<Jeffrey Altman> I have not seen an announcement to the krb-wg mailing list summarizing the audio stream and presentation information. Could one be sent?
* Jeffrey Altman has changed the subject to: Kerberos Working Group at IETF 65
<Jeffrey Altman> Audio stream info available at http://videolab.uoregon.edu/events/ietf/
<Jeffrey Altman> would someone please test the microphone
<raeburn@jis.mit.edu> just did...
<Jeffrey Altman> apparently the audio server is no longer accessible
<raeburn@jis.mit.edu> oops
<Jeffrey Altman> looks like I am going to be sad
<Jeffrey Altman> the test stream with classical music is working fine but the rooms are not
<raeburn@jis.mit.edu> The web page indicates contact addresses...
<hartmans> They have been having network issues.
[10:03:24] --- leifj has joined
<hartmans> Something about th eflooding.
<hartmans> The IESG breakfast room is still flooded
<Jeffrey Altman> I will be counting on good scribes then
<lha> we have not started yet
<hartmans> The room is very sparsely populated this morning.
<jhutz> Information about the audio and jabber is on the WG web page http://grand.central.org/krb-wg/
<jhutz> Is the audio working yet?
<nico> 'lo
<jhutz> whee!
<nico> test
<nico> grrr, I can't join apparea
<Jeffrey Altman> audio is not working yet
* nico is scribing
<nico> doc status
<nico> the slide is old
<nico> PKINIT is in the RFC Editor's queue
<nico> similarly for enctype nego
<nico> and ocsp for pkinit
<nico> several outstanding thin gs
<nico> ECC for PKINIT
<nico> passed last call
<nico> WGLC
<nico> we may need to hold off
<nico> anonymity work
<nico> set passwd
<nico> extensions
<nico> is Simon here?
<nico> we probably won't talk about his TLS thing
<nico> agenda bashing (should have come first)
<nico> see slide
<nico> order will change
<nico> anonymity first
<nico> direction?
<nico> interest in doing work is there, what path? need a conclusion
<nico> if Larry's path there's at least one issue to discuss
<jhutz> lalala
<hartmans> Test.
* nico is back
<nico> we've been talking about alg. agility
<nico> the krb5 GSS mech uses MD5 for channel bindings
<bcneuman> The Audio is working for me.
<Jeffrey Altman> I'm not getting a connection to the audio server yet
<Jeffrey Altman> there we go. I have audio
<nico> we really need to move away from MD5 for that -- we have an extensibility hole in the mech...
<Jeffrey Altman> I have read larry's draft
<Jeffrey Altman> but I just lost audio
<nico> ....
<Jeffrey Altman> The W3C is looking for an anonymous solution for third party authentication.
<hartmans> No, I was talking about identity hiding at the transport level; Larry's draft came before my talk.
Test
[10:35:53] <hartmans> Test
<Jeffrey Altman> they want to be able to ensure that if AOL has a contract with a third party to provide a service to all AOL users, they want the third party to be able to authenticate the user as "user from AOL" and not as the individual user
<leifj> not dissimilar to the problems solved by many sk identity federation protocols based on saml
<nico> no scribing
<Jeffrey Altman> exactly
<nico> the network sucks
<Jeffrey Altman> We need to have a solution in this space and I believe that larry's draft is a step in the right direction
<nico> ok, the network seems to be back
<Jeffrey Altman> (love please speak up)
<leifj> he has
<leifj> in support
<leifj> lha: I don't agree with everything but it is the right direction
<leifj> larry is summarizing draft
<Jeffrey Altman> it was better before
<jhutz> is audio working again?
<hartmans> Note that I think the name used here is wrong.
<nico> technical discussion of how the protocol (anonymity) works
<hartmans> In particular, I don' think the empty realm is valid.
<leifj> why?
<jhutz> Well, it's valid if we say it is, but I think existing implementations might not be happy about it.
<jhutz> But that's the sort of issue we can work on, if we adopt the draft
<leifj> ah, I see
<leifj> I thought sam had architectural, rather than deployment-related issues
<tlyu> i think A/N/O/N/Y/M/O/U/S might be less likely to be deployed than a three-component principal
<nico> valid realm names are useful anyways
heh
[10:48:27] <nico> heh
<nico> there were hums on the yes
<nico> none on the no
<leifj> people didn't hum at the mic
<nico> they never do...
:)
<pbh> audio just dropped?
[10:51:11] <nico> :)
<Jeffrey Altman> I still have audio
[10:53:25] <Jeffrey Altman> I still have audio
<pbh> Thanks, I have it back.
[10:54:13] <pbh> Thanks, I have it back.
<hartmans> I agree anonymous: works
<Jeffrey Altman> CIFS ?
[10:58:29] <Jeffrey Altman> CIFS ?
<nico> I've used three-component princ names for other things in the past
<Jeffrey Altman> why wouldn't it be on an ACL?
