30 likes | 148 Vues
This document outlines the current status of the Kerberos clarifications and extensions as discussed in the IETF meeting held in Fall 2003. Key updates include the issuance of a last call by the IESG, minor changes to Section 7.5.1 regarding GSS numbers, and various issues identified during an interim meeting in Boulder, CO. Important topics include the addition of language tags, nonce support in KRB-ERROR, and guidelines for error signing. The draft is set for release after Thanksgiving with hopes of including more submissions.
E N D
Kerberos Clarifications andExtensions Status Dr. Clifford Neuman Center for Computer Systems Security Information Sciences Institute School of Engineering University of Southern California http://ccss.isi.edu Fall 2003 IETFMSP
Clarifications Status • In IESG Consideration • Last call issued October 21 • Minor changes to be made: • Section 7.5.1 updating GSS numbers • For others, please send to the list (with CLARIFICATIONS in the subject). • I will make sure these get packaged up andsent to the IESG.
Extensions Status • Interim Meeting September 16-17, Boulder CO. • Issues identified (list by jhutz) with current status • Remove SMTP name type [done - bcn] • Add language tags to request as well as reply [Tom Yu] • Add nonce to krb-error [Tom Yu] • Encoding [Tom Yu, Nico Williams] • Allow KDC to offer extensions support via PA-DATA PA-AS-REQ [Sam Hartman] • Allow KDC to accept addresses of unknown families [Cliff Neuman - pending] • KRB-ERROR signing guidelines [Sam Hartman] • Typed-hole namespace assignment [Tom Yu, Nico Williams] • Cross-realm referrals [Todd Stecher/Microsoft] (how is this different from what clarifications already includes? ) • Mixed client libraries [Sam Hartman, Jeff Altman - pending] • U2U negotiation [Tom Yu - pending] • Namespace restrictions [Sam Hartman] • Downgrade ext->clar issues [Nico Williams] • I18N issues [Jeff Altman, Jeff Hutzelman – lots of discussion Monday – discussion later] • How does extensions-only client probe KDC -- deferred to list • Update MUST's -- deferred until closer to publication • Draft to be sent out after IETF (by end of Thanksgiving), with hopefully a few more of the itemssubmitted to me.