RE: Questions on modified Extended Attribute format?

"Glen Zorn" <glenzorn@comcast.net> Wed, 26 December 2007 18:21 UTC

Return-path: <owner-radiusext@ops.ietf.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1J7asN-0008FG-Dv for radext-archive-IeZ9sae2@lists.ietf.org; Wed, 26 Dec 2007 13:21:07 -0500
Received: from psg.com ([147.28.0.62]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1J7asL-0005FW-7J for radext-archive-IeZ9sae2@lists.ietf.org; Wed, 26 Dec 2007 13:21:07 -0500
Received: from majordom by psg.com with local (Exim 4.68 (FreeBSD)) (envelope-from <owner-radiusext@ops.ietf.org>) id 1J7aoX-000L6y-Hf for radiusext-data@psg.com; Wed, 26 Dec 2007 18:17:09 +0000
X-Spam-Checker-Version: SpamAssassin 3.2.3 (2007-08-08) on psg.com
X-Spam-Level:
X-Spam-Status: No, score=-2.5 required=5.0 tests=AWL,BAYES_00,RDNS_NONE autolearn=no version=3.2.3
Received: from [76.96.30.56] (helo=QMTA06.emeryville.ca.mail.comcast.net) by psg.com with esmtp (Exim 4.68 (FreeBSD)) (envelope-from <glenzorn@comcast.net>) id 1J7aoU-000L6c-RJ for radiusext@ops.ietf.org; Wed, 26 Dec 2007 18:17:08 +0000
Received: from OMTA06.emeryville.ca.mail.comcast.net ([76.96.30.51]) by QMTA06.emeryville.ca.mail.comcast.net with comcast id VRLf1Y00C16AWCU0A0Lu00; Wed, 26 Dec 2007 18:17:06 +0000
Received: from gwzPC ([67.168.164.234]) by OMTA06.emeryville.ca.mail.comcast.net with comcast id VWH41Y00353lGY38S00000; Wed, 26 Dec 2007 18:17:06 +0000
X-Authority-Analysis: v=1.0 c=1 a=Gn-g1Pkd9IgA:10 a=KyU8gm_5oIyxiH_ZlMUA:9 a=pzxYAvxED1nxWDAwYLQA:7 a=t-OMm-fGHK-DBl3VacWkXzZdn2wA:4 a=MxZ3bB5I4kYA:10
From: Glen Zorn <glenzorn@comcast.net>
To: Bernard_Aboba@hotmail.com, 'Alan DeKok' <aland@nitros9.org>
Cc: radiusext@ops.ietf.org
References: <003401c83a92$db6ed850$924c88f0$@net> <47729084.8060206@nitros9.org> <BAY117-DS154D4BF5B19166015FF82935B0@phx.gbl>
In-Reply-To: <BAY117-DS154D4BF5B19166015FF82935B0@phx.gbl>
Subject: RE: Questions on modified Extended Attribute format?
Date: Wed, 26 Dec 2007 10:16:28 -0800
Message-ID: <006b01c847eb$70096650$501c32f0$@net>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Office Outlook 12.0
Thread-Index: AchH6VnSyItJtpl6RvSUZWLy43jIIwAAIzhw
Content-Language: en-us
Sender: owner-radiusext@ops.ietf.org
Precedence: bulk
X-Spam-Score: -4.0 (----)
X-Scan-Signature: 8b30eb7682a596edff707698f4a80f7d

>  WiMAX uses the same attribute format as proposed here.  Changes that
> are incompatible with WiMAX should be discouraged.

I would agree.   If the extensions remain compatible with WiMAX then
the amount of code duplication will be minimized.

[gwz] 
If we're suddenly worried about the size of code for processing VSAs, it
would seem to make much more sense to be compatible with cisco's VSAs since
they are far more widely deployed than WiMax's (and probably always will
be).
[/gwz]

>  If it's just stealing a bit (which WiMAX doesn't use), that sounds
> fine.  The ability to group legacy RADIUS attributes via a method other
> than tags would be good.
>
>  One question: If we DO permit this for legacy RADIUS attributes, what
> does the "C" bit mean?  Do we use the WiMAX method for splitting
> attributes encrypted with the "Tunnel-Password" method?

We need to be careful about feature creep here.  The original purpose of
the Extended Attributes document was to extend the RADIUS attribute space.

If the document is now taking on new problems (extending capabilities of the
RADIUS protocol or changing the semantics of existing attributes) then that
problem needs to be clearly stated, and justification needs to be provided. 

[gwz] 
I'm not suggesting anything of the sort: the capabilities for sending large
attributes & grouping them already exist (although in limited ways); I'm
talking about standardizing these existing capabilies, not adding new ones.
[/gwz]


--
to unsubscribe send a message to radiusext-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://psg.com/lists/radiusext/>