Re: [KAML] Reminder: BOF proposals to me by October 1

"Henry B. Hotz" <hotz@jpl.nasa.gov> Thu, 27 September 2007 18:55 UTC

Return-path: <kaml-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1IayWI-0004Ac-1z; Thu, 27 Sep 2007 14:55:30 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1IayWH-00049L-2Y for kaml@ietf.org; Thu, 27 Sep 2007 14:55:29 -0400
Received: from nmta3.jpl.nasa.gov ([137.78.160.108]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1IayWA-0007nY-7t for kaml@ietf.org; Thu, 27 Sep 2007 14:55:29 -0400
Received: from xmta1.jpl.nasa.gov (xmta1.jpl.nasa.gov [137.78.160.144]) by nmta3.jpl.nasa.gov (Switch-3.2.6/Switch-3.2.6) with ESMTP id l8RIt657019271; Thu, 27 Sep 2007 11:55:06 -0700
Received: from [192.168.2.2] (vpn-149-242-026.jpl.nasa.gov [128.149.242.26]) by xmta1.jpl.nasa.gov (Switch-3.2.6/Switch-3.2.6) with ESMTP id l8RIt4p5029230; Thu, 27 Sep 2007 11:55:04 -0700
In-Reply-To: <0E2D64FCAEB5C5458A494DC28270548E06EFBE96@Netmail1.exostar.com>
References: <0E2D64FCAEB5C5458A494DC28270548E06EFBE96@Netmail1.exostar.com>
Mime-Version: 1.0 (Apple Message framework v752.3)
Content-Type: text/plain; charset="US-ASCII"; delsp="yes"; format="flowed"
Message-Id: <F88F4F1A-4B37-41BF-99EA-8CB0A13A765D@jpl.nasa.gov>
Content-Transfer-Encoding: 7bit
From: "Henry B. Hotz" <hotz@jpl.nasa.gov>
Subject: Re: [KAML] Reminder: BOF proposals to me by October 1
Date: Thu, 27 Sep 2007 11:55:01 -0700
To: Paul Rabinovich <Paul.Rabinovich@exostar.com>
X-Mailer: Apple Mail (2.752.3)
X-Source-IP: vpn-149-242-026.jpl.nasa.gov [128.149.242.26]
X-Source-Sender: hotz@jpl.nasa.gov
X-AUTH: Authorized
X-Spam-Score: -4.0 (----)
X-Scan-Signature: 8b431ad66d60be2d47c7bfeb879db82c
Cc: kaml@ietf.org
X-BeenThere: kaml@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Discussions about SAML and Kerberos intersections <kaml.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/kaml>, <mailto:kaml-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/kaml>
List-Post: <mailto:kaml@ietf.org>
List-Help: <mailto:kaml-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/kaml>, <mailto:kaml-request@ietf.org?subject=subscribe>
Errors-To: kaml-bounces@ietf.org

Not yet in a position to evaluate any proposal against possible real  
usage.  Please post times for IETF discussions, though.

On Sep 27, 2007, at 7:42 AM, Paul Rabinovich wrote:

>
> 	Leif,
>
> 	Based on your feedback I'll hold off sending my proposal as an I-D.
>
> 	Regards,
> 	PR
>
> Paul Rabinovich | Software Architect | EXOSTAR LLC
> 13530 Dulles Technology Dr., Suite 200, Herndon, VA 20171
>
> PH +1.703.793.7808 | FAX +1.703.793.7741
>
> -----Original Message-----
> From: Tom Scavo [mailto:trscavo@gmail.com]
> Sent: Tuesday, September 25, 2007 5:53 PM
> To: Leif Johansson
> Cc: Paul Rabinovich; kaml@ietf.org
> Subject: Re: [KAML] Reminder: BOF proposals to me by October 1
>
> On 9/25/07, Leif Johansson <leifj@it.su.se> wrote:
>> Paul Rabinovich wrote:
>>>
>>>       IMO it's preferable to keep the LoA piece under the  
>>> Kerberos WG
>>> rather than under the KAML WG since - in the short-term - out-of- 
>>> the-box
>>> SAML 2.0 seems not to be able to help with LoA. Whatever we design,
> however,
>>>
>> I think you are wrong. There are at least two ways to model LoA
>> using SAML - using an AC class or using an attribute.
>
> That's correct.  If you decide to use AuthnContext, that means the
> Kerberos-bound SAML assertion would contain an AuthnStatement.  On the
> other hand, an Attribute would require an AttributeStatement.
> (Personally, I think AuthnContext is the way to go for LoA, but the
> jury's still out on that issue.)
>
> Tom
------------------------------------------------------------------------
The opinions expressed in this message are mine,
not those of Caltech, JPL, NASA, or the US Government.
Henry.B.Hotz@jpl.nasa.gov, or hbhotz@oxy.edu



_______________________________________________
KAML mailing list
KAML@ietf.org
https://www1.ietf.org/mailman/listinfo/kaml