@ietf.org>; Sun, 26 Jun 2005 16:06:04 -0400 (EDT)
Received: from stratton-three-fifty-seven.mit.edu ([18.187.6.102]
	helo=carter-zimmerman.mit.edu)
	by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1DmdnI-0001fP-NB
	for secmech@ietf.org; Sun, 26 Jun 2005 16:31:57 -0400
Received: by carter-zimmerman.mit.edu (Postfix, from userid 8042)
	id B1027E0063; Sun, 26 Jun 2005 16:06:00 -0400 (EDT)
To: Josh Howlett <Josh.Howlett@bristol.ac.uk>
Subject: Re: [SECMECH] AAA requirement for middleware
References: <Pine.GSO.4.44.0506232014570.2267-100000@shark.cse.bris.ac.uk>
From: Sam Hartman <hartmans-ietf@mit.edu>
Date: Sun, 26 Jun 2005 16:06:00 -0400
In-Reply-To: <Pine.GSO.4.44.0506232014570.2267-100000@shark.cse.bris.ac.uk>
	(Josh
	Howlett's message of "Fri, 24 Jun 2005 11:05:34 +0100 (BST)")
Message-ID: <tslpsu8993r.fsf@cz.mit.edu>
User-Agent: Gnus/5.1006 (Gnus v5.10.6) Emacs/21.3 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 1ac7cc0a4cd376402b85bc1961a86ac2
Cc: secmech@ietf.org
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Sender: secmech-bounces@lists.ietf.org
Errors-To: secmech-bounces@lists.ietf.org

Well, there's a significant problem with that.  EAP has a rather
narrow applicability statement and general middleware falls outside
that statement.

One of the goals of the secmech effort is to set up the security
frameworks so that you could use an arbitrary mechanism both for AAA
and for other purposes.

I don't think extending EAP to those other frameworks is the right
solution.  I do think that making it possible to use cross-realm AAA
is a requirement.

--Sam


_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Mon Jun 27 07:42:51 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1Dms0p-0006Dx-9c; Mon, 27 Jun 2005 07:42:51 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1Dms0n-0006Ds-Kd
	for secmech@megatron.ietf.org; Mon, 27 Jun 2005 07:42:49 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA09908
	for <secmech@ietf.org>; Mon, 27 Jun 2005 07:42:48 -0400 (EDT)
Received: from dirg.bris.ac.uk ([137.222.10.102])
	by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1DmsPt-00018a-Uz
	for secmech@ietf.org; Mon, 27 Jun 2005 08:08:48 -0400
Received: from seis.bris.ac.uk ([137.222.10.93])
	by dirg.bris.ac.uk with esmtp (Exim 4.51)
	id 1Dms0F-0000Ag-En; Mon, 27 Jun 2005 12:42:20 +0100
Received: from cumulus.cse.bris.ac.uk ([137.222.12.162])
	by seis.bris.ac.uk with esmtp (Exim 4.51)
	id 1DmrzJ-0005Bb-DM; Mon, 27 Jun 2005 12:41:28 +0100
Date: Mon, 27 Jun 2005 12:41:16 +0100
From: Josh Howlett <josh.howlett@bristol.ac.uk>
To: Sam Hartman <hartmans-ietf@mit.edu>
Subject: Re: [SECMECH] AAA requirement for middleware
Message-ID: <BDF2F587280947CE549536C2@cumulus>
In-Reply-To: <tslpsu8993r.fsf@cz.mit.edu>
References: <Pine.GSO.4.44.0506232014570.2267-100000@shark.cse.bris.ac.uk>
	<tslpsu8993r.fsf@cz.mit.edu>
Originator-Info: login-token=Mulberry:01KPkDfYpubeNrYkncYolpMPBlcDfWaI0nZe9cbTfUWFZubg==;
	token_authority=postmaster@bristol.ac.uk
X-Mailer: Mulberry/3.1.5 (Linux/x86)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
X-Spam-Score: -2.8
X-Spam-Level: --
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 856eb5f76e7a34990d1d457d8e8e5b7f
Content-Transfer-Encoding: 7bit
Cc: secmech@ietf.org
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
Reply-To: Josh Howlett <josh.howlett@bristol.ac.uk>
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Sender: secmech-bounces@lists.ietf.org
Errors-To: secmech-bounces@lists.ietf.org

--On Sunday, June 26, 2005 16:06:00 -0400 Sam Hartman 
<hartmans-ietf@mit.edu> wrote:
> I don't think extending EAP to those other frameworks is the right
> solution. I do think that making it possible to use cross-realm AAA
> is a requirement.

In which case, it's important to me that these frameworks offer mechanisms 
that share the properties of EAP (or, at least, the tunelled EAP methods) 
that make it so good for cross-realm AAA.

Thanks, josh.

-- 
-----------------------------------------------------------
Josh Howlett, Networking & Digital Communications,
Information Systems & Computing, University of Bristol, U.K.
'phone: 0117 928 7850 email: josh.howlett@bris.ac.uk
------------------------------------------------------------

_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Mon Jun 27 11:11:13 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DmvGT-0006QP-1s; Mon, 27 Jun 2005 11:11:13 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1DmvGR-0006QF-U3
	for secmech@megatron.ietf.org; Mon, 27 Jun 2005 11:11:11 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA01285
	for <secmech@ietf.org>; Mon, 27 Jun 2005 11:11:09 -0400 (EDT)
Received: from carter-zimmerman.suchdamage.org ([69.25.196.178]
	helo=carter-zimmerman.mit.edu)
	by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1Dmvfb-0007Au-4h
	for secmech@ietf.org; Mon, 27 Jun 2005 11:37:12 -0400
Received: by carter-zimmerman.mit.edu (Postfix, from userid 8042)
	id C638CE0063; Mon, 27 Jun 2005 11:10:56 -0400 (EDT)
To: Josh Howlett <josh.howlett@bristol.ac.uk>
Subject: Re: [SECMECH] AAA requirement for middleware
References: <Pine.GSO.4.44.0506232014570.2267-100000@shark.cse.bris.ac.uk>
	<tslpsu8993r.fsf@cz.mit.edu> <BDF2F587280947CE549536C2@cumulus>
From: Sam Hartman <hartmans-ietf@mit.edu>
Date: Mon, 27 Jun 2005 11:10:56 -0400
In-Reply-To: <BDF2F587280947CE549536C2@cumulus> (Josh Howlett's message of
	"Mon, 27 Jun 2005 12:41:16 +0100")
Message-ID: <tslfyv3ltrz.fsf@cz.mit.edu>
User-Agent: Gnus/5.1006 (Gnus v5.10.6) Emacs/21.3 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 08170828343bcf1325e4a0fb4584481c
Cc: secmech@ietf.org
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Sender: secmech-bounces@lists.ietf.org
Errors-To: secmech-bounces@lists.ietf.org

>>>>> "Josh" == Josh Howlett <josh.howlett@bristol.ac.uk> writes:

    Josh> --On Sunday, June 26, 2005 16:06:00 -0400 Sam Hartman
    Josh> <hartmans-ietf@mit.edu> wrote:
    >> I don't think extending EAP to those other frameworks is the
    >> right solution. I do think that making it possible to use
    >> cross-realm AAA is a requirement.

    Josh> In which case, it's important to me that these frameworks
    Josh> offer mechanisms that share the properties of EAP (or, at
    Josh> least, the tunelled EAP methods) that make it so good for
    Josh> cross-realm AAA.

Mind enumerating these requirements for us?


_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Mon Jun 27 12:00:33 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1Dmw2D-00004q-7E; Mon, 27 Jun 2005 12:00:33 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1Dmw2B-0008WO-NX
	for secmech@megatron.ietf.org; Mon, 27 Jun 2005 12:00:31 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA05782
	for <secmech@ietf.org>; Mon, 27 Jun 2005 12:00:28 -0400 (EDT)
Received: from dirg.bris.ac.uk ([137.222.10.102])
	by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1DmwRL-0000Ie-OR
	for secmech@ietf.org; Mon, 27 Jun 2005 12:26:33 -0400
Received: from seis.bris.ac.uk ([137.222.10.93])
	by dirg.bris.ac.uk with esmtp (Exim 4.51)
	id 1Dmw1u-0000Mj-OC; Mon, 27 Jun 2005 17:00:21 +0100
Received: from cumulus.cse.bris.ac.uk ([137.222.12.162])
	by seis.bris.ac.uk with esmtp (Exim 4.51)
	id 1Dmvzm-0004nU-7U; Mon, 27 Jun 2005 16:58:08 +0100
Date: Mon, 27 Jun 2005 16:58:01 +0100
From: Josh Howlett <josh.howlett@bristol.ac.uk>
To: Sam Hartman <hartmans-ietf@mit.edu>
Subject: Re: [SECMECH] AAA requirement for middleware
Message-ID: <85DDD0E2BB4C365651CDCDF8@cumulus>
In-Reply-To: <tslfyv3ltrz.fsf@cz.mit.edu>
References: <Pine.GSO.4.44.0506232014570.2267-100000@shark.cse.bris.ac.uk>
	<tslpsu8993r.fsf@cz.mit.edu> <BDF2F587280947CE549536C2@cumulus>
	<tslfyv3ltrz.fsf@cz.mit.edu>
Originator-Info: login-token=Mulberry:010JlB2TIOqz8TAoc4CjEJbkwNEHUyEDXHo0sEDXUwAP4OrA==;
	token_authority=postmaster@bristol.ac.uk
X-Mailer: Mulberry/3.1.5 (Linux/x86)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
X-Spam-Score: -2.8
X-Spam-Level: --
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 769a46790fb42fbb0b0cc700c82f7081
Content-Transfer-Encoding: 7bit
Cc: secmech@ietf.org
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
Reply-To: Josh Howlett <josh.howlett@bristol.ac.uk>
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Sender: secmech-bounces@lists.ietf.org
Errors-To: secmech-bounces@lists.ietf.org



--On Monday, June 27, 2005 11:10:56 -0400 Sam Hartman 
<hartmans-ietf@mit.edu> wrote:

>>>>>> "Josh" == Josh Howlett <josh.howlett@bristol.ac.uk> writes:
>
>     Josh> --On Sunday, June 26, 2005 16:06:00 -0400 Sam Hartman
>     Josh> <hartmans-ietf@mit.edu> wrote:
>     >> I don't think extending EAP to those other frameworks is the
>     >> right solution. I do think that making it possible to use
>     >> cross-realm AAA is a requirement.
>
>     Josh> In which case, it's important to me that these frameworks
>     Josh> offer mechanisms that share the properties of EAP (or, at
>     Josh> least, the tunelled EAP methods) that make it so good for
>     Josh> cross-realm AAA.
>
> Mind enumerating these requirements for us?

Off the top of my head:

 - plays nicely with the cross-realm AAA protocol _du jour_, RADIUS, and 
successor, Diameter;
 - passthrough mode (authenticator does not participate in authentication, 
beyond acting as a go-between, and simply honours the success/failure code 
returned by the AAA backend);
 - negotiation of EAP methods;
 - extensible attributes: can be returned by the AAA/H to allow richer 
AuthZ at the resource;
 - ability to pass attributes from the AAA/H to both the peer and the 
authenticator simultaneously, but distinctly and privately, through the 
same AAA transaction;
 - security association can be established between the peer (user) and the 
AAA/H, and used to provide privacy across the hops between the peer and the 
AAA/H.
 - use of anonymous NAIs ("anonymous@example.com") to allow anonymous 
proxying of requests;
 - support for legacy AuthN mechanisms;

josh.

-- 
-----------------------------------------------------------
Josh Howlett, Networking & Digital Communications,
Information Systems & Computing, University of Bristol, U.K.
'phone: 0117 928 7850 email: josh.howlett@bris.ac.uk
------------------------------------------------------------

_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Tue Jun 28 10:24:10 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DnH0U-0006sT-G2; Tue, 28 Jun 2005 10:24:10 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1DnH0S-0006sM-Bn
	for secmech@megatron.ietf.org; Tue, 28 Jun 2005 10:24:08 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA13624
	for <secmech@ietf.org>; Tue, 28 Jun 2005 10:24:06 -0400 (EDT)
Received: from sj-iport-3-in.cisco.com ([171.71.176.72]
	helo=sj-iport-3.cisco.com) by ietf-mx.ietf.org with esmtp (Exim 4.33)
	id 1DnHPp-0000SE-48
	for secmech@ietf.org; Tue, 28 Jun 2005 10:50:21 -0400
Received: from sj-core-2.cisco.com (171.71.177.254)
	by sj-iport-3.cisco.com with ESMTP; 28 Jun 2005 07:23:58 -0700
X-IronPort-AV: i="3.93,239,1115017200"; 
	d="scan'208"; a="283828205:sNHT28835564"
Received: from E2K-SEA-XCH2.sea-alpha.cisco.com (e2k-sea-xch2.cisco.com
	[10.93.132.68])
	by sj-core-2.cisco.com (8.12.10/8.12.6) with ESMTP id j5SENqod010140
	for <secmech@ietf.org>; Tue, 28 Jun 2005 07:23:52 -0700 (PDT)
X-MimeOLE: Produced By Microsoft Exchange V6.0.6249.0
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="US-ASCII"
Content-Transfer-Encoding: quoted-printable
Date: Tue, 28 Jun 2005 07:28:14 -0700
Message-ID: <7210B31550AC934A8637D6619739CE69056DCE6E@e2k-sea-xch2.sea-alpha.cisco.com>
Thread-Topic: I-D ACTION:draft-salowey-guam-00.txt
Thread-Index: AcV7nb7lZ3GrcexVTSOhzTmUuem2FwATxj6Q
From: "Salowey, Joe" <jsalowey@cisco.com>
To: <secmech@ietf.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 73734d43604d52d23b3eba644a169745
Content-Transfer-Encoding: quoted-printable
Cc: 
Subject: [SECMECH] FW: I-D ACTION:draft-salowey-guam-00.txt
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Sender: secmech-bounces@lists.ietf.org
Errors-To: secmech-bounces@lists.ietf.org

> ---------- Forwarded message ----------
> From: Internet-Drafts@ietf.org <Internet-Drafts@ietf.org>
> Date: Jun 27, 2005 12:50 PM
> Subject: I-D ACTION:draft-salowey-guam-00.txt
> To: i-d-announce@ietf.org
>=20
>=20
> A New Internet-Draft is available from the on-line=20
> Internet-Drafts directories.
>=20
>=20
>         Title           : Generally Useful Authentication=20
> Mechanisms (GUAM)
>         Author(s)       : J. Salowey
>         Filename        : draft-salowey-guam-00.txt
>         Pages           : 31
>         Date            : 2005-6-27
>=20
>    Generic Security Services API (GSS-API), the Simple Authentication
>    and Security Layer (SASL), the Extensible Authentication Protocol
>    (EAP) and Transport Layer Security (TLS) are examples of four
>    different security frameworks within the IETF.  Each of these
>    frameworks have evolved separately towards a common goal of
>    authentication and establishing a cryptographic context.  They
>    support different types of security mechanisms and have=20
> historically
>    evolved to integrate with different security infrastructures.  This
>    document discusses their similarities and differences and how these
>    security mechanisms might start to converge into a more uniform
>    approach involving generally useful authentication mechanisms that
>    can be used in any of these frameworks with a variety of different
>    security infrastructures.
>=20
> A URL for this Internet-Draft is:
> http://www.ietf.org/internet-drafts/draft-salowey-guam-00.txt
>=20
> To remove yourself from the I-D Announcement list, send a=20
> message to i-d-announce-request@ietf.org with the word=20
> unsubscribe in the body of the message.
> You can also visit https://www1.ietf.org/mailman/listinfo/I-D-announce
> to change your subscription settings.
>=20
>=20
> Internet-Drafts are also available by anonymous FTP. Login=20
> with the username "anonymous" and a password of your e-mail=20
> address. After logging in, type "cd internet-drafts" and then
>         "get draft-salowey-guam-00.txt".
>=20
> A list of Internet-Drafts directories can be found in=20
> http://www.ietf.org/shadow.html or=20
> ftp://ftp.ietf.org/ietf/1shadow-sites.txt
>=20
>=20
> Internet-Drafts can also be obtained by e-mail.
>=20
> Send a message to:
>         mailserv@ietf.org.
> In the body type:
>         "FILE /internet-drafts/draft-salowey-guam-00.txt".
>=20
> NOTE:   The mail server at ietf.org can return the document in
>         MIME-encoded form by using the "mpack" utility.  To use this
>         feature, insert the command "ENCODING mime" before the "FILE"
>         command.  To decode the response(s), you will need=20
> "munpack" or
>         a MIME-compliant mail reader.  Different=20
> MIME-compliant mail readers
>         exhibit different behavior, especially when dealing with
>         "multipart" MIME messages (i.e. documents which have=20
> been split
>         up into multiple messages), so check your local=20
> documentation on
>         how to manipulate these messages.
>=20
>=20
> Below is the data which will enable a MIME compliant mail=20
> reader implementation to automatically retrieve the ASCII=20
> version of the Internet-Draft.
>=20
>=20
>=20
>=20
> _______________________________________________
> I-D-Announce mailing list
> I-D-Announce@ietf.org
> https://www1.ietf.org/mailman/listinfo/i-d-announce
>=20

