Suggested extension

Peter Eriksson <pen@lysator.liu.se> Sun, 29 November 1992 13:13 UTC

Received: from ietf.nri.reston.va.us by IETF.CNRI.Reston.VA.US id aa04527; 29 Nov 92 8:13 EST
Received: from CNRI.RESTON.VA.US by IETF.CNRI.Reston.VA.US id aa04523; 29 Nov 92 8:13 EST
Received: from ietf.cnri.reston.va.us by CNRI.Reston.VA.US id aa05089; 29 Nov 92 8:14 EST
Received: from ietf.nri.reston.va.us by IETF.CNRI.Reston.VA.US id aa04506; 29 Nov 92 8:13 EST
Received: from CNRI.RESTON.VA.US by IETF.CNRI.Reston.VA.US id aa04502; 29 Nov 92 8:12 EST
Received: from [130.236.253.6] by CNRI.Reston.VA.US id aa05073; 29 Nov 92 8:13 EST
Received: from robert.lysator.liu.se by lysator.liu.se with SMTP (5.65c8/1.34/Lysator-3.1) id AA17567; Sun, 29 Nov 1992 14:13:18 +0100 (rfc931-sender: pen@robert.lysator.liu.se)
Received: by robert.lysator.liu.se (5.65c8/1.34/Lysator-3.1) id AA14184; Sun, 29 Nov 1992 14:13:09 +0100 (rfc931-sender: pen@robert.lysator.liu.se)
Date: Sun, 29 Nov 1992 14:13:03 -0000
X-Orig-Sender: ident-request@IETF.CNRI.Reston.VA.US
Sender: ietf-archive-request@IETF.CNRI.Reston.VA.US
From: Peter Eriksson <pen@lysator.liu.se>
To: ident@CNRI.Reston.VA.US
Subject: Suggested extension
Message-Id: <CMM.0.90.0.723042783.pen@robert.lysator.liu.se>

Why not add the following extension to the IDENT protocol:

Allow a query of the form:

	<port-on-server> , <port-on-client> , <remote-address> , <password>

in addition to the old <port-on-server> , <port-on-client> pair. And then 
selected hosts (according to a config file or something) can be
allowed to issue requests according to the one above to query an Ident
server about connections that it isn't part of. I would also like to
have a new error message "ACCESS-DENIED" to be used when a host not in
the config file issues an extended query.

An example:

	Say we have a host B (that runs an Ident server) on a network.
To that same network we also have host A that runs some kind of
network monitoring software set up so that it monitors all TCP
connections between host B and the rest of the world. Now with the
above extension one could configure the Ident server on host B to
allow host A to query it about which user id it was that originated
a certain connection.

/Peter


Peter Eriksson                                              pen@lysator.liu.se
Lysator Academic Computer Society                 ...!uunet!lysator.liu.se!pen
University of Linkoping, Sweden                I'm still bored. Flame me again.