JiscMail Logo
Email discussion lists for the UK Education and Research communities

Help for MOONSHOT-DEV Archives


MOONSHOT-DEV Archives

MOONSHOT-DEV Archives


MOONSHOT-DEV@JISCMAIL.AC.UK


View:

Message:

[

First

|

Previous

|

Next

|

Last

]

By Topic:

[

First

|

Previous

|

Next

|

Last

]

By Author:

[

First

|

Previous

|

Next

|

Last

]

Font:

Proportional Font

LISTSERV Archives

LISTSERV Archives

MOONSHOT-DEV Home

MOONSHOT-DEV Home

MOONSHOT-DEV  February 2016

MOONSHOT-DEV February 2016

Options

Subscribe or Unsubscribe

Subscribe or Unsubscribe

Log In

Log In

Get Password

Get Password

Subject:

Re: Are Moonshot.*Targeted.*ID being used?

From:

Alejandro Pérez Méndez <[log in to unmask]>

Date:

Wed, 10 Feb 2016 13:13:10 +0100

Content-Type:

text/plain

Parts/Attachments:

Parts/Attachments

text/plain (63 lines)

In the last email from Rhys about these identifiers that I've been able 
to find, they are defined as:

1) AAA attribute of moonshot-service-targetedid.
* A persistent identifier per user, per service
* Value a hash of Gss-Acceptor-Service-Name, NAI, salt.
* Representation: [log in to unmask] [log in to unmask]

2) AAA attribute of moonshot-realm-targetedid.
* A persistent identifier per user, common across all services within a particular RP realm
* Value a hash of Gss-Acceptor-Realm-Name, NAI, salt.
* Representation: [log in to unmask] [log in to unmask]

3) AAA attribute of moonshot-tr-coi-targetedid.
* A persistent identifier per user, common across all services within a particular COI.
* Value a hash of CoI-Identifier, NAI, salt.
* Represented as [log in to unmask] [log in to unmask]


Although, for option 1, the value of Gss-Acceptor-Service-Name seems 
that might not be unique if Gss-Acceptor-Host-Name is not concatenated. 
For instance, when using mod_auth_gssapi, Gss-Acceptor-Service-Name 
would be just "HTTP", shared amongst every Moonshot-enabled HTTP server.

If I'm right, then I guess 1) should actually be something like:

* Value a hash of Gss-Acceptor-Service-Name, Gss-Acceptor-Host-Name, NAI, salt.

Regards,
Alejandro



El 09/02/16 a las 19:28, Sam Hartman escribió:
>>>>>> "Alejandro" == Alejandro Pérez Méndez <[log in to unmask]> writes:
>      Alejandro> El 09/02/16 a las 16:13, Sam Hartman escribió:
>      >>>>>>> "Alejandro" == Alejandro Pérez Méndez <[log in to unmask]> writes:
>      >>> If not, they should be done on the IdP and then released. It is
>      >>> then up to the Moonshot RP Proxy to do something with them.
>      Alejandro> Since they are representing the end user's identity, I
>      Alejandro> was expecting that it would be somehow the identifier
>      Alejandro> passed to the Application, instead of the useless
>      Alejandro> "@realm" anonymous identifier.  Ej. if scoped ID is found
>      Alejandro> by the mech_eap, use that as the name exported by the
>      Alejandro> GSS-API layer, overriding the value of the User-Name
>      Alejandro> attribute. In this way, legacy GSS-API applications that
>      Alejandro> do not ask for additinal naming attributes might work
>      Alejandro> with these pseudonyms in a transparent way.  Nonetheless,
>      Alejandro> updated applications might scan for the presence of these
>      Alejandro> identifiers and use them. But, as said, they need to know
>      Alejandro> they are being used.  Regards, Alejandro
>      >>
>      >> I don't think it would be a great idea for mech_eap to do this by
>      >> default.  Those IDs are I think fairly scoped to the
>      >> education/research community and mech_eap tries to be broader.
>      >> If I were deploying, I'd do what Stefan says and remap to
>      >> username in the RP proxy if that's what my application needed.
>
>      Alejandro> That's doable, right.
>
> Yes.  If an RP proxy sends back a username in the reply, that will be
> used.

Top of Message | Previous Page | Permalink

JiscMail Tools


RSS Feeds and Sharing


Advanced Options


Archives

March 2022
December 2021
October 2021
September 2021
August 2021
June 2021
April 2021
February 2021
January 2021
December 2020
November 2020
October 2020
August 2020
July 2020
June 2020
May 2020
April 2020
March 2020
February 2020
January 2020
December 2019
November 2019
October 2019
September 2019
July 2019
June 2019
May 2019
April 2019
March 2019
February 2019
January 2019
December 2018
November 2018
April 2018
February 2018
January 2018
December 2017
November 2017
September 2017
August 2017
July 2017
June 2017
May 2017
April 2017
February 2017
January 2017
December 2016
October 2016
September 2016
August 2016
June 2016
April 2016
March 2016
February 2016
January 2016
December 2015
November 2015
October 2015
August 2015
July 2015
May 2015
April 2015
March 2015
February 2015
January 2015
December 2014
November 2014
October 2014
September 2014
August 2014
July 2014
June 2014
May 2014
April 2014
March 2014
February 2014
January 2014
December 2013
November 2013
October 2013
September 2013
August 2013
July 2013


JiscMail is a Jisc service.

View our service policies at https://www.jiscmail.ac.uk/policyandsecurity/ and Jisc's privacy policy at https://www.jisc.ac.uk/website/privacy-notice

For help and support help@jisc.ac.uk

Secured by F-Secure Anti-Virus CataList Email List Search Powered by the LISTSERV Email List Manager