Re: [abfab] New text for section 4.3.3 and 4.3.4 of draft-ietf-abfab-aaa-saml

Sam Hartman <hartmans@painless-security.com> Tue, 28 July 2015 14:11 UTC

Return-Path: <hartmans@painless-security.com>
X-Original-To: abfab@ietfa.amsl.com
Delivered-To: abfab@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 59AD11A916A for <abfab@ietfa.amsl.com>; Tue, 28 Jul 2015 07:11:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.289
X-Spam-Level:
X-Spam-Status: No, score=0.289 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, MIME_8BIT_HEADER=0.3, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XsYsgTxA9I3k for <abfab@ietfa.amsl.com>; Tue, 28 Jul 2015 07:11:54 -0700 (PDT)
Received: from mail.painless-security.com (mail.painless-security.com [23.30.188.241]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 114A01A916F for <abfab@ietf.org>; Tue, 28 Jul 2015 07:10:41 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mail.painless-security.com (Postfix) with ESMTP id 8302B20768; Tue, 28 Jul 2015 10:10:01 -0400 (EDT)
Received: from mail.painless-security.com ([127.0.0.1]) by localhost (mail.suchdamage.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 45GRb4wfJFvL; Tue, 28 Jul 2015 10:10:01 -0400 (EDT)
Received: from carter-zimmerman.suchdamage.org (c-50-136-30-120.hsd1.ma.comcast.net [50.136.30.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "laptop", Issuer "laptop" (not verified)) by mail.painless-security.com (Postfix) with ESMTPS; Tue, 28 Jul 2015 10:10:01 -0400 (EDT)
Received: by carter-zimmerman.suchdamage.org (Postfix, from userid 8042) id DBDDD87E72; Tue, 28 Jul 2015 10:10:35 -0400 (EDT)
From: Sam Hartman <hartmans@painless-security.com>
To: Alejandro Pérez Méndez <alex@um.es>
References: <55B749D0.7070501@um.es>
Date: Tue, 28 Jul 2015 10:10:35 -0400
In-Reply-To: <55B749D0.7070501@um.es> ("Alejandro Pérez Méndez"'s message of "Tue, 28 Jul 2015 11:22:24 +0200")
Message-ID: <tsl6154id9g.fsf@mit.edu>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.3 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <http://mailarchive.ietf.org/arch/msg/abfab/p-qW4O2JlD7FcBicyhI3FDXcpP8>
Cc: "abfab@ietf.org" <abfab@ietf.org>
Subject: Re: [abfab] New text for section 4.3.3 and 4.3.4 of draft-ietf-abfab-aaa-saml
X-BeenThere: abfab@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Application Bridging, Federated Authentication Beyond \(the web\)" <abfab.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/abfab>, <mailto:abfab-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/abfab/>
List-Post: <mailto:abfab@ietf.org>
List-Help: <mailto:abfab-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/abfab>, <mailto:abfab-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Jul 2015 14:11:55 -0000

This looks good to me.
I'd appreciate it is you'd run this by Alan Dekok to make sure we've got
the right RADIUS attributes to use.
Obviously we'll also want to run by SSTC and Scott.
However, I think this may be our answer.

thanks for the great work.

--Sam