[abfab] Credential forwarding/delegation in ABFAB

Stefan Paetow <Stefan.Paetow@jisc.ac.uk> Mon, 06 July 2015 23:35 UTC

Return-Path: <stefan.paetow@jisc.ac.uk>
X-Original-To: abfab@ietfa.amsl.com
Delivered-To: abfab@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EEEA11A19FA for <abfab@ietfa.amsl.com>; Mon, 6 Jul 2015 16:35:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.302
X-Spam-Level:
X-Spam-Status: No, score=-2.302 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5QF04jEcPcgc for <abfab@ietfa.amsl.com>; Mon, 6 Jul 2015 16:35:34 -0700 (PDT)
Received: from eu-smtp-delivery-189.mimecast.com (eu-smtp-delivery-189.mimecast.com [207.82.80.189]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 67B0B1A00FF for <abfab@ietf.org>; Mon, 6 Jul 2015 16:35:34 -0700 (PDT)
Received: from emea01-am1-obe.outbound.protection.outlook.com (mail-am1lrp0019.outbound.protection.outlook.com [213.199.154.19]) (Using TLS) by eu-smtp-1.mimecast.com with ESMTP id uk-mta-8-pn-qVGOdTn-LuxoDk0-CUg-1
Received: from AM2PR07MB0898.eurprd07.prod.outlook.com (10.161.71.19) by AM2PR07MB0900.eurprd07.prod.outlook.com (10.161.71.21) with Microsoft SMTP Server (TLS) id 15.1.207.19; Mon, 6 Jul 2015 23:35:31 +0000
Received: from AM2PR07MB0898.eurprd07.prod.outlook.com ([10.161.71.19]) by AM2PR07MB0898.eurprd07.prod.outlook.com ([10.161.71.19]) with mapi id 15.01.0207.004; Mon, 6 Jul 2015 23:35:30 +0000
From: Stefan Paetow <Stefan.Paetow@jisc.ac.uk>
To: "abfab@ietf.org" <abfab@ietf.org>
Thread-Topic: Credential forwarding/delegation in ABFAB
Thread-Index: AQHQuERyrwjjXuq7kEeFyzjv3F3NHQ==
Date: Mon, 06 Jul 2015 23:35:30 +0000
Message-ID: <D1C0CF50.970B%stefan.paetow@jisc.ac.uk>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [109.176.225.93]
x-microsoft-exchange-diagnostics: 1; AM2PR07MB0900; 5:KQjOwHGYVpoBCP+TSpRmM6OmqTlhRCe6yjQ/BztP04oFtxCdPJCoGA0LrPMNk8ptl4BMEbRTgDFRSCDqwu1LSWy328RdoJtvvME7N9fUa5NkzZgGwoneNWrFIpJxMMi+SPen7HZuCEfpO6zTM3b+Pg==; 24:my4ElGtYRkYbEHWY/mlmfwJ59hjsdBwpxm/DYsCWVkdCM/jLtOg0KNwSQip0TC3hewRApRfVt4O09t35wlKGwV98fyKpt9n+cPl1/xOIKoQ=; 20:sITr1sTTd/4uy+jd4xYrcpz2JOz/R0aOqLlTBKJzfhEK2Cqc01/6diKL4sXso7b05renA3cs6Z6Q2cHzFp3dCtrp6xmXKl9qiyGEvkKfM8Uzv98jzc07B69x/M6y6tN/4y1xK3aUX8Il1bqt4V/SLJ8+BbjJfyyJ94pnCNl+Sik=
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:AM2PR07MB0900;
x-microsoft-antispam-prvs: <AM2PR07MB090024040BCDD7C72727B0DCC8930@AM2PR07MB0900.eurprd07.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(5005006)(3002001); SRVR:AM2PR07MB0900; BCL:0; PCL:0; RULEID:; SRVR:AM2PR07MB0900;
x-forefront-prvs: 06290ECA9D
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(6009001)(53754006)(40100003)(229853001)(62966003)(450100001)(74482002)(46102003)(77156002)(86362001)(19580395003)(122556002)(2351001)(15975445007)(2656002)(54356999)(50986999)(2900100001)(77096005)(102836002)(19580405001)(87936001)(189998001)(5002640100001)(107886002)(66066001)(36756003)(92566002)(106116001)(2501003)(5001920100001)(5001960100002)(110136002); DIR:OUT; SFP:1101; SCL:1; SRVR:AM2PR07MB0900; H:AM2PR07MB0898.eurprd07.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-ID: <4EAA20D4239DC34BA53BE43E48121CCC@eurprd07.prod.outlook.com>
MIME-Version: 1.0
X-OriginatorOrg: jisc.ac.uk
X-MS-Exchange-CrossTenant-originalarrivaltime: 06 Jul 2015 23:35:30.7203 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 48f9394d-8a14-4d27-82a6-f35f12361205
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM2PR07MB0900
X-MC-Unique: pn-qVGOdTn-LuxoDk0-CUg-1
Content-Type: text/plain; charset="WINDOWS-1252"
Content-Transfer-Encoding: quoted-printable
Archived-At: <http://mailarchive.ietf.org/arch/msg/abfab/IVo4W5ZIkgfAefe_c5uy2Qbjtck>
Subject: [abfab] Credential forwarding/delegation in ABFAB
X-BeenThere: abfab@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Application Bridging, Federated Authentication Beyond \(the web\)" <abfab.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/abfab>, <mailto:abfab-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/abfab/>
List-Post: <mailto:abfab@ietf.org>
List-Help: <mailto:abfab-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/abfab>, <mailto:abfab-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Jul 2015 23:35:38 -0000

Hi all, 

I've submitted a new draft for ABFAB. This one's about credential
forwarding/delegation because it's been something that's been raised by
several of our pilot infrastructures who raised concerns that ABFAB
doesn't support it.

I raised this on the Moonshot community list and had some interested
parties (Daniel Kouril and Gabriel Lopez), so I think it's worth
discussing... 

Be gentle. It's my first draft:

https://datatracker.ietf.org/doc/draft-paetow-abfab-credential-forward-dele
gate/


It's currently marked as informational, but I suspect that'll change as it
evolves.

Thank you very much!

Stefan Paetow
Moonshot Industry & Research Liaison Coordinator

t: +44 (0)1235 822 125
gpg: 0x3FCE5142
xmpp: stefanp@jabber.dev.ja.net
skype: stefan.paetow.janet

jisc.ac.uk

Jisc is a registered charity (number 1149740) and a company limited by
guarantee which is registered in England under Company No. 5747339, VAT
No. GB 197 0632 86. JiscĀ¹s registered office is: One Castlepark, Tower
Hill, Bristol, BS2 0JA. T 0203 697 5800.

Jisc Collections and Janet Ltd. is a wholly owned Jisc subsidiary and a
company limited by guarantee which is registered in England under Company
No. number 2881024, VAT No. GB 197 0632 86. The registered office is:
Lumen House, Library Avenue, Harwell, Didcot, Oxfordshire, OX11 0SG. T
01235 822200.