JiscMail Logo
Email discussion lists for the UK Education and Research communities

Help for MOONSHOT-DEV Archives


MOONSHOT-DEV Archives

MOONSHOT-DEV Archives


MOONSHOT-DEV@JISCMAIL.AC.UK


View:

Message:

[

First

|

Previous

|

Next

|

Last

]

By Topic:

[

First

|

Previous

|

Next

|

Last

]

By Author:

[

First

|

Previous

|

Next

|

Last

]

Font:

Proportional Font

LISTSERV Archives

LISTSERV Archives

MOONSHOT-DEV Home

MOONSHOT-DEV Home

MOONSHOT-DEV  July 2014

MOONSHOT-DEV July 2014

Options

Subscribe or Unsubscribe

Subscribe or Unsubscribe

Log In

Log In

Get Password

Get Password

Subject:

Several things coming together into a Potential Coordinated Release

From:

Sam Hartman <[log in to unmask]>

Date:

Fri, 11 Jul 2014 11:31:35 -0400

Content-Type:

text/plain

Parts/Attachments:

Parts/Attachments

text/plain (60 lines)

Hi.

I realized that we've been coordinating a number of development and
maintenance projects that are inter-related and that will have
significant affects on the overall system and I'm not sure we've written
it up anywhere.

* We're upgrading to Freeradius 3.0.4.  This is a bigger deal than it
  might otherwise be because we're significantly reducing the amount of
  patches to Freeradius that we need.

Unless the 3.0.4 release is later than I expect, it won't include the
RP-side trustrouter integration in the upstream.  So we will still
produce a 3.0.4 release.  However, this may be the last version where
you need to use our code for moonshot-related Freeradius. 


* We're finishing constraint support in the trust router and
  Freeradius.  Se the hartmans/tr-constraints branch on the trust router
  repository for a work in progress.

This means we'll actually store the constraints in the keys database.
We'll provide a default unlang policy to validate them  and to do
channel binding checks based on them.

As a result the keys database schema will change.  So we'll probably ask
people to delete their keys database.  That kind of breaks things, but
see below:

* We're working to add support to Freeradius (presumably not in the
  upstream 3.0.4 release but hopefully in 3.0.5) for key recovery.  The
  idea is that if trustrouter is used to select a realm  and SSL
  negotiation fails in a way consistent with an unknown PSK identity,
  and it has been a sufficient time since we acquired the key, then
  we'll try trustrouter again.
This will reduce the impact of people deleting their keys database.

* Prior to Alan integrating the trustrouter code we'd like to see some
  improvements made in it that we're working on.  Currently, only one
  COI can be used within an RP.  We'd prefer per-radius-client COI
  support.  Which means we need to keep track of the trustrouter coi in
  how we do the realm lookup.  So, something like internally store it as
  coi%realm or something like that, all managed under the covers inside
  the trustrouter module.  We also need to avoid using unstable data
  structures from the trustrouter APi in the freeradius code.

* We have a pending release of mech_eap to support CA-based trust
  anchors to facilitate trust anchor key rollover.  We may also start
  moving towards more strict channel binding support in that release.

All this is coming together this July.
It will bring significant security enhancements, as well as enabling
better stability and robustness in terms of code, deployment and ongoing
development process.

The maintenance projects are also critical for a managed IDP and RP
service we're putting together for JANET.

--Sam

Top of Message | Previous Page | Permalink

JiscMail Tools


RSS Feeds and Sharing


Advanced Options


Archives

April 2024
March 2022
December 2021
October 2021
September 2021
August 2021
June 2021
April 2021
February 2021
January 2021
December 2020
November 2020
October 2020
August 2020
July 2020
June 2020
May 2020
April 2020
March 2020
February 2020
January 2020
December 2019
November 2019
October 2019
September 2019
July 2019
June 2019
May 2019
April 2019
March 2019
February 2019
January 2019
December 2018
November 2018
April 2018
February 2018
January 2018
December 2017
November 2017
September 2017
August 2017
July 2017
June 2017
May 2017
April 2017
February 2017
January 2017
December 2016
October 2016
September 2016
August 2016
June 2016
April 2016
March 2016
February 2016
January 2016
December 2015
November 2015
October 2015
August 2015
July 2015
May 2015
April 2015
March 2015
February 2015
January 2015
December 2014
November 2014
October 2014
September 2014
August 2014
July 2014
June 2014
May 2014
April 2014
March 2014
February 2014
January 2014
December 2013
November 2013
October 2013
September 2013
August 2013
July 2013


JiscMail is a Jisc service.

View our service policies at https://www.jiscmail.ac.uk/policyandsecurity/ and Jisc's privacy policy at https://www.jisc.ac.uk/website/privacy-notice

For help and support help@jisc.ac.uk

Secured by F-Secure Anti-Virus CataList Email List Search Powered by the LISTSERV Email List Manager