Re: [KAML] latest status

"Henry B. Hotz" <> Fri, 18 September 2009 18:40 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 686163A6864 for <>; Fri, 18 Sep 2009 11:40:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -5.421
X-Spam-Status: No, score=-5.421 tagged_above=-999 required=5 tests=[AWL=1.178, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id RdpKLhx5pcxH for <>; Fri, 18 Sep 2009 11:40:13 -0700 (PDT)
Received: from ( []) by (Postfix) with ESMTP id 1F9053A67E3 for <>; Fri, 18 Sep 2009 11:40:13 -0700 (PDT)
Received: from ( []) by (Switch-3.4.1/Switch-3.3.2mp) with ESMTP id n8IIf26o011362; Fri, 18 Sep 2009 18:41:06 GMT
Received: from ( []) by (Switch-3.2.6/Switch-3.2.6) with ESMTP id n8IIf0RO008836 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NOT); Fri, 18 Sep 2009 11:41:00 -0700
Message-Id: <>
From: "Henry B. Hotz" <>
To: James Ryan <>
In-Reply-To: <>
Content-Type: text/plain; charset=US-ASCII; format=flowed; delsp=yes
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (Apple Message framework v936)
Date: Fri, 18 Sep 2009 11:41:00 -0700
References: <>
X-Mailer: Apple Mail (2.936)
X-Source-IP: []
X-AUTH: Authorized
Subject: Re: [KAML] latest status
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Discussions about SAML and Kerberos intersections <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 18 Sep 2009 18:40:14 -0000

On Sep 18, 2009, at 7:13 AM, James Ryan wrote:

> I have been unplugged on this topic for a few years.  Could someone  
> give the latest status?
> thanks!!

The short answer is that we failed to reach consensus and petered  
out.  Of course that doesn't mean the issues have gone away.  I'm not  
sure I recall all the solutions people were proposing any more.  There  
were some reasonable attempts at summaries near the end of what  
exchanges did happen on-list.

The concept that defined the name of this list was to include a SAML  
token in a ticket.  I personally opposed that because I thought it  
undesirable to mix ASN.1 and XML in the same thing.  (It's possible my  
objections are Quixotic.)

Many (most) of us wanted a way to pass on information from or about  
the original cert used in a PKINIT exchange.  Probably the simplest  
proposal of that type was Doug Engert's that the cert itself just be  
included, but people apparently felt that was excessive, and/or  
excessively distant from the information desired.

My own desire was for a way to label a ticket according to the US  
Government level of assurance that was used to acquire it.  A standard  
mechanism ought to be more general than a US standard of course.   
Unfortunately, that created unwanted complexities in defining what  
ought to be in the ticket, if it wasn't necessarily a US LOA.

The Microsoft PAC was not considered a good basis for a solution, but  
everyone wanted to remain compatible with it if it was present.

Off-list I have second- or third-hand information (unreliable  
information in other words) that NASA asked Microsoft to include the  
US LOA in the PAC as a dynamic group membership, and they agreed.  I  
also have possibly-contradictory information that Microsoft told NASA  
to work through the IETF and the Kerberos Consortium to define how the  
LOA information should be handled and they would conform to and  
implement whatever was agreed on.

Absent a better consensus, I proposed that we create a framework  
document covering how multiple representations of authorization data  
should coexist and their degree of consistency.  There did not seem to  
be any interest.

I think there is interest in solving the authorization problem in a  
way that scales better than the MS PAC.  There's interest on  
Microsoft's part as well.  Nobody's come up with a solution that  
enough people find attractive though.
The opinions expressed in this message are mine,
not those of Caltech, JPL, NASA, or the US Government., or