[abfab] Trust router (was Re: Fwd: New Version Notification for draft-wierenga-ietf-eduroam-00.txt)

Josh Howlett <Josh.Howlett@ja.net> Mon, 15 October 2012 12:56 UTC

Return-Path: <Josh.Howlett@ja.net>
X-Original-To: abfab@ietfa.amsl.com
Delivered-To: abfab@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4CCEE21F8758 for <abfab@ietfa.amsl.com>; Mon, 15 Oct 2012 05:56:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.516
X-Spam-Level:
X-Spam-Status: No, score=-102.516 tagged_above=-999 required=5 tests=[AWL=0.083, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gMpsA8dL-DQm for <abfab@ietfa.amsl.com>; Mon, 15 Oct 2012 05:56:39 -0700 (PDT)
Received: from egw002.ukerna.ac.uk (egw002.ukerna.ac.uk [194.81.3.65]) by ietfa.amsl.com (Postfix) with ESMTP id 6FEB821F86F8 for <abfab@ietf.org>; Mon, 15 Oct 2012 05:56:39 -0700 (PDT)
Received: from egw002.ukerna.ac.uk (localhost.localdomain [127.0.0.1]) by localhost (Email Security Appliance) with SMTP id 2A50320C71B8_7C0805B; Mon, 15 Oct 2012 12:56:37 +0000 (GMT)
Received: from EXC001.atlas.ukerna.ac.uk (exc001.atlas.ukerna.ac.uk [193.62.83.37]) by egw002.ukerna.ac.uk (Sophos Email Appliance) with ESMTP id 4751C20C7123_7C0804F; Mon, 15 Oct 2012 12:56:36 +0000 (GMT)
Received: from EXC001.atlas.ukerna.ac.uk ([193.62.83.37]) by EXC001 ([193.62.83.37]) with mapi id 14.02.0247.003; Mon, 15 Oct 2012 13:56:35 +0100
From: Josh Howlett <Josh.Howlett@ja.net>
To: Klaas Wierenga <klaas@cisco.com>, "<abfab@ietf.org>" <abfab@ietf.org>
Thread-Topic: Trust router (was Re: [abfab] Fwd: New Version Notification for draft-wierenga-ietf-eduroam-00.txt)
Thread-Index: AQHNqtSBIG2/OYb8xkuALeXxRwN1Dg==
Date: Mon, 15 Oct 2012 12:56:35 +0000
Message-ID: <CCA1BA78.20480%Josh.Howlett@ja.net>
In-Reply-To: <A3ADBB74-9992-409A-A33C-684C43B68575@cisco.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.2.4.120824
x-originating-ip: [194.82.140.76]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <B3151510F3F4094394CB8055090665E3@ukerna.ac.uk>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: [abfab] Trust router (was Re: Fwd: New Version Notification for draft-wierenga-ietf-eduroam-00.txt)
X-BeenThere: abfab@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Application Bridging, Federated Authentication Beyond \(the web\)" <abfab.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/abfab>, <mailto:abfab-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/abfab>
List-Post: <mailto:abfab@ietf.org>
List-Help: <mailto:abfab-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/abfab>, <mailto:abfab-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 15 Oct 2012 12:56:40 -0000

Hi Klaas,

I probably shouldn't be writing this email until I have finished the
update to aaa-saml :-). However I thought it was worth pointing out that
section 3.3. ('Routing table complexity') is a nice description of the
kind of problem that Trust Router (draft-howlett-abfab-trust-router-ps) is
trying to fix.

But now let us imagine that one was also interested in operating "govroam"
in parallel to eduroam, where they may be some overlap between these
communities. Now, in addition to the naming/connectivity incongruence
described in section 3.3, you can also add incongruence of trust
communities.

My contention is that, for the use cases that Abfab is addressing, the
number and overlap of trust communities wanting to consume identity is in
fact rather large. Therefore it will be significantly cheaper to operate a
single infrastructure that can manage these incongruences, rather than
instantiate N distinct infrastructures for N different trust communities.

It should be as cheap and easy to create and manage a trust community of
arbitrary actors as it is to connect a house full of consumer electronics
to a domestic WiFi router.

Josh.

On 15/10/2012 12:11, "Klaas Wierenga" <klaas@cisco.com> wrote:

>FYI
>
>Begin forwarded message:
>
>> From: <internet-drafts@ietf.org>
>> Subject: New Version Notification for draft-wierenga-ietf-eduroam-00.txt
>> Date: October 15, 2012 12:24:23 PM GMT+02:00
>> To: <klaas@cisco.com>
>> Cc: <stefan.winter@restena.lu>, <twoln@umk.pl>
>> 
>> 
>> A new version of I-D, draft-wierenga-ietf-eduroam-00.txt
>> has been successfully submitted by Klaas Wierenga and posted to the
>> IETF repository.
>> 
>> Filename:	 draft-wierenga-ietf-eduroam
>> Revision:	 00
>> Title:		 The eduroam architecture for network roaming
>> Creation date:	 2012-10-15
>> WG ID:		 Individual Submission
>> Number of pages: 31
>> URL:            
>>http://www.ietf.org/internet-drafts/draft-wierenga-ietf-eduroam-00.txt
>> Status:         
>>http://datatracker.ietf.org/doc/draft-wierenga-ietf-eduroam
>> Htmlized:       
>>http://tools.ietf.org/html/draft-wierenga-ietf-eduroam-00
>> 
>> 
>> Abstract:
>>   This document describes the architecture of the eduroam service for
>>   federated (wireless) network access in academia.  The combination of
>>   802.1X, EAP and RADIUS that is used in eduroam provides a secure,
>>   scalable and deployable service for roaming network access.  The
>>   successful deployment of eduroam over the last decade in the
>>   educational sector may serve as an example for other sectors, hence
>>   this document.  In particular the initial architectural and standards
>>   choices and the changes that were prompted by operational experience
>>   are highlighted.
>> 
>> 
>> 
>> 
>> The IETF Secretariat
>> 
>
>_______________________________________________
>abfab mailing list
>abfab@ietf.org
>https://www.ietf.org/mailman/listinfo/abfab


Janet is a trading name of The JNT Association, a company limited
by guarantee which is registered in England under No. 2881024 
and whose Registered Office is at Lumen House, Library Avenue,
Harwell Oxford, Didcot, Oxfordshire. OX11 0SG