Re: [abfab] I-D Action: draft-ietf-abfab-aaa-saml-11.txt

Alejandro Pérez Méndez <alex@um.es> Fri, 07 August 2015 10:37 UTC

Return-Path: <alex@um.es>
X-Original-To: abfab@ietfa.amsl.com
Delivered-To: abfab@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC97B1ACD6C for <abfab@ietfa.amsl.com>; Fri, 7 Aug 2015 03:37:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.91
X-Spam-Level:
X-Spam-Status: No, score=-3.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gzl8c4QsU8cy for <abfab@ietfa.amsl.com>; Fri, 7 Aug 2015 03:37:05 -0700 (PDT)
Received: from xenon22.um.es (xenon22.um.es [155.54.212.162]) by ietfa.amsl.com (Postfix) with ESMTP id 759731ACD00 for <abfab@ietf.org>; Fri, 7 Aug 2015 03:37:05 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by xenon22.um.es (Postfix) with ESMTP id 9242A171B for <abfab@ietf.org>; Fri, 7 Aug 2015 12:37:03 +0200 (CEST)
X-Virus-Scanned: by antispam in UMU at xenon22.um.es
Received: from xenon22.um.es ([127.0.0.1]) by localhost (xenon22.um.es [127.0.0.1]) (amavisd-new, port 10024) with LMTP id loNk6Bko2xY2 for <abfab@ietf.org>; Fri, 7 Aug 2015 12:37:03 +0200 (CEST)
Received: from [10.42.0.179] (84.121.18.25.dyn.user.ono.com [84.121.18.25]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: alex) by xenon22.um.es (Postfix) with ESMTPSA id 5E05A9DD for <abfab@ietf.org>; Fri, 7 Aug 2015 12:37:02 +0200 (CEST)
To: abfab@ietf.org
References: <20150807103108.31573.9033.idtracker@ietfa.amsl.com>
From: Alejandro Pérez Méndez <alex@um.es>
Message-ID: <55C48A4D.2020403@um.es>
Date: Fri, 07 Aug 2015 12:37:01 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.1.0
MIME-Version: 1.0
In-Reply-To: <20150807103108.31573.9033.idtracker@ietfa.amsl.com>
Content-Type: multipart/alternative; boundary="------------050903080200050401080301"
Archived-At: <http://mailarchive.ietf.org/arch/msg/abfab/t8kjGUWZ0HX2a8bxF5WLABOmKrs>
Subject: Re: [abfab] I-D Action: draft-ietf-abfab-aaa-saml-11.txt
X-BeenThere: abfab@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Application Bridging, Federated Authentication Beyond \(the web\)" <abfab.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/abfab>, <mailto:abfab-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/abfab/>
List-Post: <mailto:abfab@ietf.org>
List-Help: <mailto:abfab-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/abfab>, <mailto:abfab-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 07 Aug 2015 10:37:09 -0000

Dear all,

we have posted a new version of draft-ietf-abfab-aaa-saml, which 
addresses most of the pending issues we discussed in the IETF meeting. 
This version will be used to request a review from the SSTC.

The main changes include:

  * Section 1: Remove mention to [I-D.jones-diameter-abfab]
  * Section 1.1: Included table of terminology (similar to the one in
    the ABFAB architecture I-D)
  * Section 4: Inclusion of the SAML metadata extensions to represent
    RADIUS names.
  * Section 8: "RADIUS State Confirmation Methods" moved to "Section 6:
    RADIUS State Confirmation Method Identifiers". The "sender vouches"
    Confirmation Method is no longer used. Instead, the SAML V2.0
    "RADIUS State" is used (i.e. urn:ietf:params:abfab:cm:user or
    urn:ietf:params:abfab:cm:machine)
  * Section 11. Changed the format of the IANA table describing the
    RADIUS attributes, splitting Type and Ext. Type for clarity.

Regards,
Alejandro

El 07/08/15 a las 12:31, internet-drafts@ietf.org escribió:
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
>   This draft is a work item of the Application Bridging for Federated Access Beyond web Working Group of the IETF.
>
>          Title           : A RADIUS Attribute, Binding, Profiles, Name Identifier Format, and Confirmation Methods for SAML
>          Authors         : Josh Howlett
>                            Sam Hartman
>                            Alejandro Perez-Mendez
> 	Filename        : draft-ietf-abfab-aaa-saml-11.txt
> 	Pages           : 28
> 	Date            : 2015-08-07
>
> Abstract:
>     This document describes the use of the Security Assertion Mark-up
>     Language (SAML) with RADIUS in the context of the ABFAB architecture.
>     It defines two RADIUS attributes, a SAML binding, a SAML name
>     identifier format, two SAML profiles, and two SAML confirmation
>     methods.  The RADIUS attributes permit encapsulation of SAML
>     assertions and protocol messages within RADIUS, allowing SAML
>     entities to communicate using the binding.  The two profiles describe
>     the application of this binding for ABFAB authentication and
>     assertion query/request, enabling a Relying Party to request
>     authentication of, or assertions for, users or machines (Clients).
>     These Clients may be named using a NAI name identifier format.
>     Finally, the subject confirmation methods allow requests and queries
>     to be issued for a previously authenticated user or machine without
>     needing to explicitly identify them as the subject.  These artifacts
>     have been defined to permit application in AAA scenarios other than
>     ABFAB, such as network access.
>
>
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-abfab-aaa-saml/
>
> There's also a htmlized version available at:
> https://tools.ietf.org/html/draft-ietf-abfab-aaa-saml-11
>
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-abfab-aaa-saml-11
>
>
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
> _______________________________________________
> abfab mailing list
> abfab@ietf.org
> https://www.ietf.org/mailman/listinfo/abfab