Re: [abfab] I-D Action: draft-ietf-abfab-aaa-saml-11.txt
Alejandro Pérez Méndez <alex@um.es> Fri, 07 August 2015 10:37 UTC
Return-Path: <alex@um.es>
X-Original-To: abfab@ietfa.amsl.com
Delivered-To: abfab@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1])
by ietfa.amsl.com (Postfix) with ESMTP id DC97B1ACD6C
for <abfab@ietfa.amsl.com>; Fri, 7 Aug 2015 03:37:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.91
X-Spam-Level:
X-Spam-Status: No, score=-3.91 tagged_above=-999 required=5
tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3,
RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01]
autolearn=ham
Received: from mail.ietf.org ([4.31.198.44])
by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id gzl8c4QsU8cy for <abfab@ietfa.amsl.com>;
Fri, 7 Aug 2015 03:37:05 -0700 (PDT)
Received: from xenon22.um.es (xenon22.um.es [155.54.212.162])
by ietfa.amsl.com (Postfix) with ESMTP id 759731ACD00
for <abfab@ietf.org>; Fri, 7 Aug 2015 03:37:05 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1])
by xenon22.um.es (Postfix) with ESMTP id 9242A171B
for <abfab@ietf.org>; Fri, 7 Aug 2015 12:37:03 +0200 (CEST)
X-Virus-Scanned: by antispam in UMU at xenon22.um.es
Received: from xenon22.um.es ([127.0.0.1])
by localhost (xenon22.um.es [127.0.0.1]) (amavisd-new, port 10024)
with LMTP id loNk6Bko2xY2 for <abfab@ietf.org>;
Fri, 7 Aug 2015 12:37:03 +0200 (CEST)
Received: from [10.42.0.179] (84.121.18.25.dyn.user.ono.com [84.121.18.25])
(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
(No client certificate requested) (Authenticated sender: alex)
by xenon22.um.es (Postfix) with ESMTPSA id 5E05A9DD
for <abfab@ietf.org>; Fri, 7 Aug 2015 12:37:02 +0200 (CEST)
To: abfab@ietf.org
References: <20150807103108.31573.9033.idtracker@ietfa.amsl.com>
From: =?UTF-8?Q?Alejandro_P=c3=a9rez_M=c3=a9ndez?= <alex@um.es>
Message-ID: <55C48A4D.2020403@um.es>
Date: Fri, 7 Aug 2015 12:37:01 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101
Thunderbird/38.1.0
MIME-Version: 1.0
In-Reply-To: <20150807103108.31573.9033.idtracker@ietfa.amsl.com>
Content-Type: multipart/alternative;
boundary="------------050903080200050401080301"
Archived-At: <http://mailarchive.ietf.org/arch/msg/abfab/t8kjGUWZ0HX2a8bxF5WLABOmKrs>
Subject: Re: [abfab] I-D Action: draft-ietf-abfab-aaa-saml-11.txt
X-BeenThere: abfab@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Application Bridging,
Federated Authentication Beyond \(the web\)" <abfab.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/abfab>,
<mailto:abfab-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/abfab/>
List-Post: <mailto:abfab@ietf.org>
List-Help: <mailto:abfab-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/abfab>,
<mailto:abfab-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 07 Aug 2015 10:37:09 -0000
Dear all,
we have posted a new version of draft-ietf-abfab-aaa-saml, which
addresses most of the pending issues we discussed in the IETF meeting.
This version will be used to request a review from the SSTC.
The main changes include:
* Section 1: Remove mention to [I-D.jones-diameter-abfab]
* Section 1.1: Included table of terminology (similar to the one in
the ABFAB architecture I-D)
* Section 4: Inclusion of the SAML metadata extensions to represent
RADIUS names.
* Section 8: "RADIUS State Confirmation Methods" moved to "Section 6:
RADIUS State Confirmation Method Identifiers". The "sender vouches"
Confirmation Method is no longer used. Instead, the SAML V2.0
"RADIUS State" is used (i.e. urn:ietf:params:abfab:cm:user or
urn:ietf:params:abfab:cm:machine)
* Section 11. Changed the format of the IANA table describing the
RADIUS attributes, splitting Type and Ext. Type for clarity.
Regards,
Alejandro
El 07/08/15 a las 12:31, internet-drafts@ietf.org escribió:
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
> This draft is a work item of the Application Bridging for Federated Access Beyond web Working Group of the IETF.
>
> Title : A RADIUS Attribute, Binding, Profiles, Name Identifier Format, and Confirmation Methods for SAML
> Authors : Josh Howlett
> Sam Hartman
> Alejandro Perez-Mendez
> Filename : draft-ietf-abfab-aaa-saml-11.txt
> Pages : 28
> Date : 2015-08-07
>
> Abstract:
> This document describes the use of the Security Assertion Mark-up
> Language (SAML) with RADIUS in the context of the ABFAB architecture.
> It defines two RADIUS attributes, a SAML binding, a SAML name
> identifier format, two SAML profiles, and two SAML confirmation
> methods. The RADIUS attributes permit encapsulation of SAML
> assertions and protocol messages within RADIUS, allowing SAML
> entities to communicate using the binding. The two profiles describe
> the application of this binding for ABFAB authentication and
> assertion query/request, enabling a Relying Party to request
> authentication of, or assertions for, users or machines (Clients).
> These Clients may be named using a NAI name identifier format.
> Finally, the subject confirmation methods allow requests and queries
> to be issued for a previously authenticated user or machine without
> needing to explicitly identify them as the subject. These artifacts
> have been defined to permit application in AAA scenarios other than
> ABFAB, such as network access.
>
>
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-abfab-aaa-saml/
>
> There's also a htmlized version available at:
> https://tools.ietf.org/html/draft-ietf-abfab-aaa-saml-11
>
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-abfab-aaa-saml-11
>
>
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
> _______________________________________________
> abfab mailing list
> abfab@ietf.org
> https://www.ietf.org/mailman/listinfo/abfab
- [abfab] I-D Action: draft-ietf-abfab-aaa-saml-11.… internet-drafts
- Re: [abfab] I-D Action: draft-ietf-abfab-aaa-saml… Alejandro Pérez Méndez