A New Internet-Draft is available from the on-line Internet-Drafts directories. Title : Retrieving remote attributes using GSS-API naming extensions Authors : Alejandro Perez-Mendez Rafa Marin-Lopez Gabriel Lopez-Millan Filename : draft-perez-abfab-gss-remote-attr-00.txt Pages : 9 Date : 2015-10-05 Abstract: The GSS-API Naming Extensions define new APIs that extend the GSS-API naming model to support name attribute transfer between GSS-API peers. Historically, this set of functions has been used to obtain the authorization information contained in some sort of authorization token provided to the GSS acceptor during the context establishment process, such as a Kerberos ticket, a SAML assertion, or an X.509 attribute certificate. However, some scenarios require to allow the GSS acceptor to request additional attributes after context establishment. If these attributes are not locally stored by the GSS mechanism they have to be retrieved from an external source (e.g. SQL database, LDAP directory, external IdP, etc.). This document describes how current GSS-API extensions are able to encompass such functionality without requiring of any change, neither on the existing calls nor on the way applications use the API. The IETF datatracker status page for this draft is: https://datatracker.ietf.org/doc/draft-perez-abfab-gss-remote-attr/ There's also a htmlized version available at: https://tools.ietf.org/html/draft-perez-abfab-gss-remote-attr-00 Please note that it may take a couple of minutes from the time of submission until the htmlized version and diff are available at tools.ietf.org. Internet-Drafts are also available by anonymous FTP at: ftp://ftp.ietf.org/internet-drafts/ _______________________________________________ I-D-Announce mailing list I-D-Announce@ietf.org https://www.ietf.org/mailman/listinfo/i-d-announce Internet-Draft directories: http://www.ietf.org/shadow.html or ftp://ftp.ietf.org/ietf/1shadow-sites.txt