_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Tue Jun 28 12:53:59 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DnJLT-0008AW-6a; Tue, 28 Jun 2005 12:53:59 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1DnJLR-00089k-6J
	for secmech@megatron.ietf.org; Tue, 28 Jun 2005 12:53:57 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA00614
	for <secmech@ietf.org>; Tue, 28 Jun 2005 12:53:54 -0400 (EDT)
Received: from sj-iport-2-in.cisco.com ([171.71.176.71]
	helo=sj-iport-2.cisco.com) by ietf-mx.ietf.org with esmtp (Exim 4.33)
	id 1DnJko-000208-AS
	for secmech@ietf.org; Tue, 28 Jun 2005 13:20:11 -0400
Received: from sj-core-2.cisco.com (171.71.177.254)
	by sj-iport-2.cisco.com with ESMTP; 28 Jun 2005 09:53:47 -0700
Received: from E2K-SEA-XCH2.sea-alpha.cisco.com (e2k-sea-xch2.cisco.com
	[10.93.132.68])
	by sj-core-2.cisco.com (8.12.10/8.12.6) with ESMTP id j5SGrfod004499;
	Tue, 28 Jun 2005 09:53:41 -0700 (PDT)
X-MimeOLE: Produced By Microsoft Exchange V6.0.6249.0
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="US-ASCII"
Content-Transfer-Encoding: quoted-printable
Subject: RE: [SECMECH] AAA requirement for middleware
Date: Tue, 28 Jun 2005 09:58:02 -0700
Message-ID: <7210B31550AC934A8637D6619739CE69056DCF3E@e2k-sea-xch2.sea-alpha.cisco.com>
Thread-Topic: [SECMECH] AAA requirement for middleware
Thread-Index: AcV7MmtOFq+LO0poSEiMVSsDAXX1CgAvK/Vw
From: "Salowey, Joe" <jsalowey@cisco.com>
To: "Josh Howlett" <josh.howlett@bristol.ac.uk>,
	"Sam Hartman" <hartmans-ietf@mit.edu>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 41c17b4b16d1eedaa8395c26e9a251c4
Content-Transfer-Encoding: quoted-printable
Cc: secmech@ietf.org
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Sender: secmech-bounces@lists.ietf.org
Errors-To: secmech-bounces@lists.ietf.org

Hi Josh,

I just posted a link to an Internet draft I have been working on about
creating generally useful authentication mechanisms (GUAM). =20

I tried to state your requirements below as requirements for generally
useful authentication mechanisms.=20

>  - plays nicely with the cross-realm AAA protocol _du jour_,=20
> RADIUS, and successor, Diameter;

[Joe] Generally useful mechanisms should be usable in the EAP
framework/protocol.=20

Currently to support RADIUS or DIAMETER it is helpful to be able to use
an authentication mechanism within the EAP framework.  There are other
possibilities but EAP provides a nice interface to AAA servers.=20

>  - passthrough mode (authenticator does not participate in=20
> authentication, beyond acting as a go-between, and simply=20
> honours the success/failure code returned by the AAA backend);

[Joe] Generally useful mechanisms should perform authentication between
two parties and should expect than an arbitrary number of proxies
between the parties may handle the messages.

>  - negotiation of EAP methods;

[Joe] There should be a secure means of negotiating generally useful
mechanisms.  I assume you mean protected negotiation of EAP methods
(perhaps within a tunnel).=20

>  - extensible attributes: can be returned by the AAA/H to=20
> allow richer AuthZ at the resource;

[Joe] Generally useful mechanism should be able to exchange
authenticated data between authenticated parties and export this data to
the calling framework. In the GUAM draft I referred to this as channel
bindings (EAP). =20

>  - ability to pass attributes from the AAA/H to both the peer=20
> and the authenticator simultaneously, but distinctly and=20
> privately, through the same AAA transaction;

[Joe] can you elaborate on this?

>  - security association can be established between the peer=20
> (user) and the AAA/H, and used to provide privacy across the=20
> hops between the peer and the AAA/H.

[Joe] Generally useful mechanisms should provide the ability to provide
confidentiality for the data exchanged as channel binding (eap). This
might not be a general requirement for all mechanisms, but a desirable
feature (integrity protection should be required).   =20

>  - use of anonymous NAIs ("anonymous@example.com") to allow=20
> anonymous proxying of requests;

[Joe] Generally useful mechanisms should allow for privacy of the
identity of one of the parties. This might not be a general requirement
for all mechanisms, but it is desirable feature of mechanisms.  =20

>  - support for legacy AuthN mechanisms;

[Joe] I expect that this would depend upon the specific generally useful
mechanism  and the legacy mechanism.  Not all generally useful
mechanisms will support legacy AuthN mechanisms. What legacy mechanisms
are you interested in supporting? =20
=20

