9 Oct 2008 20:13
draft-lha-gssapi-delegate-policy-01.txt
Tom Yu <tlyu <at> MIT.EDU>
2008-10-09 18:13:54 GMT
2008-10-09 18:13:54 GMT
I have examined draft-lha-gssapi-delegate-policy-01.txt and believe that it is ready to submit for publication. The rationale section that I requested addresses some of Michael Allen's concerns, explaining why we want to proceed with GSS_C_DELEG_POLICY_FLAG rather than something like GSS_C_DELEG_IGNORE_POLICY_FLAG, despite the proposal being non-ideal if we were designing GSS-API anew today. I believe the GSS_C_DELEG_POLICY_FLAG proposal is an incremental improvement to the security of GSS-API. Even if it is not ideal, I think it is more deployable than a solution involving GSS_C_DELEG_IGNORE_POLICY_FLAG. Theoretically superior security is not helpful if nobody is willing to deploy it.
RSS Feed