OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

security-services message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]


Subject: AuthenticatorLocale Definition


The current core describes AuthenticatorLocale thus:

The <AuthenticationLocale> element specifies the DNS domain name and IP
address for the system entity that performed the authentication.

IMO this might reasonably be interpreted as the IP and DNS of the
Authentication Authority, or associated server that validated the
credentials. Is that what was wanted? My understanding was that we wanted
the IP and DNS or the client being authenticated.

Proposed wording:

The <AuthenticationLocale> element specifies the DNS domain name and IP
address of the host  which the system entity used when it was authenticated.

-----------------

I would also like to see the semantics of the DNS name specified explicitly
(or the element dropped.)

Proposed wording:

The DNS domain name is the result of doing a reverse lookup on the IP
address contained in the authentication messages at the time the
Authentication took place.

Note: we already have issues open on this stuff: DS-7-04 and DS-7-05.

Hal


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]


Powered by eList eXpress LLC