Name: draft-ietf-kitten-gss-naming-00
Title: Desired Enhancements to GSSAPI Naming
State: Active
Authors: Sam Hartman
Group: Kitten (GSS-API Next Generation) (kitten)
Date: 2004-12-01
The Generic Security Services API (GSS-API) provides a naming architecture
that supports name-based authorization. GSS-API authenticates two named
parties to each other. Names can be stored on access control lists to make
authorization decisions. Advances in security mechanisms and the way
implementers wish to use GSS-API require this model to be extended. Some
mechanisms such as public-key mechanisms do not have a single name to be
used across all environments. Other mechanisms such as Kerberos allow names
to change as people move around organizations. This document proposes
expanding the definition of GSS-API names to deal with these situations.
|
|
|