Re: RPCSEC_GSSv3: extensions for process labeling, etc...
David P. Quigley <dpquigl <at> tycho.nsa.gov>
2009-01-13 18:40:18 GMT
Since this is instrumental to my work I'll co-author it but keep in mind
I'm still relatively new to RPC and the IETF process as a whole. What
kind of effort do you need on my part with respect to the document and
implementation?
Dave
On Tue, 2009-01-13 at 12:06 -0600, Nicolas Williams wrote:
> I finally wrote an I-D for dealing with process security labels in NFSv4
> (and other ONC RPC protocols).
>
> If the WG wants to take this on I'll need an editor and/or co-author as
> I don't really have the cycles to see this through to publication.
>
> Features of RPCSEC_GSSv3:
>
> - compound authentication of client host and user to server
> - needed to provide servers with assurance of client ID in order to
> evaluate process credentials assertions while still retaining user
> authentication
> - process credentials assertions
> - security labels
> - privileges (app-specific)
> - identity (app-specific; think: replacement for AUTH_SYS that uses
> name <at> domain on the wire, plus GSS-API for client auth!)
> - channel binding (without a hash function)
>
> Nico
>
>
> ----- Forwarded message from IETF I-D Submission Tool <idsubmission <at> ietf.org> -----
>
> Date: Mon, 12 Jan 2009 19:08:59 -0800 (PST)
> From: IETF I-D Submission Tool <idsubmission <at> ietf.org>
> Subject: New Version Notification for draft-williams-rpcsecgssv3-00
> To: Nicolas.Williams <at> Sun.COM
>
>
> A new version of I-D, draft-williams-rpcsecgssv3-00.txt has been successfuly submitted by Nicolas
Williams and posted to the IETF repository.
>
> Filename: draft-williams-rpcsecgssv3
> Revision: 00
> Title: Remote Procedure Call (RPC) Security Version 3
> Creation_date: 2009-01-12
> WG ID: Independent Submission
> Number_of_pages: 22
>
> Abstract:
> This document specifies version 3 of the Remote Procedure Call (RPC)
> security protocol (RPCSEC_GSS). This protocol provides for: compound
> authentication of client hosts and users to server (constructed by
> generic composition), channel binding, security label assertions for
> multi-level and type enforcement, privilege assertions and identity
> assertions.
>
>
>
> The IETF Secretariat.
>
>
>
> ----- End forwarded message -----
> _______________________________________________
> nfsv4 mailing list
> nfsv4 <at> ietf.org
> https://www.ietf.org/mailman/listinfo/nfsv4
_______________________________________________
nfsv4 mailing list
nfsv4 <at> ietf.org
https://www.ietf.org/mailman/listinfo/nfsv4