Re: [Isms] SSHSMRADIUSIntegrationdraft(draft-narayan-isms-sshsm-radius-01.txt)submitted

Juergen Schoenwaelder <j.schoenwaelder@iu-bremen.de> Fri, 16 March 2007 08:47 UTC

Return-path: <isms-bounces@lists.ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1HS866-0004R1-QY; Fri, 16 Mar 2007 04:47:38 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HS865-0004Qa-C8 for isms@ietf.org; Fri, 16 Mar 2007 04:47:37 -0400
Received: from hermes.iu-bremen.de ([212.201.44.23]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HS864-0007w4-2C for isms@ietf.org; Fri, 16 Mar 2007 04:47:37 -0400
Received: from localhost (demetrius.iu-bremen.de [212.201.44.32]) by hermes.iu-bremen.de (Postfix) with ESMTP id 25D1C6D9DC; Fri, 16 Mar 2007 09:47:29 +0100 (CET)
Received: from hermes.iu-bremen.de ([212.201.44.23]) by localhost (demetrius.iu-bremen.de [212.201.44.32]) (amavisd-new, port 10024) with ESMTP id 29011-02; Fri, 16 Mar 2007 09:47:25 +0100 (CET)
Received: from elstar.iuhb02.iu-bremen.de (elstar.iuhb02.iu-bremen.de [10.50.231.133]) by hermes.iu-bremen.de (Postfix) with ESMTP id BCA7F6D9FF; Fri, 16 Mar 2007 09:47:25 +0100 (CET)
Received: by elstar.iuhb02.iu-bremen.de (Postfix, from userid 501) id 8CF461E896F; Fri, 16 Mar 2007 09:47:24 +0100 (CET)
Date: Fri, 16 Mar 2007 09:47:24 +0100
From: Juergen Schoenwaelder <j.schoenwaelder@iu-bremen.de>
To: "Kaushik Narayan (kaushik)" <kaushik@cisco.com>
Subject: Re: [Isms] SSHSMRADIUSIntegrationdraft(draft-narayan-isms-sshsm-radius-01.txt)submitted
Message-ID: <20070316084724.GE759@elstar.iuhb02.iu-bremen.de>
Mail-Followup-To: "Kaushik Narayan (kaushik)" <kaushik@cisco.com>, David Harrington <ietfdbh@comcast.net>, "David B. Nelson" <d.b.nelson@comcast.net>, isms@ietf.org
References: <01df01c7670b$4eb38ec0$0600a8c0@china.huawei.com> <618694EF0B657246A4D55A97E38274C3032CC615@xmb-sjc-22d.amer.cisco.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <618694EF0B657246A4D55A97E38274C3032CC615@xmb-sjc-22d.amer.cisco.com>
User-Agent: Mutt/1.5.14 (2007-02-12)
X-Virus-Scanned: amavisd-new 2.3.3 (20050822) at iu-bremen.de
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 93238566e09e6e262849b4f805833007
Cc: isms@ietf.org
X-BeenThere: isms@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
Reply-To: j.schoenwaelder@iu-bremen.de
List-Id: Mailing list for the ISMS working group <isms.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/isms>, <mailto:isms-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/isms>
List-Post: <mailto:isms@lists.ietf.org>
List-Help: <mailto:isms-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/isms>, <mailto:isms-request@lists.ietf.org?subject=subscribe>
Errors-To: isms-bounces@lists.ietf.org

On Thu, Mar 15, 2007 at 04:04:23PM -0700, Kaushik Narayan (kaushik) wrote:

> [...] A critical feature of USM, not provided by SSH or TLS or
> RADIUS proposals so far, is local authentication with NO ties to a
> third party authenticator.

Isn't a locally stored password or key pair providing just exactly
that feature?

Anyway, I am in general quite confused by this thread as it seems that
people talk about different things without really trying to understand
the other's background / terminology / view of the world.

Perhaps it helps to go through the RADIUS document and to bring up
paragraphs that are considered problematic and to propose alternative
text fragments so that we avoid getting trapped in some general and
abstract discussions that we had in the past and which might not be
effective to improve our documents.

/js

-- 
Juergen Schoenwaelder		 Jacobs University Bremen
<http://www.eecs.iu-bremen.de/>	 P.O. Box 750 561, 28725 Bremen, Germany

_______________________________________________
Isms mailing list
Isms@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/isms