I-D Action: draft-iab-identifier-comparison-08.txt

internet-drafts@ietf.org Sun, 24 February 2013 00:03 UTC

Return-Path: <internet-drafts@ietf.org>
X-Original-To: i-d-announce@ietfa.amsl.com
Delivered-To: i-d-announce@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 815DB21F8B8F; Sat, 23 Feb 2013 16:03:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.403
X-Spam-Level:
X-Spam-Status: No, score=-102.403 tagged_above=-999 required=5 tests=[AWL=0.196, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id O6dmCnV5BB4j; Sat, 23 Feb 2013 16:03:20 -0800 (PST)
Received: from ietfa.amsl.com (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D2B4D21F8EBF; Sat, 23 Feb 2013 16:03:19 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
Subject: I-D Action: draft-iab-identifier-comparison-08.txt
X-Test-IDTracker: no
X-IETF-IDTracker: 4.40
Message-ID: <20130224000319.18126.31805.idtracker@ietfa.amsl.com>
Date: Sat, 23 Feb 2013 16:03:19 -0800
Cc: iab@iab.org
X-BeenThere: i-d-announce@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: internet-drafts@ietf.org
List-Id: Internet Draft Announcements only <i-d-announce.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/i-d-announce>, <mailto:i-d-announce-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/i-d-announce>
List-Post: <mailto:i-d-announce@ietf.org>
List-Help: <mailto:i-d-announce-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/i-d-announce>, <mailto:i-d-announce-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 24 Feb 2013 00:03:20 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Internet Architecture Board Working Group of the IETF.

	Title           : Issues in Identifier Comparison for Security Purposes
	Author(s)       : Dave Thaler
	Filename        : draft-iab-identifier-comparison-08.txt
	Pages           : 25
	Date            : 2013-02-23

Abstract:
   Identifiers such as hostnames, URIs, IP addresses, and email
   addresses are often used in security contexts to identify security
   principals and resources.  In such contexts, an identifier supplied
   via some protocol is often compared using some policy to make
   security decisions such as whether the security principal may access
   the resource, what level of authentication or encryption is required,
   etc.  If the parties involved in a security decision use different
   algorithms to compare identifiers, then failure scenarios ranging
   from denial of service to elevation of privilege can result.  This
   document provides a discussion of these issues that designers should
   consider when defining identifiers and protocols, and when
   constructing architectures that use multiple protocols.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-iab-identifier-comparison

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-iab-identifier-comparison-08

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=draft-iab-identifier-comparison-08


Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/