Proxy authentication (was WG Last Call: draft-ietf-sasl-rfc2222bis-02.txt)
Alexey Melnikov <Alexey.Melnikov@isode.com> Wed, 08 October 2003 12:06 UTC
Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h98C6RKP042074 for <ietf-sasl-bks@above.proper.com>; Wed, 8 Oct 2003 05:06:27 -0700 (PDT) (envelope-from owner-ietf-sasl@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h98C6RTI042073 for ietf-sasl-bks; Wed, 8 Oct 2003 05:06:27 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-sasl@mail.imc.org using -f
Received: from rufus.isode.com (rufus.isode.com [62.3.217.251]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h98C6PKP042068 for <ietf-sasl@imc.org>; Wed, 8 Oct 2003 05:06:26 -0700 (PDT) (envelope-from Alexey.Melnikov@isode.com)
Received: from isode.com (shiny.isode.com [62.3.217.250]) by rufus.isode.com via TCP (with SMTP (internal)) with ESMTP; Wed, 8 Oct 2003 13:06:21 +0100
Message-ID: <3F83FDBB.70702@isode.com>
Date: Wed, 08 Oct 2003 13:06:19 +0100
From: Alexey Melnikov <Alexey.Melnikov@isode.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: "Kurt D. Zeilenga" <Kurt@OpenLDAP.org>
CC: ietf-sasl@imc.org, Jeffrey Hutzelman <jhutz@cmu.edu>
Subject: Proxy authentication (was WG Last Call: draft-ietf-sasl-rfc2222bis-02.txt)
References: <5.2.0.9.0.20030915103818.03b51a88@127.0.0.1> <6.0.0.22.0.20031001100505.03e9ffd0@127.0.0.1>
In-Reply-To: <6.0.0.22.0.20031001100505.03e9ffd0@127.0.0.1>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-sasl@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-sasl/mail-archive/>
List-ID: <ietf-sasl.imc.org>
List-Unsubscribe: <mailto:ietf-sasl-request@imc.org?body=unsubscribe>
[Because there are too many issues raised I will be starting a separate thread for each] Kurt D. Zeilenga wrote: >> During the authentication protocol exchange, the mechanism performs >> authentication, transmits an authorization identity (frequently known >> as a userid) from the client to server, and negotiates the use of a >> mechanism-specific security layer. If the use of a security layer is >> agreed upon, then the mechanism must also define or negotiate the >> maximum security layer buffer size that each side is able to receive. >> >>4.2. Authorization identities and proxy authentication >> > > >See note below regarding the term "proxy authentication". > > > ... >> The identity derived from the client's authentication credentials is >> known as the "authentication identity". With any mechanism, >> transmitting an authorization identity of the empty string directs >> the server to derive an authorization identity from the client's >> authentication identity. >> >> If the authorization identity transmitted during the authentication >> protocol exchange is not the empty string, this is typically referred >> to as "proxy authentication". >> >> > >Personally, I refer to this as "proxy authorization". Proxy >authentication makes it sound like the feature can be used by a >proxy to authenticate its users. > > > Jeffrey Hutzelman wrote: >>> If the authorization identity transmitted during the authentication >>> protocol exchange is not the empty string, this is typically referred >>> to as "proxy authentication". >> >> Personally, I refer to this as "proxy authorization". Proxy >> authentication makes it sound like the feature can be used by a >> proxy to authenticate its users. > > The same argument can be made for "proxy authorization". We are > talking about "authentication by proxy", not "authentication to a > proxy". And yes, we're really talking about authorization, not > authentication, but it's not really "authorization by proxy"; it's > just authorization. > > The terminology is pretty bad. It's not clear to me that we need a > name for this at all. But I'm pretty sure the phrase "proxy > authentication" has been in use for a while, and to change it might > cause more confusion than leaving it alone. So, I will leave it as is. Alexey
- WG Last Call: draft-ietf-sasl-rfc2222bis-02.txt Kurt D. Zeilenga
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Alexey Melnikov
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Alexey Melnikov
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Kurt D. Zeilenga
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Alexey Melnikov
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Kurt D. Zeilenga
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Hallvard B Furuseth
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Jeffrey Hutzelman
- CHARSET-POLICY Re: WG Last Call: draft-ietf-sasl-… Kurt D. Zeilenga
- Re: CHARSET-POLICY Re: WG Last Call: draft-ietf-s… Alexey Melnikov
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Alexey Melnikov
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Jeffrey Hutzelman
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Alexey Melnikov
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Kurt D. Zeilenga
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Sam Hartman
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Rob Siemborski
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Alexey Melnikov
- Proxy authentication (was WG Last Call: draft-iet… Alexey Melnikov
- Re: WG Last Call: draft-ietf-sasl-rfc2222bis-02.t… Alexey Melnikov