Re: [kitten] I-D Action: draft-ietf-kitten-sasl-openid-07.txt

Eliot Lear <lear@cisco.com> Wed, 23 November 2011 14:18 UTC

Return-Path: <lear@cisco.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9E3F521F8B5E for <kitten@ietfa.amsl.com>; Wed, 23 Nov 2011 06:18:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -109.066
X-Spam-Level:
X-Spam-Status: No, score=-109.066 tagged_above=-999 required=5 tests=[AWL=0.240, BAYES_00=-2.599, HTML_MESSAGE=0.001, MISSING_HEADERS=1.292, RCVD_IN_DNSWL_HI=-8, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TCLhWrTbXHaA for <kitten@ietfa.amsl.com>; Wed, 23 Nov 2011 06:18:37 -0800 (PST)
Received: from ams-iport-1.cisco.com (ams-iport-1.cisco.com [144.254.224.140]) by ietfa.amsl.com (Postfix) with ESMTP id 7B83221F8B6E for <kitten@ietf.org>; Wed, 23 Nov 2011 06:18:36 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=lear@cisco.com; l=5212; q=dns/txt; s=iport; t=1322057916; x=1323267516; h=message-id:date:from:mime-version:cc:subject:references: in-reply-to; bh=tLHj+g9faB7rBje80QM58Jgxynn+YSBByaYvyWV5h4k=; b=CEA5rekIG2ueG4y7141qNJZgyuF5KsnZeFgmeKAPr6XnfHTwHBtpBgKo IK/XbQZeMBBThcRteal1MOcE+bKg5YIl4MKGsG2417kax9WV7qraIlPGO /s+qRNpZD1K2wTV9HrsU9qCYU4l+cDJuN7+pMo7lK9wqWUVZs/gXl6L0N E=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: ApsMAI4AzU6Q/khM/2dsb2JhbAA7CYUBpGmBAYEFgXIBAQEEAQEBDwEQBEcLEAsEFAkhAgIPAhYwEwEFAgEBBRmHa5VqAYxZkWiHL4IdgRYElEiSCw
X-IronPort-AV: E=Sophos; i="4.69,559,1315180800"; d="scan'208,217"; a="122458802"
Received: from ams-core-3.cisco.com ([144.254.72.76]) by ams-iport-1.cisco.com with ESMTP; 23 Nov 2011 14:18:24 +0000
Received: from dhcp-10-61-105-144.cisco.com (dhcp-10-61-105-144.cisco.com [10.61.105.144]) by ams-core-3.cisco.com (8.14.3/8.14.3) with ESMTP id pANEIOYd005200 for <kitten@ietf.org>; Wed, 23 Nov 2011 14:18:24 GMT
Message-ID: <4ECD00AF.80409@cisco.com>
Date: Wed, 23 Nov 2011 15:18:23 +0100
From: Eliot Lear <lear@cisco.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:8.0) Gecko/20111105 Thunderbird/8.0
MIME-Version: 1.0
CC: kitten@ietf.org
References: <20111123141250.14132.8999.idtracker@ietfa.amsl.com>
In-Reply-To: <20111123141250.14132.8999.idtracker@ietfa.amsl.com>
X-Enigmail-Version: 1.3.3
Content-Type: multipart/alternative; boundary="------------000003050806000906000608"
Subject: Re: [kitten] I-D Action: draft-ietf-kitten-sasl-openid-07.txt
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Nov 2011 14:18:37 -0000

Hi,

This version addresses the following issues that were raised in various
reviews, as discussed in Taipei:

  * Reference instead of copy OpenID specification;
  * Replace URIs for OpenID spec, as requested by OpenID foundation
  * Add explanation for transaction ID
  * Use HTTPS
  * Update references (3920->6120)
  * XRIs MUST NOT be used
  * Tighten security considerations.


Eliot

On 11/23/11 3:12 PM, internet-drafts@ietf.org wrote:
> A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Common Authentication Technology Next Generation Working Group of the IETF.
>
> 	Title           : A SASL & GSS-API Mechanism for OpenID
> 	Author(s)       : Eliot Lear
>                           Hannes Tschofenig
>                           Henry Mauldin
>                           Simon Josefsson
> 	Filename        : draft-ietf-kitten-sasl-openid-07.txt
> 	Pages           : 23
> 	Date            : 2011-11-23
>
>    OpenID has found its usage on the Internet for Web Single Sign-On.
>    Simple Authentication and Security Layer (SASL) and the Generic
>    Security Service Application Program Interface (GSS-API) are
>    application frameworks to generalize authentication.  This memo
>    specifies a SASL and GSS-API mechanism for OpenID that allows the
>    integration of existing OpenID Identity Providers with applications
>    using SASL and GSS-API.
>
>
> A URL for this Internet-Draft is:
> http://www.ietf.org/internet-drafts/draft-ietf-kitten-sasl-openid-07.txt
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
> This Internet-Draft can be retrieved at:
> ftp://ftp.ietf.org/internet-drafts/draft-ietf-kitten-sasl-openid-07.txt
>
> _______________________________________________
> Kitten mailing list
> Kitten@ietf.org
> https://www.ietf.org/mailman/listinfo/kitten
>