[11:02:12] <Jeffrey Altman> why wouldn't it be on an ACL?
<nico> we could
[11:03:28] <nico> we could
<nico> but I do think we need an authz-data element for anonymity and pseudonymity
<nico> how's the audio stream?
<Jeffrey Altman> audio is good
[11:06:42] <Jeffrey Altman> audio is good
<nico> and in authz-data, yes
<leifj> yes
[11:07:42] <leifj> yes
<jhutz> maybe we need to turn down the level a notch on larry's mic, too
[11:08:04] <jhutz> maybe we need to turn down the level a notch on larry's mic, too
<nico> yes
<nico> that would be my retort
[11:09:19] <nico> that would be my retort
<nico> I'm not sure where he's going with that
<nico> jhutz made an ugly face
<nico> at my suggestion at the mic
<tlyu> oh look i appear to have love's name as a last name
<nico> how much time do we have?
<nico> will we have time for extensions?
[11:13:50] <nico> will we have time for extensions?
* nico worries about how to ensure that the issued ticket really is anonymous
<nico> authenticated plaintext and all that
<Jeffrey Altman> lost audio
<jhutz> You don't have any now?
<jhutz> Aaron is talking about the issue he thinks he found in Larry's anonymous draft
<Jeffrey Altman> nope,none
<nico> ok, so that's the sort of thing I was just saying I was worried about
<pbh> also lost audio and a local rstart didn't help
<Jeffrey Altman> could someone please scribe?
<nico> are the slides online?
<Jeffrey Altman> slides are online. I'm trying to convert them to PDF
<nico> should be sufficient
<leifj> this was more or less a straight narrative of the slides
<leifj> nico claims this is a problem which stems from the fact that not all plaintext is authenticated
<leifj> some discussion around this
<nico> I claimed no such thing
<leifj> k - nico will say what he said ...
<lha> I converted the slides, jhutz have them
<Jeffrey Altman> if jhutz adds me to the krb-wg acl I can upload the ones I produced
<nico> I asked
<nico> I asked if solving the authenticated plaintext problem would be sufficient
[11:26:48] <jhutz> I have the ones from Love. They are on the gco site now.
[11:26:55] <nico> there is the issue of binding the ticket and reply
[11:26:55] <jhutz> I am about to upload to the IETF proceedings.
[11:27:06] <nico> which I consider part of the authenticated plaintext problem
[11:27:35] <nico> if we authenticate the plaintext, by which I mean the entire requests and replies
[11:27:50] <Jeffrey Altman> audio is back
[11:28:07] <nico> then the existing binding between of reply to request ought to suffice
[11:28:21] <nico> thought I'd certainly like stronger reply-to-request bindings
[11:30:53] <jhutz> Files are uploaded to the IETF meeting materials page, including an updated agenda.
[11:31:55] <Jeffrey Altman> mic please (to Sam)
[11:32:36] <nico> sam provided an answer
[11:32:50] <jhutz> can people here tom right now?
[11:34:31] <nico> the PA-TGS-REQ AP-REQ authenticator has a checksum of the TGS-REQ
[11:38:48] <nico> we don't have such a checksum on AS-REQ bodies though, do we
[11:39:17] <nico> i.e., PA-ENC-TIMESTAMP does not provide any such authentication, unlike PA-TGS-REQ
[11:39:32] <hartmans> No, we do not.
[11:39:34] <hartmans> So you can definitely swap replies.
[11:41:43] <nico> right, so we should either do something about that
[11:42:00] <nico> (extensions)
[11:43:25] <Jeffrey Altman> sam please use the mic
[11:43:48] <hartmans> This is fixed in extensions.
[11:44:23] <hartmans> O, hey, no it isn't.
[11:45:13] <hartmans> Particularly given that we don't know how we would rework to fix this
[11:46:03] <nico> huh?
[11:46:08] <nico> sam is going to the mic
[11:53:04] <Jeffrey Altman> I think we need to go with the Security Considerations approach
[11:53:25] <Jeffrey Altman> are we going to discuss referrals?
[11:53:42] <Ken Raeburn> Only if there's time, it seems.
[12:08:39] <pbh> repeat the question
[12:08:50] <Ken Raeburn> "What about rfc4121?"
[12:08:56] <Ken Raeburn> (it uses md5 hashes)
[12:08:57] <pbh> thanks
[12:10:24] <Ken Raeburn> (Hmm, too bad we don't have a way of broadcasting the projector data to the net... would probably be a low-bandwidth video feed...)
[12:14:14] <Jeffrey Altman> it would be easy
[12:14:22] <Jeffrey Altman> jhutz should edit the file in afs
[12:14:27] <Jeffrey Altman> and save it periodically
[12:38:22] <Jeffrey Altman> by original plan was to grab a web cam that would take photographs once a minute and save them to afs
[12:39:00] --- Jeffrey Altman has left
