Re: [nfsv4] Fwd: New Version Notification for draft-haynes-nfsv4-flex-filesv2-00.txt

Benjamin Kaduk <kaduk@mit.edu> Tue, 08 August 2017 19:49 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: nfsv4@ietfa.amsl.com
Delivered-To: nfsv4@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 69A14132492 for <nfsv4@ietfa.amsl.com>; Tue, 8 Aug 2017 12:49:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level:
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qGLTJqhEU6lv for <nfsv4@ietfa.amsl.com>; Tue, 8 Aug 2017 12:49:22 -0700 (PDT)
Received: from dmz-mailsec-scanner-7.mit.edu (dmz-mailsec-scanner-7.mit.edu [18.7.68.36]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 20A631324D7 for <nfsv4@ietf.org>; Tue, 8 Aug 2017 12:49:22 -0700 (PDT)
X-AuditID: 12074424-ddfff70000007e0a-88-598a15c0afc8
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-7.mit.edu (Symantec Messaging Gateway) with SMTP id 71.A9.32266.0C51A895; Tue, 8 Aug 2017 15:49:21 -0400 (EDT)
Received: from outgoing.mit.edu (OUTGOING-AUTH-1.MIT.EDU [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id v78JnJ41032028; Tue, 8 Aug 2017 15:49:20 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v78JnGMp020042 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Tue, 8 Aug 2017 15:49:18 -0400
Date: Tue, 8 Aug 2017 14:49:16 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: Trond Myklebust <trondmy@gmail.com>
Cc: Olga Kornievskaia <aglo@citi.umich.edu>, "nfsv4@ietf.org" <nfsv4@ietf.org>, Thomas Haynes <loghyr@primarydata.com>
Message-ID: <20170808194916.GR70977@kduck.kaduk.org>
References: <150215110527.12392.18161698955589691126.idtracker@ietfa.amsl.com> <2CA259E3-BD3A-482B-BFBF-3B90425AD3EA@primarydata.com> <CAN-5tyETNMCPVC5wJ-_77vM5+hVB+-uasd37kn+M=hoCeK6P7w@mail.gmail.com> <CAABAsM6rmrDU4BR6Ho7YFjjYA2amEkwuRGtzN537VXUZ-Eh-hg@mail.gmail.com> <20170808185803.GQ70977@kduck.kaduk.org> <CAABAsM7xOpbopPa3v1YMtfcFZbNZ=Jygap37Bg6qGfDDAvRHhQ@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <CAABAsM7xOpbopPa3v1YMtfcFZbNZ=Jygap37Bg6qGfDDAvRHhQ@mail.gmail.com>
User-Agent: Mutt/1.8.3 (2017-05-23)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrHIsWRmVeSWpSXmKPExsUixCmqrHtQtCvS4N9KJou1j56yWyzfs5Xd Yvb7R6wW9x5/ZXVg8VjT2snisXPWXXaPJUt+MnnMnysXwBLFZZOSmpNZllqkb5fAldE06xxL wRquiitXTjI1MK7h6GLk5JAQMJF48W4BG4gtJLCYSeLvneIuRi4gewOjxPsPa9ghnCtMEhMe XmAFqWIRUJH4evoBC4jNBmQ3dF9mBrFFBNQlend8BYszC9RLvPvQwA5iCwvES6yf/ZQRxOYF 2ra3ZTsbxNB2ZokTX/qZIBKCEidnPoFq1pK48e8lUJwDyJaWWP4P7FJOgUCJmfuvgpWLCihL zNu3im0Co8AsJN2zkHTPQuhewMi8ilE2JbdKNzcxM6c4NVm3ODkxLy+1SNdcLzezRC81pXQT IyiY2V1UdjB293gfYhTgYFTi4b2xpzNSiDWxrLgy9xCjJAeTkijvJm2gEF9SfkplRmJxRnxR aU5q8SFGCQ5mJRFeFWAMCfGmJFZWpRblw6SkOViUxHnFNRojhATSE0tSs1NTC1KLYLIyHBxK ErxnRIAaBYtS01Mr0jJzShDSTBycIMN5gIabgw0vLkjMLc5Mh8ifYlSUEueVAmkWAElklObB 9YKSjUT2/ppXjOJArwjzyoJU8QATFVz3K6DBTECDI3w7QQaXJCKkpBoYhVzt2762W5j2qz/c v2maluYThaQryrlhtv/r3fbdEu8tD1fk0pZQ2xR9NHaW3Om3xU++zuMROfBMZ6vkce5JxYkr czWjj+4M+6pV+eqeif0EeZPJolVnAvsezqicuHn2feljmd3/jvtd/HcnK0EgSmhHX/2scqHi ysnzrVVYY1J2zCj4oLpLiaU4I9FQi7moOBEAQN07rBEDAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/nfsv4/GGqvg4nyz7I7BSTrepD5zUO2aBA>
Subject: Re: [nfsv4] Fwd: New Version Notification for draft-haynes-nfsv4-flex-filesv2-00.txt
X-BeenThere: nfsv4@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: NFSv4 Working Group <nfsv4.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/nfsv4>, <mailto:nfsv4-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/nfsv4/>
List-Post: <mailto:nfsv4@ietf.org>
List-Help: <mailto:nfsv4-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/nfsv4>, <mailto:nfsv4-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Aug 2017 19:49:23 -0000

On Tue, Aug 08, 2017 at 03:37:41PM -0400, Trond Myklebust wrote:
> On 8 August 2017 at 14:58, Benjamin Kaduk <kaduk@mit.edu> wrote:
> 
> > On Tue, Aug 08, 2017 at 02:54:58PM -0400, Trond Myklebust wrote:
> > > Why pass Kerberos tickets around? Is there any reason not to just pass an
> > > initialised RPCSEC_GSS session handle?
> >
> > There's not a standard serialization of the GSS security context object
> > that it contains, for transfer across the network.
> >
> 
> I thought rfc1964 provides one, which is pretty much the basis for the user
> library gss_krb5_lucid_context_v1_t typedef. Am I mistaken?

I only see formats for security context establishment (negotiation) tokens,
which are exchanged so that the peers can establish a complete security
context -- I think you're mistaken.

AIUI the gss_krb5 lucid contexts came about due to the need to establish
a GSS security context in userspace and then export the keying material
into the kernel for per-message processing (for NFS).  I'm only about 95%
sure, but the information from a lucid context ought to be enough to
send from MDS to client and let the client use RPCSEC_GSSv3.  The
lucid context is a per-implementation extension, though, and we can't
use it in our standard without standardizing the lucid context first.

-Ben