Re: [abfab] Direction Forward for aaa-saml
Leif Johansson <leifj@mnt.se> Wed, 22 July 2015 15:00 UTC
Return-Path: <leifj@mnt.se>
X-Original-To: abfab@ietfa.amsl.com
Delivered-To: abfab@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1])
by ietfa.amsl.com (Postfix) with ESMTP id 42B361A0047
for <abfab@ietfa.amsl.com>; Wed, 22 Jul 2015 08:00:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5
tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44])
by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id adOlNGJ6NOlS for <abfab@ietfa.amsl.com>;
Wed, 22 Jul 2015 08:00:09 -0700 (PDT)
Received: from mail-wi0-f182.google.com (mail-wi0-f182.google.com
[209.85.212.182])
(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
(No client certificate requested)
by ietfa.amsl.com (Postfix) with ESMTPS id EE6101A000B
for <abfab@ietf.org>; Wed, 22 Jul 2015 08:00:03 -0700 (PDT)
Received: by wicmv11 with SMTP id mv11so85391550wic.0
for <abfab@ietf.org>; Wed, 22 Jul 2015 08:00:02 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20130820;
h=x-gm-message-state:content-type:mime-version:subject:from
:in-reply-to:date:cc:content-transfer-encoding:message-id:references
:to; bh=JvWSurlzZlCkeZ1bVBcw0JdzzZhTpk6ixWk8iYWfMLY=;
b=MLSj9qmUuJjAKSujeUI8Fov7xV7pChlu2I8fhc+XG5x0dmptaxwnXy8Ad+WK6Bl2f/
nsJeMO0WtB0ooB0Lf01veAKM2BM9tCZbQFz314Yq4ZcPS5luGFb0YstkqwKPkCpyPM8X
J/xPynZZ5+RAGfVb8Daa+QmEcuKWbO7WcCQamu3Yn1QqzqcZo0Bpkif6i2SuE63x3EYN
UK7RN4HGikM6E2Vp1OgrqHSlKkaBhCifs8SB39cH2/bEj+G1uxDx5mkQoKv5OTwei0wb
eJO4pps7k9Y2xKscyCqdVp1y3zqEO324vBnxTJA3E4N2+4ivvvbrykz2nifmJJ+h3YQH
g4YQ==
X-Gm-Message-State: ALoCoQnOBZpfdt0gvbnE5EAurrYjI4yBpo7szTEAOR95aX9YXOHTepzs8ijkYwCeD8XJsZWqr1h4
X-Received: by 10.194.175.65 with SMTP id by1mr6537046wjc.152.1437577202422;
Wed, 22 Jul 2015 08:00:02 -0700 (PDT)
Received: from [31.133.155.46] (dhcp-9b2e.meeting.ietf.org. [31.133.155.46])
by smtp.gmail.com with ESMTPSA id iy4sm3785095wic.24.2015.07.22.08.00.01
(version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128);
Wed, 22 Jul 2015 08:00:01 -0700 (PDT)
Content-Type: text/plain;
charset=us-ascii
Mime-Version: 1.0 (1.0)
From: Leif Johansson <leifj@mnt.se>
X-Mailer: iPhone Mail (12H143)
In-Reply-To: <tslio9cw8yd.fsf@mit.edu>
Date: Wed, 22 Jul 2015 17:00:00 +0200
Content-Transfer-Encoding: 7bit
Message-Id: <D143C9FB-F878-49C1-89C4-6A494714A3EC@mnt.se>
References: <tslwpxsy0ql.fsf@mit.edu>
<8E4E5965-0E43-4ABD-8853-8A6C7C6926C5@mnt.se> <tsloaj4xzvr.fsf@mit.edu>
<0B96365A-4F6B-427A-9A87-70F069473F84@mnt.se> <tsl7fpsxrve.fsf@mit.edu>
<0A08B89E-5533-4E34-9014-97C0D7877B6E@osu.edu> <tslio9cw8yd.fsf@mit.edu>
To: Sam Hartman <hartmans@painless-security.com>
Archived-At: <http://mailarchive.ietf.org/arch/msg/abfab/OnFe29PL3GP-9X-Bj3nHL7-0Dns>
Cc: "abfab@ietf.org" <abfab@ietf.org>
Subject: Re: [abfab] Direction Forward for aaa-saml
X-BeenThere: abfab@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Application Bridging,
Federated Authentication Beyond \(the web\)" <abfab.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/abfab>,
<mailto:abfab-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/abfab/>
List-Post: <mailto:abfab@ietf.org>
List-Help: <mailto:abfab-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/abfab>,
<mailto:abfab-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Jul 2015 15:00:12 -0000
22 jul 2015 kl. 16:41 skrev Sam Hartman <hartmans@painless-security.com>om>: >>>>>> "Cantor," == Cantor, Scott <cantor.2@osu.edu> writes: > > Cantor,> On 7/22/15, 9:07 AM, "abfab on behalf of Sam Hartman" > Cantor,> <abfab-bounces@ietf.org on behalf of > Cantor,> hartmans@painless-security.com> > Cantor,> wrote: > > >>> >>> I think you'd need to: >>> >>> 1) Explain how I figure out which entity I'm using for my RADIUS >>> server > >>> Consider this especially in a case where you're retrieving >>> metadata dynamically rather than just having all the metadata in >>> the world. > > Cantor,> That's orthogonal to any use of SAML metadata. How you get > Cantor,> it (and verify it) is architecturally distinct from what it > Cantor,> means and how it's used. > > Not really. > If I'm starting with an NAI realm and would like to find the entity > description of an entity that is at that NAI realm, I can only do that > if my metadata access mechanism lets me search by that. so its a requirement for the mdquery draft, not on metadata > > However I do agree that this problem is general to the case where you're > using SAML naming rather than AAA naming, not just to the case where > you're getting protocol endpoints from metadata.
- [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Alejandro Pérez Méndez
- Re: [abfab] Direction Forward for aaa-saml Cantor, Scott
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Cantor, Scott
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Alejandro Pérez Méndez
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Cantor, Scott
- Re: [abfab] Direction Forward for aaa-saml Sam Hartman
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Cantor, Scott
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Alejandro Pérez Méndez
- Re: [abfab] Direction Forward for aaa-saml Cantor, Scott
- Re: [abfab] Direction Forward for aaa-saml Leif Johansson
- Re: [abfab] Direction Forward for aaa-saml Jim Schaad