internet-drafts | 23 May 16:52
Picon
Favicon

I-D Action: draft-ietf-krb-wg-cammac-02.txt


A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item
of the Kerberos Working Group of the IETF.

	Title           : Container Authenticated by Multiple MACs
	Author(s)       : Simo Sorce
                          Tom Yu
                          Thomas Hardjono
	Filename        : draft-ietf-krb-wg-cammac-02.txt
	Pages           : 7
	Date            : 2012-05-23

   Abstract: This document proposes a Kerberos Authorization Data
   container that supersedes AD-KDC-ISSUED.  It allows for multiple MACs
   or signatures on the contained Authorization Data elements.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-krb-wg-cammac-02.txt

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

This Internet-Draft can be retrieved at:
ftp://ftp.ietf.org/internet-drafts/draft-ietf-krb-wg-cammac-02.txt

The IETF datatracker page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-krb-wg-cammac/

_______________________________________________
ietf-krb-wg mailing list
(Continue reading)

Sam Hartman | 26 Apr 15:14
Picon
Favicon

A proposal from Adrian on the des deprecation registry


IANA's question about whether we should  deprecate code points in the
registry came up during IESG discussion of
draft-ietf-krb-wg-des-die-die-die.
It looks like our discussion is sufficient and we will be able to move
forward with no change if we like.

However, since a specific proposal was made  I'd like to forward it to
the WG in case people start shouting for joy.
we could potentially make the change now if the document doesn't end up
getting approved today and people are very supportive.
Or we could make this with some-numbers-to-iana.

Picon
From: Adrian Farrel <adrian <at> olddog.co.uk>
Subject: RE: Adrian Farrel's Discuss on draft-ietf-krb-wg-des-die-die-die-04: (with DISCUSS)
Date: 2012-04-26 13:06:35 GMT

Hi again,

 

(Apologies for html email, but the layout of the registry columns works better in a non-proportional font)

 

> >> [1] https://lists.anl.gov/pipermail/ietf-krb-wg/2012-April/010096.html

> >

(Continue reading)

Sam Hartman | 17 Apr 22:26
Picon
Favicon

Please review draft-ietf-abfab-gss-eap-06 by May 1 2012


HI.  Speaking as an editor in another working gorup.  We'd appreciate
review from the Kerberos community of draft-ietf-abfab-gss-eap-06.  In
particular that draft sets up a registry of RFC 4121 token types in the
Kerberos V GSS-API Parameters Registry that we recently established in
this working group.
Also, we re-use aspects of the RFC 4121 mechanism.

Comments should be sent to abfab <at> ietf.org by May 1, 2012.

Thanks for your consideration

--Sam
_______________________________________________
ietf-krb-wg mailing list
ietf-krb-wg <at> lists.anl.gov
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg

Sam Hartman | 9 Apr 21:35
Picon
Favicon

Preliminary minutes uploaded


I've uploaded prelininary minutes to the meeting materials manager.
_______________________________________________
ietf-krb-wg mailing list
ietf-krb-wg <at> lists.anl.gov
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg

Sam Hartman | 9 Apr 20:09
Picon
Favicon

Call for adoption: draft-josefsson-kerberos5-i18n-01.txt


This message starts a two-week call on wether to adopt
https://tools.ietf.org/id/draft-josefsson-kerberos5-i18n-01.txt as a
draft to address our charter item regarding the internationalization of
Kerberos error messages.

I'd appreciate comments by April 24, 2012.

Sam Hartman
Kerberos co-chair
_______________________________________________
ietf-krb-wg mailing list
ietf-krb-wg <at> lists.anl.gov
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg

rfc-editor | 6 Apr 23:12
Favicon

RFC 6560 on One-Time Password (OTP) Pre-Authentication


A new Request for Comments is now available in online RFC libraries.

        
        RFC 6560

        Title:      One-Time Password (OTP) Pre-Authentication 
        Author:     G. Richards
        Status:     Standards Track
        Stream:     IETF
        Date:       April 2012
        Mailbox:    gareth.richards <at> rsa.com
        Pages:      43
        Characters: 95896
        Updates/Obsoletes/SeeAlso:   None

        I-D Tag:    draft-ietf-krb-wg-otp-preauth-21.txt

        URL:        http://www.rfc-editor.org/rfc/rfc6560.txt

The Kerberos protocol provides a framework authenticating a client
using the exchange of pre-authentication data.  This document
describes the use of this framework to carry out One-Time Password
(OTP) authentication.  [STANDARDS-TRACK]

This document is a product of the Kerberos WG Working Group of the IETF.

