Re: [abfab] Direction Forward for aaa-saml
Leif Johansson <leifj@mnt.se> Wed, 22 July 2015 16:13 UTC
Return-Path: <leifj@mnt.se>
X-Original-To: abfab@ietfa.amsl.com
Delivered-To: abfab@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 713611A882F for <abfab@ietfa.amsl.com>; Wed, 22 Jul 2015 09:13:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yfuPXTk4dA5J for <abfab@ietfa.amsl.com>; Wed, 22 Jul 2015 09:13:50 -0700 (PDT)
Received: from mail-wi0-f176.google.com (mail-wi0-f176.google.com [209.85.212.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A1A081A700A for <abfab@ietf.org>; Wed, 22 Jul 2015 09:13:49 -0700 (PDT)
Received: by wicmv11 with SMTP id mv11so88273992wic.0 for <abfab@ietf.org>; Wed, 22 Jul 2015 09:13:48 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :subject:references:in-reply-to:content-type :content-transfer-encoding; bh=3hvBBPw4FbB7BebB33pVKyiTj6386OvA1Z7fX+tXExg=; b=gN2jSII3is2+INlGB+RaazAKohGxrT3t+Na5Qwu6n0P7VUnmmIL38mug4jrllRS9+p CcLJ6S3udX+xlKLMd+bJWO3dcd6TYyID/cFy2BynT+TspsfmvtBJp4M0nnc/F2Ywt4DW G9VZZ8t5hLjai/Pe0k8Mem27hYJmXknkmxTMIMu2gAM6VF4+J8VY/XLFZBDK915dT6RZ bDNNvrrKQMPi4AAIX0/Kls6T/MIN3VfE0sDparoVcL1PzmvozFkUp6aND3zaGZA3qqv1 4Zil4oGOz4tObgbwL9PxnJnhu0P1c9NRLJCscEULucJThaWGS2OxPVgjxEcFX7If5tcw yD0A==
X-Gm-Message-State: ALoCoQn3LK1oayOVc+5KZ6urtTUnTm41521uAuxN7zzP16XEeGkNj9pLEh78o6xAuuxiwUN7ELFx
X-Received: by 10.194.175.65 with SMTP id by1mr7215417wjc.152.1437581628256; Wed, 22 Jul 2015 09:13:48 -0700 (PDT)
Received: from [31.133.176.110] (dhcp-b06e.meeting.ietf.org. [31.133.176.110]) by smtp.googlemail.com with ESMTPSA id js3sm3108479wjc.5.2015.07.22.09.13.46 for <abfab@ietf.org> (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 22 Jul 2015 09:13:46 -0700 (PDT)
Message-ID: <55AFC139.10805@mnt.se>
Date: Wed, 22 Jul 2015 18:13:45 +0200
From: Leif Johansson <leifj@mnt.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.7.0
MIME-Version: 1.0
To: abfab@ietf.org
References: <tslwpxsy0ql.fsf@mit.edu> <8E4E5965-0E43-4ABD-8853-8A6C7C6926C5@mnt.se> <tsloaj4xzvr.fsf@mit.edu> <0B96365A-4F6B-427A-9A87-70F069473F84@mnt.se> <tsl7fpsxrve.fsf@mit.edu> <0A08B89E-5533-4E34-9014-97C0D7877B6E@osu.edu> <tslio9cw8yd.fsf@mit.edu> <D143C9FB-F878-49C1-89C4-6A494714A3EC@mnt.se> <tslegk0w7iw.fsf@mit.edu> <1FA8CCED-221E-4A88-B525-BF46FAA53A3F@mnt.se> <55AFC0E3.8030500@um.es>
In-Reply-To: <55AFC0E3.8030500@um.es>
Content-Type: text/plain; charset="windows-1252"
Content-Transfer-Encoding: 8bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/abfab/0YyMF5ZuLkpJmgPBwVLpixS9CAI>
Subject: Re: [abfab] Direction Forward for aaa-saml
X-BeenThere: abfab@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Application Bridging, Federated Authentication Beyond \(the web\)" <abfab.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/abfab>, <mailto:abfab-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/abfab/>
List-Post: <mailto:abfab@ietf.org>
List-Help: <mailto:abfab-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/abfab>, <mailto:abfab-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Jul 2015 16:13:52 -0000
On 2015-07-22 18:12, Alejandro Pérez Méndez wrote: > > > El 22/07/15 a las 17:14, Leif Johansson escribió: >> >> 22 jul 2015 kl. 17:12 skrev Sam Hartman <hartmans@painless-security.com>: >> >>>>>>>> "Leif" == Leif Johansson <leifj@mnt.se> writes: >>> Leif> 22 jul 2015 kl. 16:41 skrev Sam Hartman >>> Leif> <hartmans@painless-security.com>: >>> >>>>>>>>>> "Cantor," == Cantor, Scott <cantor.2@osu.edu> writes: >>>>> Cantor,> On 7/22/15, 9:07 AM, "abfab on behalf of Sam Hartman" >>>>> Cantor,> <abfab-bounces@ietf.org on behalf of Cantor,> >>>>> hartmans@painless-security.com> >>>>> Cantor,> wrote: >>>>> >>>>> >>>>>>> I think you'd need to: >>>>>>> >>>>>>> 1) Explain how I figure out which entity I'm using for my >>>>>>> RADIUS server >>>>>>> Consider this especially in a case where you're retrieving >>>>>>> metadata dynamically rather than just having all the metadata >>>>>>> in the world. >>>>> Cantor,> That's orthogonal to any use of SAML metadata. How you >>>>> get Cantor,> it (and verify it) is architecturally distinct from >>>>> what it Cantor,> means and how it's used. >>>>> >>>>> Not really. If I'm starting with an NAI realm and would like to >>>>> find the entity description of an entity that is at that NAI >>>>> realm, I can only do that if my metadata access mechanism lets me >>>>> search by that. >>> Leif> so its a requirement for the mdquery draft, not on metadata >>> >>> Nod. >>> >>> I don't anticipate implementing using metadata to select a RADIUS >>> endpoint. >>> So I don't have a lot of interest in working on that. I'm happy to >>> review a specific proposal someone comes up with, but I'd prefer it not >>> end up in aaa-saml and I'd strongly prefer it not block aaa-saml. >>> >>> --Sam >> agree but i think endpoint could be useful for radsec and i suspect it >> will be reasonably simple to do > > I might be mistaken, but wasn't that what we wanted to avoid in the > first place when we decided not to use the RADIUS URI scheme from my > original proposal? > I guess having an endpoint for radsec will require to define how the > "Location" values will look like, and they should be in a URI format as > well. > We agree that we want something other than Entpoint for name2key binding but we are still debating if we want Endpoint for the radsec case. It is debatable.
- [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Alejandro Pérez Méndez
- Re: [abfab] Direction Forward for aaa-saml Cantor, Scott
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Cantor, Scott
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Alejandro Pérez Méndez
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Cantor, Scott
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Cantor, Scott
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Alejandro Pérez Méndez
- Re: [abfab] Direction Forward for aaa-saml Cantor, Scott
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Jim Schaad