_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Tue Jun 28 13:19:37 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DnJkH-0005Cd-LM; Tue, 28 Jun 2005 13:19:37 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1DnJkF-0005CY-SG
	for secmech@megatron.ietf.org; Tue, 28 Jun 2005 13:19:36 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA02322
	for <secmech@ietf.org>; Tue, 28 Jun 2005 13:19:30 -0400 (EDT)
Received: from nwkea-mail-2.sun.com ([192.18.42.14])
	by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1DnK9X-0002eI-E8
	for secmech@ietf.org; Tue, 28 Jun 2005 13:45:48 -0400
Received: from centralmail1brm.Central.Sun.COM ([129.147.62.1])
	by nwkea-mail-2.sun.com (8.12.10/8.12.9) with ESMTP id j5SHJRFF017802
	for <secmech@ietf.org>; Tue, 28 Jun 2005 10:19:27 -0700 (PDT)
Received: from binky.Central.Sun.COM (binky.Central.Sun.COM [129.153.128.104])
	by centralmail1brm.Central.Sun.COM (8.12.10+Sun/8.12.10/ENSMAIL,
	v2.2) with ESMTP id j5SHJQ3Z002569
	for <secmech@ietf.org>; Tue, 28 Jun 2005 11:19:26 -0600 (MDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.13.3+Sun/8.13.3) with ESMTP id
	j5SHJQJp020961; Tue, 28 Jun 2005 12:19:26 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.13.3+Sun/8.13.3/Submit) id j5SHJOKm020960; 
	Tue, 28 Jun 2005 12:19:24 -0500 (CDT)
Date: Tue, 28 Jun 2005 12:19:24 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: Josh Howlett <Josh.Howlett@bristol.ac.uk>
Subject: Re: [SECMECH] AAA requirement for middleware
Message-ID: <20050628171924.GN16670@binky.Central.Sun.COM>
References: <Pine.GSO.4.44.0506232014570.2267-100000@shark.cse.bris.ac.uk>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <Pine.GSO.4.44.0506232014570.2267-100000@shark.cse.bris.ac.uk>
User-Agent: Mutt/1.5.7i
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 52e1467c2184c31006318542db5614d5
Cc: secmech@ietf.org
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Sender: secmech-bounces@lists.ietf.org
Errors-To: secmech-bounces@lists.ietf.org

On Fri, Jun 24, 2005 at 11:05:34AM +0100, Josh Howlett wrote:
> There is growing interest in re-using this infrastructure for
> cross-realm Middleware functionality for other applications (thereby
> providing similiar functionality to M/W architectures such as
> Shibboleth).

The point of this BoF, and hopefully WG, as I understand it is to ensure
the availability of various security mechanisms, AAA-types, PKI and
Kerberos V, and maybe even MD5Digest-types, to all of four common
security frameworks -- EAP, TLS, SASL and the GSS-API.

Either SECMECH could be agnostic w.r.t. framework/mechanism use in
middleware vs. other contexts, or it might tackle any technical matters
specific to middleware.  One technical matter that I can think of that
would be of particular interest in middleware scenarios is credential
delegation, constrained credential delegation, SAML assertion token
exchanges, etc...  I note that KITTEN WG is tackling some related
topics, in relation to naming and name attributes (which I suspect may
be of interest to you, given that you mention Shibboleth).

> However, there are no available means to provide an equivalent degree
> of security as that provided by tunnelled EAP methods over EAPOL.
> 
> To a naive observer, it seems that what is required is a means of
> encapsulating EAP in-band over TCP for application protocols. There is
> a proposal from Funk et al (TLS/IA) to implement this within the TLS
> handshake. Something of this ilk - perhaps ideally an EAP over SASL
> mechanism - would be very welcome.

SECMECH, as proposed, would provide something along these lines, either
by providing mechanism bridges between security frameworks (like SASL
does for the GSS-API), or by providing framework bindings of mechanisms
for various mechanisms/frameworks.

