Protocol Action: 'LDAP 'Who am I?' Operation' to Proposed Standard

The IESG <iesg-secretary@ietf.org> Fri, 31 December 2004 16:02 UTC

Received: from ietf-mx.ietf.org (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA06560; Fri, 31 Dec 2004 11:02:08 -0500 (EST)
Received: from megatron.ietf.org ([132.151.6.71]) by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1CkPPj-00035h-J8; Fri, 31 Dec 2004 11:14:07 -0500
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1CkP59-0006O8-5o; Fri, 31 Dec 2004 10:52:51 -0500
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1CkP0B-0004hE-Fj; Fri, 31 Dec 2004 10:47:43 -0500
Received: from ietf-mx.ietf.org (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA05410; Fri, 31 Dec 2004 10:47:41 -0500 (EST)
Received: from megatron.ietf.org ([132.151.6.71]) by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1CkPBk-0002d9-I6; Fri, 31 Dec 2004 10:59:40 -0500
Received: from apache by megatron.ietf.org with local (Exim 4.32) id 1CkOqI-0002ku-T7; Fri, 31 Dec 2004 10:37:30 -0500
X-test-idtracker: no
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
Message-Id: <E1CkOqI-0002ku-T7@megatron.ietf.org>
Date: Fri, 31 Dec 2004 10:37:30 -0500
X-Spam-Score: 0.0 (/)
X-Scan-Signature: a7d6aff76b15f3f56fcb94490e1052e4
Cc: Internet Architecture Board <iab@iab.org>, RFC Editor <rfc-editor@rfc-editor.org>
Subject: Protocol Action: 'LDAP 'Who am I?' Operation' to Proposed Standard
X-BeenThere: ietf-announce@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: ietf-announce.ietf.org
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ietf-announce>, <mailto:ietf-announce-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ietf-announce@ietf.org>
List-Help: <mailto:ietf-announce-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ietf-announce>, <mailto:ietf-announce-request@ietf.org?subject=subscribe>
Sender: ietf-announce-bounces@ietf.org
Errors-To: ietf-announce-bounces@ietf.org
X-Spam-Score: 0.0 (/)
X-Scan-Signature: c1c65599517f9ac32519d043c37c5336

The IESG has approved the following document:

- 'LDAP 'Who am I?' Operation '
   <draft-zeilenga-ldap-authzid-10.txt> as a Proposed Standard

This document has been reviewed in the IETF but is not the product of an
IETF Working Group. 

The IESG contact person is Ted Hardie.

Technical Summary

This document describes a mechanism for Lightweight Directory
Access Protocol (LDAP) clients to obtain the authorization identity
the server uses for them.  This mechanism, called "Who am I"
which the server has associated with the user or application entity.
This replaces the AUTHCTL mechanism, which uses Bind request and 
response controls to request and return the authorization identity.  
Bind controls are not protected by the security layers established by the 
Bind operation which they are transferred as part of.   An extended operation sent after a Bind operation is protected by the security layers established by the Bind operation.

This mechanism will also be used in cases where  the
authorization identity is requested seperately  from the Bind operation.  
For example, the "Who am I?" operation can be augmented with a Proxied 
Authorization Control [PROXYCTL] to determine the authorization identity 
which the server associates with the identity asserted in the Proxied Authorization
Control.  The "Who am I?" operation can also be used prior to the Bind
operation.

Working Group Summary
  
This was not a WG document, but has been discussed on various
mailing lists (LDAPEXT, LDAPBIS, etc.)  The only issue raised during
last call was whether this was suffciently distinguished from
draft-weltman-ldapv3-auth-response-09.txt, and this issue has been
resolved.

  
Protocol Quality
  
This document has been reviewed for the IESG by Ted Hardie.


_______________________________________________
IETF-Announce mailing list
IETF-Announce@ietf.org
https://www1.ietf.org/mailman/listinfo/ietf-announce