Re: [abfab] Direction Forward for aaa-saml

Leif Johansson <leifj@mnt.se> Wed, 22 July 2015 15:14 UTC

Return-Path: <leifj@mnt.se>
X-Original-To: abfab@ietfa.amsl.com
Delivered-To: abfab@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 63E9A1A0210 for <abfab@ietfa.amsl.com>; Wed, 22 Jul 2015 08:14:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yKBN1t2nw-Th for <abfab@ietfa.amsl.com>; Wed, 22 Jul 2015 08:14:43 -0700 (PDT)
Received: from mail-wi0-f181.google.com (mail-wi0-f181.google.com [209.85.212.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 001D81A010C for <abfab@ietf.org>; Wed, 22 Jul 2015 08:14:42 -0700 (PDT)
Received: by wicmv11 with SMTP id mv11so85980253wic.0 for <abfab@ietf.org>; Wed, 22 Jul 2015 08:14:41 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:content-type:mime-version:subject:from :in-reply-to:date:cc:content-transfer-encoding:message-id:references :to; bh=8ep1iYmcTJGp/NLtpvqRtFSp9YXcDFOcG+eN1n2HPL8=; b=XTgS2TAQ77EXbM8nVZ+oMCXWRMrjbrfyIHojWU/r65A40gfWhKGPPOiVaSiXvhTXU7 eHePAXdSSRstcnHvX1LxOGwGv5lLlSvIiUWTDrmAn7E3A2D6Pai2mNEIrrh3pUahngvB EfoQZjZtbvbaI8po8r5mzlN24iRe6cvAgUfsMmjoyPaXJFfMuzW6LS8huij9n11DWOBz NUdmMAw55ijukHMU8fnMcAx43P2PExvB+vGazu+cgf4jC0M0LRh/8n1p7X2pgST6H5L2 WBVCGUfi+raNFz9/f9xTGi0P1Q89LnvDNzWaiTuUscLuVKza78HNJ9yMypZWRELZBGjU lGxg==
X-Gm-Message-State: ALoCoQmwEPUzeLWO3I+dsw2Lj0HVz081RnKjZCISJR3W1Exsh/vOB8RFFqdRBfVkpnUhajLCnTbA
X-Received: by 10.194.86.65 with SMTP id n1mr2749382wjz.100.1437578081575; Wed, 22 Jul 2015 08:14:41 -0700 (PDT)
Received: from [31.133.155.46] (dhcp-9b2e.meeting.ietf.org. [31.133.155.46]) by smtp.gmail.com with ESMTPSA id ev8sm2877688wjb.8.2015.07.22.08.14.40 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Wed, 22 Jul 2015 08:14:40 -0700 (PDT)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (1.0)
From: Leif Johansson <leifj@mnt.se>
X-Mailer: iPhone Mail (12H143)
In-Reply-To: <tslegk0w7iw.fsf@mit.edu>
Date: Wed, 22 Jul 2015 17:14:39 +0200
Content-Transfer-Encoding: quoted-printable
Message-Id: <1FA8CCED-221E-4A88-B525-BF46FAA53A3F@mnt.se>
References: <tslwpxsy0ql.fsf@mit.edu> <8E4E5965-0E43-4ABD-8853-8A6C7C6926C5@mnt.se> <tsloaj4xzvr.fsf@mit.edu> <0B96365A-4F6B-427A-9A87-70F069473F84@mnt.se> <tsl7fpsxrve.fsf@mit.edu> <0A08B89E-5533-4E34-9014-97C0D7877B6E@osu.edu> <tslio9cw8yd.fsf@mit.edu> <D143C9FB-F878-49C1-89C4-6A494714A3EC@mnt.se> <tslegk0w7iw.fsf@mit.edu>
To: Sam Hartman <hartmans@painless-security.com>
Archived-At: <http://mailarchive.ietf.org/arch/msg/abfab/zw0V4BuFPIWYRNPd8mg1MBAbz9U>
Cc: "abfab@ietf.org" <abfab@ietf.org>
Subject: Re: [abfab] Direction Forward for aaa-saml
X-BeenThere: abfab@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Application Bridging, Federated Authentication Beyond \(the web\)" <abfab.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/abfab>, <mailto:abfab-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/abfab/>
List-Post: <mailto:abfab@ietf.org>
List-Help: <mailto:abfab-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/abfab>, <mailto:abfab-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Jul 2015 15:14:44 -0000


22 jul 2015 kl. 17:12 skrev Sam Hartman <hartmans@painless-security.com>om>:

>>>>>> "Leif" == Leif Johansson <leifj@mnt.se> writes:
> 
>    Leif> 22 jul 2015 kl. 16:41 skrev Sam Hartman
>    Leif> <hartmans@painless-security.com>om>:
> 
>>>>>>>> "Cantor," == Cantor, Scott <cantor.2@osu.edu> writes:
>>> 
>>> Cantor,> On 7/22/15, 9:07 AM, "abfab on behalf of Sam Hartman"
>>> Cantor,> <abfab-bounces@ietf.org on behalf of Cantor,>
>>> hartmans@painless-security.com>
>>> Cantor,> wrote:
>>> 
>>> 
>>>>> 
>>>>> I think you'd need to:
>>>>> 
>>>>> 1) Explain how I figure out which entity I'm using for my
>>>>> RADIUS server
>>> 
>>>>> Consider this especially in a case where you're retrieving
>>>>> metadata dynamically rather than just having all the metadata
>>>>> in the world.
>>> 
>>> Cantor,> That's orthogonal to any use of SAML metadata. How you
>>> get Cantor,> it (and verify it) is architecturally distinct from
>>> what it Cantor,> means and how it's used.
>>> 
>>> Not really.  If I'm starting with an NAI realm and would like to
>>> find the entity description of an entity that is at that NAI
>>> realm, I can only do that if my metadata access mechanism lets me
>>> search by that.
> 
>    Leif> so its a requirement for the mdquery draft, not on metadata
> 
> Nod.
> 
> I don't anticipate implementing using metadata  to select a RADIUS
> endpoint.
> So I don't have a lot of interest in working on that.  I'm happy to
> review a specific proposal someone comes up with, but I'd prefer it not
> end up in aaa-saml and I'd strongly prefer it not block aaa-saml.
> 
> --Sam

agree but i think endpoint could be useful for radsec and i suspect it will be reasonably simple to do