Proxy authentication (was WG Last Call: draft-ietf-sasl-rfc2222bis-02.txt)

Alexey Melnikov <Alexey.Melnikov@isode.com> Wed, 08 October 2003 12:06 UTC

Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h98C6RKP042074 for <ietf-sasl-bks@above.proper.com>; Wed, 8 Oct 2003 05:06:27 -0700 (PDT) (envelope-from owner-ietf-sasl@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h98C6RTI042073 for ietf-sasl-bks; Wed, 8 Oct 2003 05:06:27 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-sasl@mail.imc.org using -f
Received: from rufus.isode.com (rufus.isode.com [62.3.217.251]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h98C6PKP042068 for <ietf-sasl@imc.org>; Wed, 8 Oct 2003 05:06:26 -0700 (PDT) (envelope-from Alexey.Melnikov@isode.com)
Received: from isode.com (shiny.isode.com [62.3.217.250]) by rufus.isode.com via TCP (with SMTP (internal)) with ESMTP; Wed, 8 Oct 2003 13:06:21 +0100
Message-ID: <3F83FDBB.70702@isode.com>
Date: Wed, 08 Oct 2003 13:06:19 +0100
From: Alexey Melnikov <Alexey.Melnikov@isode.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: "Kurt D. Zeilenga" <Kurt@OpenLDAP.org>
CC: ietf-sasl@imc.org, Jeffrey Hutzelman <jhutz@cmu.edu>
Subject: Proxy authentication (was WG Last Call: draft-ietf-sasl-rfc2222bis-02.txt)
References: <5.2.0.9.0.20030915103818.03b51a88@127.0.0.1> <6.0.0.22.0.20031001100505.03e9ffd0@127.0.0.1>
In-Reply-To: <6.0.0.22.0.20031001100505.03e9ffd0@127.0.0.1>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-sasl@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-sasl/mail-archive/>
List-ID: <ietf-sasl.imc.org>
List-Unsubscribe: <mailto:ietf-sasl-request@imc.org?body=unsubscribe>

[Because there are too many issues raised I will be starting a separate 
thread for each]

Kurt D. Zeilenga wrote:

>>  During the authentication protocol exchange, the mechanism performs
>>  authentication, transmits an authorization identity (frequently known
>>  as a userid) from the client to server, and negotiates the use of a
>>  mechanism-specific security layer.  If the use of a security layer is
>>  agreed upon, then the mechanism must also define or negotiate the
>>  maximum security layer buffer size that each side is able to receive.
>>
>>4.2.  Authorization identities and proxy authentication    
>>
>
>
>See note below regarding the term "proxy authentication".
>
>  
>
...

>>  The identity derived from the client's authentication credentials is
>>  known as the "authentication identity".  With any mechanism,
>>  transmitting an authorization identity of the empty string directs
>>  the server to derive an authorization identity from the client's
>>  authentication identity.
>>
>>  If the authorization identity transmitted during the authentication
>>  protocol exchange is not the empty string, this is typically referred
>>  to as "proxy authentication".
>>    
>>
>
>Personally, I refer to this as "proxy authorization".  Proxy
>authentication makes it sound like the feature can be used by a
>proxy to authenticate its users.
>
>  
>
Jeffrey Hutzelman wrote:

>>>   If the authorization identity transmitted during the authentication
>>>   protocol exchange is not the empty string, this is typically referred
>>>   to as "proxy authentication".
>>
>> Personally, I refer to this as "proxy authorization".  Proxy
>> authentication makes it sound like the feature can be used by a
>> proxy to authenticate its users.
>
> The same argument can be made for "proxy authorization".  We are 
> talking about "authentication by proxy", not "authentication to a 
> proxy".  And yes, we're really talking about authorization, not 
> authentication, but it's not really "authorization by proxy"; it's 
> just authorization.
>
> The terminology is pretty bad.  It's not clear to me that we need a 
> name for this at all.  But I'm pretty sure the phrase "proxy 
> authentication" has been in use for a while, and to change it might 
> cause more confusion than leaving it alone.


So, I will leave it as is.

Alexey