Re: [saag] SSH Protocol Extensions

Benjamin Kaduk <kaduk@MIT.EDU> Thu, 13 August 2015 01:44 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9EB2C1B2F01; Wed, 12 Aug 2015 18:44:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PuoG_FBD7A0H; Wed, 12 Aug 2015 18:44:01 -0700 (PDT)
Received: from dmz-mailsec-scanner-3.mit.edu (dmz-mailsec-scanner-3.mit.edu [18.9.25.14]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9B4011B2EE9; Wed, 12 Aug 2015 18:44:01 -0700 (PDT)
X-AuditID: 1209190e-f79c76d000002631-b5-55cbf660ef23
Received: from mailhub-auth-1.mit.edu ( [18.9.21.35]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-3.mit.edu (Symantec Messaging Gateway) with SMTP id AC.FF.09777.066FBC55; Wed, 12 Aug 2015 21:44:00 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-1.mit.edu (8.13.8/8.9.2) with ESMTP id t7D1hxYr028987; Wed, 12 Aug 2015 21:43:59 -0400
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t7D1htj6004541 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 12 Aug 2015 21:43:58 -0400
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t7D1ht35022933; Wed, 12 Aug 2015 21:43:55 -0400 (EDT)
Date: Wed, 12 Aug 2015 21:43:53 -0400
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: Simon Josefsson <simon@josefsson.org>
In-Reply-To: <20150812195437.2e03c0c8@latte.josefsson.org>
Message-ID: <alpine.GSO.1.10.1508122142130.22210@multics.mit.edu>
References: <CAPofZaFwCdNKzM42HJMJzLsx+VSVt07Jp+FHA7rV1g7+X7RNNQ@mail.gmail.com> <tsltws4ze6d.fsf@mit.edu> <20150812195437.2e03c0c8@latte.josefsson.org>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrHIsWRmVeSWpSXmKPExsUixCmqrJvw7XSoweUbghZHN69isZjS38lk cW/LJXYHZo8lS34yecw8c5E9gCmKyyYlNSezLLVI3y6BK6Pr6Wf2gqtMFf+/HGJrYOxm6mLk 5JAQMJH4vuA0M4QtJnHh3nq2LkYuDiGBxUwSn7q2soIkhAQ2Mkpcvm8MkTjEJLHl/juoqgZG ieMH5rGBVLEIaEtc/HcCrINNQEVi5puNQHEODhEBTYm57RkgYWYBJYldizvByoWByie+Xwa2 mVPASmJZUzcLiM0r4Cix+eUZRoj5MxglTrz6xgiSEBXQkVi9fwpUkaDEyZlPWCCGakksn76N ZQKj4CwkqVlIUgsYmVYxyqbkVunmJmbmFKcm6xYnJ+blpRbpGuvlZpbopaaUbmIEB60k3w7G rweVDjEKcDAq8fBueHQ6VIg1say4MvcQoyQHk5Ior9odoBBfUn5KZUZicUZ8UWlOavEhRgkO ZiUR3qRnQDnelMTKqtSifJiUNAeLkjjvph98IUIC6YklqdmpqQWpRTBZGQ4OJQnezV+AGgWL UtNTK9Iyc0oQ0kwcnCDDeYCG7wWp4S0uSMwtzkyHyJ9i1OVY8OP2WiYhlrz8vFQpoDUgRQIg RRmleXBzYMnmFaM40FvCvB9AqniAiQpu0iugJUxAS9LlToEsKUlESEk1MPqteb1iX1CeqWrC 4ZSy1ce+rkxm3mswd/6juo9Zhue9d307bsqU+faG+W0V9wneURfn2q2//zXitcHmfX+9Mp27 PdbpmYXzHD0e8uuiTLFIL2v/8uI555/KrbqXU/08kuuruQrvwvdvV4Q4XpPlEeZ/Z9XtfFTm 0qcWhWOcO/ddSd1isqMkS0eJpTgj0VCLuag4EQBH39WIEQMAAA==
Archived-At: <http://mailarchive.ietf.org/arch/msg/saag/Uhc2eUlWDenxHDKToLluyZTvCV8>
Cc: kitten@ietf.org, saag@ietf.org
Subject: Re: [saag] SSH Protocol Extensions
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 13 Aug 2015 01:44:03 -0000

On Wed, 12 Aug 2015, Simon Josefsson wrote:

> The OAuth SASL mechanism (long delayed, still being worked on) may also
> be relevant to look into, but it does not support GSS-API so SSH support
> is not a given.

The spec just hit AUTH48 today; I am given to understand there are a
couple of implementations floating around.

-Ben