Re: [abfab] Comments on draft-ietf-abfab-aaa-saml-11

Sam Hartman <hartmans@painless-security.com> Mon, 10 August 2015 14:38 UTC

Return-Path: <hartmans@painless-security.com>
X-Original-To: abfab@ietfa.amsl.com
Delivered-To: abfab@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C7A981B362C for <abfab@ietfa.amsl.com>; Mon, 10 Aug 2015 07:38:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level:
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ENndt7iP_sai for <abfab@ietfa.amsl.com>; Mon, 10 Aug 2015 07:38:05 -0700 (PDT)
Received: from mail.painless-security.com (mail.painless-security.com [23.30.188.241]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 462EC1B3637 for <abfab@ietf.org>; Mon, 10 Aug 2015 07:38:05 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mail.painless-security.com (Postfix) with ESMTP id 0187D2078D; Mon, 10 Aug 2015 10:36:51 -0400 (EDT)
Received: from mail.painless-security.com ([127.0.0.1]) by localhost (mail.suchdamage.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8hToruRdwTnj; Mon, 10 Aug 2015 10:36:51 -0400 (EDT)
Received: from carter-zimmerman.suchdamage.org (c-50-136-30-120.hsd1.ma.comcast.net [50.136.30.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "laptop", Issuer "laptop" (not verified)) by mail.painless-security.com (Postfix) with ESMTPS; Mon, 10 Aug 2015 10:36:51 -0400 (EDT)
Received: by carter-zimmerman.suchdamage.org (Postfix, from userid 8042) id E75E280910; Mon, 10 Aug 2015 10:38:02 -0400 (EDT)
From: Sam Hartman <hartmans@painless-security.com>
To: "Cantor, Scott" <cantor.2@osu.edu>
References: <75CEE38C-77DD-438B-BECD-6FF8ADB6826E@osu.edu> <55C5AF0A.2060000@um.es> <0EB79B20-E2CE-451A-9139-CC581DFD28B7@osu.edu>
Date: Mon, 10 Aug 2015 10:38:02 -0400
In-Reply-To: <0EB79B20-E2CE-451A-9139-CC581DFD28B7@osu.edu> (Scott Cantor's message of "Sun, 9 Aug 2015 18:59:45 +0000")
Message-ID: <tslk2t35hv9.fsf@mit.edu>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.3 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <http://mailarchive.ietf.org/arch/msg/abfab/TyfN23g8k3m7kD4HnPUmFC_QR8I>
Cc: "abfab@ietf.org" <abfab@ietf.org>
Subject: Re: [abfab] Comments on draft-ietf-abfab-aaa-saml-11
X-BeenThere: abfab@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Application Bridging, Federated Authentication Beyond \(the web\)" <abfab.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/abfab>, <mailto:abfab-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/abfab/>
List-Post: <mailto:abfab@ietf.org>
List-Help: <mailto:abfab-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/abfab>, <mailto:abfab-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Aug 2015 14:38:07 -0000

>>>>> "Cantor," == Cantor, Scott <cantor.2@osu.edu> writes:

    Cantor,> It may be that the right value here is just
    Cantor,> "urn:oasis:names:tc:SAML:2.0:protocol", which is the one
    Cantor,> that's called out by default in the metadata spec for SAML
    Cantor,> 2.0 entities.

    Cantor,> Since these roles were, I thought, more intended to
    Cantor,> describe RADIUS entities, that didn't seem entirely
    Cantor,> appropriate, but OTOH if these are RADIUS entities able to
    Cantor,> communicate SAML 2.0 messages, I don't know that it isn't
    Cantor,> appropriate either.

These are in fact RADIUS entities that can communicate using SAML 2.0
using the binding defined in this document.
Currently, that is the only use for these roles.

--Sam