Nico
-- 

_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Tue Jun 28 15:39:55 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DnLw2-0005gd-U5; Tue, 28 Jun 2005 15:39:54 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1DnLw2-0005gN-Cf
	for secmech@megatron.ietf.org; Tue, 28 Jun 2005 15:39:54 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA11248
	for <secmech@ietf.org>; Tue, 28 Jun 2005 15:39:51 -0400 (EDT)
Received: from dirg.bris.ac.uk ([137.222.10.102])
	by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1DnMJJ-0002UN-JI
	for secmech@ietf.org; Tue, 28 Jun 2005 16:03:58 -0400
Received: from shark.cse.bris.ac.uk ([137.222.12.110])
	by dirg.bris.ac.uk with esmtp (Exim 4.51)
	id 1DnLtJ-0000FC-7g; Tue, 28 Jun 2005 20:37:06 +0100
Received: from localhost (localhost [127.0.0.1])
	by shark.cse.bris.ac.uk (8.11.7-20030918/8.11.6) with ESMTP id
	j5SJZiv02247; Tue, 28 Jun 2005 20:35:44 +0100 (BST)
Date: Tue, 28 Jun 2005 20:35:44 +0100 (BST)
From: Josh Howlett <Josh.Howlett@bristol.ac.uk>
X-X-Sender: bujfxh@shark.cse.bris.ac.uk
To: "Salowey, Joe" <jsalowey@cisco.com>
Subject: RE: [SECMECH] AAA requirement for middleware
In-Reply-To: <7210B31550AC934A8637D6619739CE69056DCF3E@e2k-sea-xch2.sea-alpha.cisco.com>
Message-ID: <Pine.GSO.4.44.0506281951330.2267-100000@shark.cse.bris.ac.uk>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Spam-Score: -2.8
X-Spam-Level: --
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 769a46790fb42fbb0b0cc700c82f7081
Cc: secmech@ietf.org
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Sender: secmech-bounces@lists.ietf.org
Errors-To: secmech-bounces@lists.ietf.org

Hi Sam,

On Tue, 28 Jun 2005, Salowey, Joe wrote:
> I tried to state your requirements below as requirements for generally
> useful authentication mechanisms.

Your restatements are good. I have appended the additional
clarifications as requested below.

> >  - extensible attributes: can be returned by the AAA/H to
> > allow richer AuthZ at the resource;
>
> [Joe] Generally useful mechanism should be able to exchange
> authenticated data between authenticated parties and export this data to
> the calling framework. In the GUAM draft I referred to this as channel
> bindings (EAP).

FWIW, a useful outcome of the SECMECH discussion might be a consistent
glossary :-)

> >  - ability to pass attributes from the AAA/H to both the peer
> > and the authenticator simultaneously, but distinctly and
> > privately, through the same AAA transaction;
>
> [Joe] can you elaborate on this?

This is a special case of the previous requirement. Attributes can be
passed from the AAA/H to the NAS and the peer within independent
channel bindings (?) but over the same transport (ie. TTLS (binding
to peer), over EAP, over RADIUS (binding to NAS)).

> >  - support for legacy AuthN mechanisms;
>
> [Joe] I expect that this would depend upon the specific generally useful
> mechanism  and the legacy mechanism.  Not all generally useful
> mechanisms will support legacy AuthN mechanisms. What legacy mechanisms
> are you interested in supporting?

Tunneled cleartext credentials.

best regards, josh.

------------------------------------------------------------
Josh Howlett, Networking & Digital Communications,
Information Systems & Computing, University of Bristol, U.K.
'phone: 0117 928 7850 email: josh.howlett@bris.ac.uk
------------------------------------------------------------


_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Tue Jun 28 17:20:27 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DnNVL-0006OD-J4; Tue, 28 Jun 2005 17:20:27 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1DnNVK-0006O3-Ib
	for secmech@megatron.ietf.org; Tue, 28 Jun 2005 17:20:26 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA27207
	for <secmech@ietf.org>; Tue, 28 Jun 2005 17:20:22 -0400 (EDT)
Received: from nwkea-mail-2.sun.com ([192.18.42.14])
	by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1DnNug-0002bc-GX
	for secmech@ietf.org; Tue, 28 Jun 2005 17:46:41 -0400
Received: from centralmail1brm.Central.Sun.COM ([129.147.62.1])
	by nwkea-mail-2.sun.com (8.12.10/8.12.9) with ESMTP id j5SLKJFF017436
	for <secmech@ietf.org>; Tue, 28 Jun 2005 14:20:19 -0700 (PDT)
Received: from binky.Central.Sun.COM (binky.Central.Sun.COM [129.153.128.104])
	by centralmail1brm.Central.Sun.COM (8.12.10+Sun/8.12.10/ENSMAIL,
	v2.2) with ESMTP id j5SLKI3b026094
	for <secmech@ietf.org>; Tue, 28 Jun 2005 15:20:19 -0600 (MDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.13.3+Sun/8.13.3) with ESMTP id
	j5SLKHpO021198; Tue, 28 Jun 2005 16:20:17 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.13.3+Sun/8.13.3/Submit) id j5SLKD1W021197; 
	Tue, 28 Jun 2005 16:20:13 -0500 (CDT)
Date: Tue, 28 Jun 2005 16:20:13 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: Josh Howlett <Josh.Howlett@bristol.ac.uk>
Subject: Re: [SECMECH] AAA requirement for middleware
Message-ID: <20050628212013.GV16670@binky.Central.Sun.COM>
References: <7210B31550AC934A8637D6619739CE69056DCF3E@e2k-sea-xch2.sea-alpha.cisco.com>
	<Pine.GSO.4.44.0506281951330.2267-100000@shark.cse.bris.ac.uk>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <Pine.GSO.4.44.0506281951330.2267-100000@shark.cse.bris.ac.uk>
User-Agent: Mutt/1.5.7i
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 08e48e05374109708c00c6208b534009
Cc: secmech@ietf.org
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Sender: secmech-bounces@lists.ietf.org
Errors-To: secmech-bounces@lists.ietf.org

