Re: [pkix] Comments on draft-santesson-auth-context-extension-04

mrex@sap.com (Martin Rex) Fri, 08 March 2013 23:18 UTC

Return-Path: <mrex@sap.com>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6BD2A21F8605 for <pkix@ietfa.amsl.com>; Fri, 8 Mar 2013 15:18:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.005
X-Spam-Level:
X-Spam-Status: No, score=-10.005 tagged_above=-999 required=5 tests=[AWL=0.244, BAYES_00=-2.599, HELO_EQ_DE=0.35, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6RDSmuK42FML for <pkix@ietfa.amsl.com>; Fri, 8 Mar 2013 15:18:33 -0800 (PST)
Received: from smtpde02.sap-ag.de (smtpde02.sap-ag.de [155.56.68.140]) by ietfa.amsl.com (Postfix) with ESMTP id 1E9B321F85FE for <pkix@ietf.org>; Fri, 8 Mar 2013 15:18:32 -0800 (PST)
Received: from mail05.wdf.sap.corp by smtpde02.sap-ag.de (26) with ESMTP id r28NIOVt005820 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK); Sat, 9 Mar 2013 00:18:24 +0100 (MET)
In-Reply-To: <5139A4E4.2010107@bull.net>
To: Denis Pinkas <denis.pinkas@bull.net>
Date: Sat, 09 Mar 2013 00:18:24 +0100
X-Mailer: ELM [version 2.4ME+ PL125 (25)]
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="US-ASCII"
Message-Id: <20130308231824.595391A617@ld9781.wdf.sap.corp>
From: mrex@sap.com
X-SAP: out
Cc: Stefan Santesson <stefan@aaa-sec.com>, pkix <pkix@ietf.org>
Subject: Re: [pkix] Comments on draft-santesson-auth-context-extension-04
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: mrex@sap.com
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/pkix>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 08 Mar 2013 23:18:34 -0000

Denis,

While I have no personal interest or use in this proposal myself,
I'm somewhat confused by your message.

Denis Pinkas wrote:
> 
> Allowing to have SAML attributes in a PKC would be a very good thing. 
> However, the relying party DOES NOT care
> how these SAML attributes have been translated into a subject DN. It is 
> the responsibility of the CA.

Stefan said that he _has_ RPs who care.  Where is your problem with this?


> 
> Thus, if the scope only remains to know how the correspondence was made 
> between  the SAML attributes and
> the subject DN, I don't believe that this document will be useful for 
> the Internet community and thus I am still unconvinced
> that this document should progress as an Internet Draft.

"progress as Internet Draft"?
(I have not the slightest idea what that is.)

>From the document header, Stefan seems to be looking for an Individual
Submission with the intended document status "Informational".

Were you thinking of a Standards track document?
Or were you thinking about a WG work item (Last thing I heard was that
PKIX is scheduled to shut down (as IETF WG) and not accepting any further
work items).  Only the latter two would need any kind of "approval".


Stefan's primary interest seems to be sharing information about what he
does (or intends to do) with the IETF community.  And Stefan seems to
solicit and accept feedback and suggestions from the PKIX community
to make this work more useful to others.


> 
> If the scope is changed to allow to include SAML attributes as another 
> name form in a PKC, then this is
> an important issue which deserves an Internet Draft.

Stefan indicated that he needs this extension to convey information
that does not qualify as SAN/otherName, so this feedback seems to be
missing the point.

If you have a need for this, you might have to create your own proposal/I-D
to fit this purpose.


-Martin