I-D Action: draft-iab-identifier-comparison-07.txt

internet-drafts@ietf.org Mon, 17 December 2012 16:45 UTC

Return-Path: <internet-drafts@ietf.org>
X-Original-To: i-d-announce@ietfa.amsl.com
Delivered-To: i-d-announce@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3FD2421F8B8F; Mon, 17 Dec 2012 08:45:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.533
X-Spam-Level:
X-Spam-Status: No, score=-102.533 tagged_above=-999 required=5 tests=[AWL=0.066, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9eDrqX5Ot6T0; Mon, 17 Dec 2012 08:45:46 -0800 (PST)
Received: from ietfa.amsl.com (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE33421F8B7F; Mon, 17 Dec 2012 08:45:46 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
Subject: I-D Action: draft-iab-identifier-comparison-07.txt
X-Test-IDTracker: no
X-IETF-IDTracker: 4.37
Message-ID: <20121217164546.25185.71472.idtracker@ietfa.amsl.com>
Date: Mon, 17 Dec 2012 08:45:46 -0800
Cc: iab@iab.org
X-BeenThere: i-d-announce@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: internet-drafts@ietf.org
List-Id: Internet Draft Announcements only <i-d-announce.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/i-d-announce>, <mailto:i-d-announce-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/i-d-announce>
List-Post: <mailto:i-d-announce@ietf.org>
List-Help: <mailto:i-d-announce-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/i-d-announce>, <mailto:i-d-announce-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Dec 2012 16:45:47 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Internet Architecture Board Working Group of the IETF.

	Title           : Issues in Identifier Comparison for Security Purposes
	Author(s)       : Dave Thaler
	Filename        : draft-iab-identifier-comparison-07.txt
	Pages           : 24
	Date            : 2012-12-17

Abstract:
   Identifiers such as hostnames, URIs, and email addresses are often
   used in security contexts to identify security principals and
   resources.  In such contexts, an identifier supplied via some
   protocol is often compared against some policy to make security
   decisions such as whether the principal may access the resource, what
   level of authentication or encryption is required, etc.  If the
   parties involved in a security decision use different algorithms to
   compare identifiers, then failure scenarios ranging from denial of
   service to elevation of privilege can result.  This document provides
   a discussion of these issues that designers should consider when
   defining identifiers and protocols, and when constructing
   architectures that use multiple protocols.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-iab-identifier-comparison

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-iab-identifier-comparison-07

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=draft-iab-identifier-comparison-07


Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/