Re: [kitten] AuthorizationData Type registry?

Benjamin Kaduk <kaduk@MIT.EDU> Wed, 11 March 2015 15:39 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5AB931A8971 for <kitten@ietfa.amsl.com>; Wed, 11 Mar 2015 08:39:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.611
X-Spam-Level:
X-Spam-Status: No, score=-3.611 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, J_CHICKENPOX_52=0.6, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EXmIsSKlq4m1 for <kitten@ietfa.amsl.com>; Wed, 11 Mar 2015 08:39:18 -0700 (PDT)
Received: from dmz-mailsec-scanner-4.mit.edu (dmz-mailsec-scanner-4.mit.edu [18.9.25.15]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 358D61A0222 for <kitten@ietf.org>; Wed, 11 Mar 2015 08:39:18 -0700 (PDT)
X-AuditID: 1209190f-f79546d000007593-57-550061a563d7
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-4.mit.edu (Symantec Messaging Gateway) with SMTP id 7C.04.30099.5A160055; Wed, 11 Mar 2015 11:39:17 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id t2BFdGuu016273; Wed, 11 Mar 2015 11:39:16 -0400
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t2BFdEjI005015 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 11 Mar 2015 11:39:15 -0400
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t2BFdEgW004096; Wed, 11 Mar 2015 11:39:14 -0400 (EDT)
Date: Wed, 11 Mar 2015 11:39:14 -0400
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: "Stefan (metze) Metzmacher" <metze@samba.org>
In-Reply-To: <550056FF.80706@samba.org>
Message-ID: <alpine.GSO.1.10.1503111137130.3953@multics.mit.edu>
References: <550056FF.80706@samba.org>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrDIsWRmVeSWpSXmKPExsUixG6nors0kSHUYM9Zboujm1exWFxc9pPF gcljyZKfTB5zd/UxBjBFcdmkpOZklqUW6dslcGUcWP+AqeAhZ0XjgY+sDYzTOLoYOTkkBEwk HizfwAphi0lcuLeerYuRi0NIYDGTxISb5xlBEkICGxklZi5xgEgcYpLoeLiHBcJpYJRYt/wo G0gVi4C2xO0/r1lAbDYBFYmZbzaCxUUEDCUufn0PNolZQF3i25k3YLawgJnEhHW7mEBsTqD4 tcmNQGdwcPAKOEhM+28IsVhN4s6mhWAjRQV0JFbvnwJm8woISpyc+YQFYqSWxPLp21gmMArO QpKahSS1gJFpFaNsSm6Vbm5iZk5xarJucXJiXl5qka6JXm5miV5qSukmRlCgckry72D8dlDp EKMAB6MSD++MWf9DhFgTy4orcw8xSnIwKYny3gljCBXiS8pPqcxILM6ILyrNSS0+xCjBwawk wrsjECjHm5JYWZValA+TkuZgURLn3fSDL0RIID2xJDU7NbUgtQgmK8PBoSTBezgBqFGwKDU9 tSItM6cEIc3EwQkynAdo+GWQGt7igsTc4sx0iPwpRkUpcd5VIAkBkERGaR5cLyyRvGIUB3pF mHcaSBUPMAnBdb8CGswENJjFGuhJ3uKSRISUVANj1o11rsmW3F9+Hg7V8ty3vvT3n0CZRw7/ 40Mfm5Q9DT60IE35aP7Ke+ev2x5+9vK8VFbc07wH59Z4/5OL7qxeNXtN9II+sR3FcQ7XvrG1 nw00T0y1j7h7r8CnSm9xbjL3wbbu5+u3cDSf6GP8uduj8Hzn9LAtwd+evYrMjn5+IahzLf8j oekvlFiKMxINtZiLihMBTjkZCf8CAAA=
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/4UckjbgF_27vZSgqa3bJgBbqq2M>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] AuthorizationData Type registry?
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Mar 2015 15:39:23 -0000

On Wed, 11 Mar 2015, Stefan (metze) Metzmacher wrote:

> Hi,
>
> I'm wondering if there's a place where AuthorizationData types
> are listed. rfc4120.txt hash section "7.5.4.  Authorization Data Types",
> but there're a lot a values missing.
>
> E.g. 142 was used by early MIT and Heimdal releases for
> KRB5-AUTHDATA-SIGNTICKET,
> it seems this got renumbered to 512 because [MS-KILE] has
> KERB-AD-RESTRICTION-ENTRY (141) and KERB-LOCAL (142).
>
> For "Pre-Authentication and Typed Data" there's a much better list, e.g.
> in rfc6113.txt section "7.1.  Pre-Authentication and Typed Data".
> This seems to be the current list:
> http://www.iana.org/assignments/kerberos-parameters/kerberos-parameters.xhtml#pre-authentication
>
> But
> http://www.iana.org/assignments/kerberos-parameters/kerberos-parameters.xhtml
> doesn't
> list AuthorizationData types.

The document
https://tools.ietf.org/html/draft-ietf-kitten-kerberos-iana-registries-03
proposes to move control of this number space over to IANA, but that
document has been lingering around due to lack of WG energy.

Its author (Tom Yu) currently maintains a local registry for many Kerberos
numbers which have not yet been transitioned to IANA.

-Ben Kaduk