[154010] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

AAA design document pointers

daemon@ATHENA.MIT.EDU (Jay Ashworth)
Wed Jun 20 20:00:00 2012

Date: Wed, 20 Jun 2012 19:59:09 -0400 (EDT)
From: Jay Ashworth <jra@baylink.com>
To: NANOG <nanog@nanog.org>
In-Reply-To: <16360948.10276.1340236470252.JavaMail.root@benjamin.baylink.com>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

My takeaway from the conversations we're having as the second and third-order
resultants of the LinkedIn password break is that, if there *is* an accepted
definition of the problem, in slices small enough for implementers to 
understand, a lot of people haven't read it.  Including me.

*Is* there a good defnition of the current shape of the authentication/
authorization problem as it presently exists in the Wide Area with the
General Public as audience, which someone can point to?

One that identifies, as it goes along, all the points we batted around
today, like "person or PC", "multiple accounts", "non/repudiation",
and whatever you call "multiple services not being able to tell you're
the same person as an account holder, unless you *want* them to"?

Not even the solutions, you understand, just the definition of the
problem?  Seems to me we're on different pages in the hymnal...

Off-list, please; I'll summarize.

Cheers,
-- jra
-- 
Jay R. Ashworth                  Baylink                       jra@baylink.com
Designer                     The Things I Think                       RFC 2100
Ashworth & Associates     http://baylink.pitas.com         2000 Land Rover DII
St Petersburg FL USA      http://photo.imageinc.us             +1 727 647 1274


home help back first fref pref prev next nref lref last post