This is now a Proposed Standard Protocol.

STANDARDS TRACK: This document specifies an Internet standards track
(Continue reading)

Tom Yu | 5 Apr 16:33
Picon
Favicon

des-die-die-die and adding IANA registry status columns

IANA has asked whether we want to add status columns to the Kerberos
enctype and checksumtype registries, given that we are deprecating
some of them, so that we can use those columns to mark the algorithms
as "deprecated".  IANA also notes that we have existing preauth
registry entries with comments such as "obsoleted" and "deprecated"
(though these don't have their own column either).

Any strong opinions about whether to add such status columns?

Relatedly, there is a "checksum size" column in the checksum registry
that has some incorrect values (e.g. for the hmac-sha1-96 checksums).
Does it make more sense to correct these values, or to drop the column
from the registry completely?
_______________________________________________
ietf-krb-wg mailing list
ietf-krb-wg <at> lists.anl.gov
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg

Thomas Hardjono | 28 Mar 16:08
Picon
Favicon

FW: [security-services] (ANN) SAML V2.0 Kerberos Web Browser SSO Profile V1.0 Committee Specification published

FYI.

__________________________________________

-----Original Message-----
From: security-services <at> lists.oasis-open.org [mailto:security-services <at> lists.oasis-open.org]
On Behalf Of Chet Ensign
Sent: Wednesday, March 28, 2012 9:36 AM
To: tc-announce <at> lists.oasis-open.org; members <at> lists.oasis-open.org; security-services <at> lists.oasis-open.org
Subject: [security-services] (ANN) SAML V2.0 Kerberos Web Browser SSO Profile V1.0 Committee
Specification published

OASIS Members,

We are pleased to announce the approval and publication of an OASIS Committee Specification (CS) by the
members of the OASIS Security Services (SAML) TC:

SAML V2.0 Kerberos Web Browser SSO Profile Version 1.0 Committee Specification 01
07 February 2012

Overview: 
The SAML V2.0 Kerberos Web Browser SSO Profile allows for transport of assertions using the Kerberos
subject confirmation method by standard HTTP user agents with no modification of client software and
maximum compatibility with existing deployments.  The flow is similar to standard Web Browser SSO, but a
Kerberos AP-REQ message is presented by the user agent via the HTTP Negotiate authentication scheme and
the Kerberos GSS-API mechanism. The presentation of a valid Kerberos AP-REQ message whose client
principal name matches the principal name given in the subject confirmation strengthens the assurance
of the resulting authentication context and protects against credential theft.

URIs: 
(Continue reading)

Meetecho session recording available

Dear all,

the full recording (synchronized video, audio, slides and jabber room)
of KERBEROS session at IETF-83 is available.

You can watch it by either clicking the proper link on the remote 
participation page 
(http://www.ietf.org/meeting/83/remote-participation.html#Meetecho), or 
by directly accessing the following URL:
http://www.meetecho.com/ietf83/recordings#KRBWG_IETF83

For the chair(s): please feel free to put the link to the recording in 
the minutes, if you think this might be useful.

In case of problems with the playout, just drop an e-mail to
ietf-support <at> meetecho.com.

Cheers,
the Meetecho team

--

-- 
Meetecho s.r.l.
Web Conferencing and Collaboration Tools
www.meetecho.com
_______________________________________________
ietf-krb-wg mailing list
ietf-krb-wg <at> lists.anl.gov
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg

(Continue reading)

Jeffrey Hutzelman | 26 Mar 21:46
Picon
Favicon

Scribe needed

We need a scribe/note-taker for tomorrow's krb-wg meeting.  The meeting
cannot start without a scribe, and we're sharing a timeslot with another
group, so it would be especially impolite not to be ready to go at the
appointed time.  Therefore, the chairs would appreciate one or more
volunteers.

-- Jeff

_______________________________________________
ietf-krb-wg mailing list
ietf-krb-wg <at> lists.anl.gov
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg

Henry B. Hotz | 26 Mar 20:12
Picon
Picon
Favicon

Meeting Time?

The iPhone App and datatracker don't agree on *anything*, not even on whether it's joint with kitten.  I
suppose the latter is authoritative?
------------------------------------------------------
The opinions expressed in this message are mine,
not those of Caltech, JPL, NASA, or the US Government.
Henry.B.Hotz <at> jpl.nasa.gov, or hbhotz <at> oxy.edu

_______________________________________________
ietf-krb-wg mailing list
ietf-krb-wg <at> lists.anl.gov
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg


Gmane