[OPSAWG] Local Authentication at the network device

"Satyanarayana Danda (sdanda)" <sdanda@cisco.com> Thu, 27 June 2013 11:04 UTC

Return-Path: <sdanda@cisco.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E9B1121F9CFE for <opsawg@ietfa.amsl.com>; Thu, 27 Jun 2013 04:04:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.598
X-Spam-Level:
X-Spam-Status: No, score=-10.598 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cCnxb7IcqXtY for <opsawg@ietfa.amsl.com>; Thu, 27 Jun 2013 04:04:23 -0700 (PDT)
Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) by ietfa.amsl.com (Postfix) with ESMTP id 52C5B21F9CF0 for <opsawg@ietf.org>; Thu, 27 Jun 2013 04:04:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=4500; q=dns/txt; s=iport; t=1372331063; x=1373540663; h=from:to:cc:subject:date:message-id:mime-version; bh=zzuj173JlEm1aM+ispsUCWwhCsOeneNXu2aAHW/rQkA=; b=OMye/5IkTDibGn+eA/vuMuQ9y4slRLfBG5u/Lr0XNyyikqE5Rd6a/cSF YGCxPqg+hmUo/VKtMYUFvdBy7YyJuSxMOGOJ3oy1l7MCSrkw4QNHoqq1D IdAhOsK7VJiAe/0CGdK1WfgsebzGtwJZBptkvfD6F8sbxbgYF0oa2neAD I=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AjMFAGobzFGtJXHB/2dsb2JhbABbgkVEMUm/A30WdIIlAQQtTBIBKlYmAQQODROHc7pAjyQxgwlhA6kKgxGCKA
X-IronPort-AV: E=Sophos; i="4.87,951,1363132800"; d="scan'208,217"; a="227875879"
Received: from rcdn-core2-6.cisco.com ([173.37.113.193]) by rcdn-iport-1.cisco.com with ESMTP; 27 Jun 2013 11:04:22 +0000
Received: from xhc-rcd-x13.cisco.com (xhc-rcd-x13.cisco.com [173.37.183.87]) by rcdn-core2-6.cisco.com (8.14.5/8.14.5) with ESMTP id r5RB4M2A010957 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL) for <opsawg@ietf.org>; Thu, 27 Jun 2013 11:04:22 GMT
Received: from xmb-rcd-x14.cisco.com ([169.254.4.194]) by xhc-rcd-x13.cisco.com ([173.37.183.87]) with mapi id 14.02.0318.004; Thu, 27 Jun 2013 06:04:22 -0500
From: "Satyanarayana Danda (sdanda)" <sdanda@cisco.com>
To: "opsawg@ietf.org" <opsawg@ietf.org>
Thread-Topic: Local Authentication at the network device
Thread-Index: Ac5zJhMUcRbed1sNTvi+S5IKfitR9Q==
Date: Thu, 27 Jun 2013 11:04:22 +0000
Message-ID: <E06F3B652F60A4409C49D8E840BEEC921D6940DB@xmb-rcd-x14.cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.142.105.254]
Content-Type: multipart/alternative; boundary="_000_E06F3B652F60A4409C49D8E840BEEC921D6940DBxmbrcdx14ciscoc_"
MIME-Version: 1.0
Subject: [OPSAWG] Local Authentication at the network device
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/opsawg>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 27 Jun 2013 11:04:29 -0000

Hi All,

In small enterprise deployment, instead of Remote AAA server based authentication, local authentication at the network device can be performed.
The device can have a few user authorization parameters and properties which can be used for local authentication/authorization.
This optimization  is useful for performance and reducing the OPEX and CAPEX for the customers.

However, for this, there are many proprietary solutions.

We are seeking feedback or guidance from the WG on standard based solutions analogous to standard based AAA authentication schemes.

Thanks
Satya