On Tue, Jun 28, 2005 at 08:35:44PM +0100, Josh Howlett wrote:
> FWIW, a useful outcome of the SECMECH discussion might be a consistent
> glossary :-)

Sure, but, do not expect a unified glossary... :/

Nico
-- 

_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



From secmech-bounces@lists.ietf.org Wed Jun 29 16:50:31 2005
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32)
	id 1DnjVu-0001yB-Vu; Wed, 29 Jun 2005 16:50:31 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.32) id 1DnjVr-0001y4-R8
	for secmech@megatron.ietf.org; Wed, 29 Jun 2005 16:50:28 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA24163
	for <secmech@ietf.org>; Wed, 29 Jun 2005 16:50:25 -0400 (EDT)
Received: from sj-iport-3-in.cisco.com ([171.71.176.72]
	helo=sj-iport-3.cisco.com) by ietf-mx.ietf.org with esmtp (Exim 4.33)
	id 1DnjvT-0007J6-RW
	for secmech@ietf.org; Wed, 29 Jun 2005 17:16:57 -0400
Received: from sj-core-1.cisco.com (171.71.177.237)
	by sj-iport-3.cisco.com with ESMTP; 29 Jun 2005 13:50:16 -0700
X-IronPort-AV: i="3.93,243,1115017200"; 
	d="scan'208"; a="284381244:sNHT3518041042"
Received: from E2K-SEA-XCH2.sea-alpha.cisco.com (e2k-sea-xch2.cisco.com
	[10.93.132.68])
	by sj-core-1.cisco.com (8.12.10/8.12.6) with ESMTP id j5TKoFvM004425
	for <secmech@ietf.org>; Wed, 29 Jun 2005 13:50:16 -0700 (PDT)
X-MimeOLE: Produced By Microsoft Exchange V6.0.6249.0
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="US-ASCII"
Content-Transfer-Encoding: quoted-printable
Date: Wed, 29 Jun 2005 13:54:32 -0700
Message-ID: <7210B31550AC934A8637D6619739CE69056DD3D5@e2k-sea-xch2.sea-alpha.cisco.com>
Thread-Topic: Generally Usable Authentication Mechanisms
Thread-Index: AcV87Can8ULd6eIfSJK0iux2ksw5gw==
From: "Salowey, Joe" <jsalowey@cisco.com>
To: <secmech@ietf.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 79899194edc4f33a41f49410777972f8
Content-Transfer-Encoding: quoted-printable
Cc: 
Subject: [SECMECH] Generally Usable Authentication Mechanisms
X-BeenThere: secmech@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Security mechanisms BOF <secmech.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/secmech>
List-Post: <mailto:secmech@lists.ietf.org>
List-Help: <mailto:secmech-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/secmech>,
	<mailto:secmech-request@lists.ietf.org?subject=subscribe>
Sender: secmech-bounces@lists.ietf.org
Errors-To: secmech-bounces@lists.ietf.org

Generally Usable Authentication Mechanisms

We have several frameworks (EAP, GSS-API and SASL) that provide access
to multiple security mechanisms.  Each of these frameworks have
developed to focus on different environments and has strengths in
different areas, however at the core they are trying to reach the same
goal of authentication and cryptographic context establishment.  We
should be able to develop a mechanisms once as a generally useful
mechanism and have it work in any of these frameworks.  The requirements
for a generally useful mechanisms are a superset of the requirements of
the individual frameworks.  I have tried to collect some of these ideas
and requirements in draft-salowey-guam-00.txt. =20

http://www.ietf.org/internet-drafts/draft-salowey-guam-00.txt

Comments on this approach?

Thanks,

Joe

_______________________________________________
SECMECH mailing list
SECMECH@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/secmech



