Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv3: request for review
Benjamin Kaduk <kaduk@MIT.EDU> Mon, 04 August 2014 20:01 UTC
Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1FAE01A028A; Mon, 4 Aug 2014 13:01:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.202
X-Spam-Level:
X-Spam-Status: No, score=-4.202 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ss0I-JyUWTaj; Mon, 4 Aug 2014 13:01:22 -0700 (PDT)
Received: from dmz-mailsec-scanner-7.mit.edu (dmz-mailsec-scanner-7.mit.edu [18.7.68.36]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 20C801A020A; Mon, 4 Aug 2014 13:01:22 -0700 (PDT)
X-AuditID: 12074424-f79146d00000067c-27-53dfe690adcc
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-7.mit.edu (Symantec Messaging Gateway) with SMTP id 0D.F8.01660.096EFD35; Mon, 4 Aug 2014 16:01:20 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id s74K1IFb008173; Mon, 4 Aug 2014 16:01:19 -0400
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id s74K1GwJ001912 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Mon, 4 Aug 2014 16:01:18 -0400
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id s74K1Fdk013901; Mon, 4 Aug 2014 16:01:15 -0400 (EDT)
Date: Mon, 04 Aug 2014 16:01:15 -0400
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Nico Williams <nico@cryptonector.com>
In-Reply-To: <20140804180946.GR3579@localhost>
Message-ID: <alpine.GSO.1.10.1408041555210.21571@multics.mit.edu>
References: <DC941FEB-725A-49E1-8C38-FF765454827C@netapp.com> <alpine.GSO.1.10.1407301239260.21571@multics.mit.edu> <20140801055401.GA7409@localhost> <8FD0C272-6FD3-44FE-BD3D-BAB220E0FF13@netapp.com> <20140801221535.GA3579@localhost> <DDC64AA5-C2B4-404A-A864-212A3A3AECF1@netapp.com> <20140804180946.GR3579@localhost>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: MULTIPART/MIXED; boundary="-559023410-1280839398-1407182342=:21571"
Content-ID: <alpine.GSO.1.10.1408041559090.21571@multics.mit.edu>
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrGKsWRmVeSWpSXmKPExsUixG6nojvh2f1ggzWHLC2Obl7FYjH7/SNW i1PXjrBZTF9k5cDi8fLUOUaPJUt+MnnM+PSFLYA5issmJTUnsyy1SN8ugSvjwu6VjAVThSqu 7pnK1MDYwN/FyMkhIWAi8eZgCwuELSZx4d56ti5GLg4hgdlMEptOHmSHcDYwSszoWswK4Rxk klhzYC4jSIuQQL3Ej6NLgKo4OFgEtCS6d/qChNkEVCRmvtnIBmKLCGhKXJ+3FMxmFiiT6J7W zgpiCwu4STS/+sUMYnMK6EnsmHyeCcTmFXCUmNjQyAKxaz+TxMpzc8ASogI6Eqv3T2GBKBKU ODnzCQvE0ECJiz+fsUPYjhK3eo6zTWAUmoWkbBaSsllIymYBnc0sYCaxYW82RFhb4v7NNjaY kkfL37EvYGRbxSibklulm5uYmVOcmqxbnJyYl5dapGuul5tZopeaUrqJERw9Lio7GJsPKR1i FOBgVOLhFVC7HyzEmlhWXJl7iFGSg0lJlPfeE6AQX1J+SmVGYnFGfFFpTmrxIUYJDmYlEd64 U0A53pTEyqrUonyYlDQHi5I471trq2AhgfTEktTs1NSC1CKYrAwHh5IEr+NToEbBotT01Iq0 zJwShDQTByfIcB6g4dUgNbzFBYm5xZnpEPlTjIpS4rw+IAkBkERGaR5cLyy5vWIUB3pFmLcb pIoHmBjhul8BDWYCGmymAza4JBEhJdXA2LIuI7nw8JdlvxarVP97+uNkZfrH3Zc4TmySuRfK bMl+XthklYZ96/r1x39m61yzenRhcZjUhPo3x47ZtAi6b6haaMHNvyQ90Cunc7sFd+KL5fHn Th+OyjDbKf/1l+GS6287FFbcZeZ/Ld/2x3LdnS85Hc3fVK+EJT9d5P/7kvP32AuGoqUP5iux FGckGmoxFxUnAgAcUGWASQMAAA==
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/-hu8UJVKnYKV4NsviNtw2gUqNNE
Cc: "kitten@ietf.org" <kitten@ietf.org>, "Adamson, Andy" <William.Adamson@netapp.com>, NFSv4 <nfsv4@ietf.org>
Subject: Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv3: request for review
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 04 Aug 2014 20:01:24 -0000
On Mon, 4 Aug 2014, Nico Williams wrote: > On Mon, Aug 04, 2014 at 04:55:57PM +0000, Adamson, Andy wrote: >> On Aug 1, 2014, at 6:15 PM, Nico Williams <nico@cryptonector.com> wrote: >>> (Was "multi-principal" my name for this? No, I called them compound >>> authentication. I prefer "compound”.) >> >> Hi NIco >> >> I changed the name from ‘compound’ to multi-principal’ in response >> the review comments at IETF 89 where many NFSv4 WG members expressed >> that ‘compound’ had too many meanings (especially in NFSv4.x) and >> led to confusion. > > "Compound" is used as an adjective in all cases. I don't see how > "compound authentication" (or "compound context handle", ...) is > confusable with "compound RPC". But this isn't important enough to me; > aligning the terminology with AFS' rxgk is. Ben, what does rxgk call > this? If I remember correclty from the talk from Toronto, Andy was not quite so keen to align with rxgk, but that may have been based on incomplete data. Anyway, for rxgk, we don't talk very much about the actual ~compound token; the operation itself is CombineTokens or AFSCombineTokens, with the latter being the operation which is analogous to the rpcsec case. The AFSCombineTokens case is a little convoluted, since rxgk-afs differentiates between "vlserver tokens" (roughly analogous to the MDS) and "fileserver tokens" (analogous to the DS). AFSCombineTokens takes vlserver tokens as input and produces fileserver tokens as output, so a lot of the time they are just referred to as "fileserver tokens". There are a couple places where we refer to the CombineTokens output as a "combined token", which is I think what you're looking for as an answer. That doesn't look like it translates very nicely to the rpcsec case, though. :( -Ben
- [kitten] draft-ietf-nfsv4-rpcsec-gssv3: request f… Adamson, Andy
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… J. Bruce Fields
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Benjamin Kaduk
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Benjamin Kaduk
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… J. Bruce Fields
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Adamson, Andy
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Adamson, Andy
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Adamson, Andy
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Benjamin Kaduk
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Benjamin Kaduk
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Benjamin Kaduk
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Benjamin Kaduk
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… J. Bruce Fields
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Adamson, Andy
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Adamson, Andy
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Benjamin Kaduk
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Benjamin Kaduk
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Adamson, Andy
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Benjamin Kaduk
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Benjamin Kaduk
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Adamson, Andy
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Benjamin Kaduk
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Adamson, Andy
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Adamson, Andy
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Nico Williams
- [kitten] rpcsec-gssv3 multi-principal authenticat… Benjamin Kaduk
- Re: [kitten] rpcsec-gssv3 multi-principal authent… Benjamin Kaduk
- Re: [kitten] [nfsv4] rpcsec-gssv3 multi-principal… Nico Williams
- Re: [kitten] rpcsec-gssv3 multi-principal authent… Adamson, Andy
- Re: [kitten] [nfsv4] rpcsec-gssv3 multi-principal… J. Bruce Fields
- Re: [kitten] [nfsv4] rpcsec-gssv3 multi-principal… Nico Williams
- Re: [kitten] [nfsv4] rpcsec-gssv3 multi-principal… J. Bruce Fields
- Re: [kitten] [nfsv4] rpcsec-gssv3 multi-principal… Benjamin Kaduk
- Re: [kitten] [nfsv4] rpcsec-gssv3 multi-principal… Nico Williams
- Re: [kitten] [nfsv4] rpcsec-gssv3 multi-principal… J. Bruce Fields
- Re: [kitten] rpcsec-gssv3 multi-principal authent… Benjamin Kaduk
- Re: [kitten] [nfsv4] rpcsec-gssv3 multi-principal… Benjamin Kaduk
- Re: [kitten] [nfsv4] rpcsec-gssv3 multi-principal… Nico Williams
- Re: [kitten] [nfsv4] rpcsec-gssv3 multi-principal… Adamson, Andy
- Re: [kitten] [nfsv4] rpcsec-gssv3 multi-principal… Nico Williams
- Re: [kitten] [nfsv4] rpcsec-gssv3 multi-principal… Adamson, Andy
- Re: [kitten] [nfsv4] draft-ietf-nfsv4-rpcsec-gssv… Benjamin Kaduk