Re: [Ietf-krb-wg] the PKU2U DN to Kerberos Principal name mapping
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Ietf-krb-wg] the PKU2U DN to Kerberos Principal name mapping




On Jan 28, 2008, at 12:42 PM, Nicolas Williams wrote:

On Mon, Jan 28, 2008 at 03:38:17PM -0500, Jeffrey Hutzelman wrote:
I should note that this is not a krb-wg document, and is getting close to
off-topic here. I started the discussion here because I was raising an
issue specifically related to Kerberos and potentially broader than just
PKU2U; namely, handling of mapping X.500 DN's to Kerberos principal names.
It seems that particular issue has been resolved, at least for PKU2U, by
observing that PKU2U needn't expose Kerberos principal names and so doesn't
actually need such a mapping.


At this point, I think the remaining issues are not particularly Kerberos
specific, and in fact much of this seems to touch on things that affect
other GSS-API mechanisms and the work of the Kitten WG. I think it might
be worth taking the discussion of naming issues and especially naming
extensions to the Kitten list.

KITTEN doesn't work on mechanisms either, but KITTEN is appropriate for
discussion of GSS-API naming issues. So, yes, we should take this to
the KITTEN list, though eventually PKU2U will be off-topic there also.


Nico

Since I'm not on that list, I'll throw my 2 cents in here:

It would be nice if you could do a gss_compare_name() between smith at EXAMPLE.COM and uid=smith,ou=People,dc=example,dc=com and get a "true" result. I think the detail you threw out was headed in that direction, but it wasn't clear to me if it would get you all the way there.

------------------------------------------------------------------------
The opinions expressed in this message are mine,
not those of Caltech, JPL, NASA, or the US Government.
Henry.B.Hotz at jpl.nasa.gov, or hbhotz at oxy.edu




_______________________________________________ Kitten mailing list Kitten at lists.ietf.org https://www1.ietf.org/mailman/listinfo/kitten




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.