A New Internet-Draft is available from the on-line Internet-Drafts directories.
Title : GSS-API: Delegate if approved by policy
Author(s) : L. Astrand, S. Hartman
Filename : draft-lha-gssapi-delegate-policy-05.txt
Pages : 14
Date : 2010-03-22
Several GSS-API applications work in a multi-tiered architecture,
where the server takes advantage of delegated user credentials to act
on behalf of the user and contact additional servers. In effect, the
server acts as an agent on behalf of the user. Examples include web
applications that need to access e-mail or file servers as well as
CIFS (Common Internet File System) file servers. However, delegating
the user credentials to a party who is not sufficiently trusted is
problematic from a security standpoint. Kerberos provides a flag
called OK-AS-DELEGATE that allows the administrator of a Kerberos
realm to communicate that a particular service is trusted for
delegation. This specification adds support for this flag and
similar facilities in other authentication mechanisms to GSS-API (RFC
2743).
A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-lha-gssapi-delegate-policy-05.txt
Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.
- <ftp://ftp.ietf.org/internet-drafts/draft-lha-gssapi-delegate-policy-05.txt>
-
_______________________________________________
I-D-Announce mailing list
I-D-Announce@ietf.org
https://www.ietf.org/mailman/listinfo/i-d-announce
Internet-Draft directories: http://www.ietf.org/shadow.html
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt