[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: Follow up on Authorize Only issue
- To: "Nelson, David" <dnelson@enterasys.com>, <isms@ietf.org>, <radiusext@ops.ietf.org>
- Subject: RE: Follow up on Authorize Only issue
- From: "Joseph Salowey \(jsalowey\)" <jsalowey@cisco.com>
- Date: Fri, 21 Jul 2006 14:27:47 -0700
- Authentication-results: sj-dkim-1.cisco.com; header.From=jsalowey@cisco.com; dkim=pass ( sig from cisco.com verified; );
- Dkim-signature: a=rsa-sha1; q=dns; l=1205; t=1153517329; x=1154381329; c=relaxed/simple; s=sjdkim1002; h=Content-Type:From:Subject:Content-Transfer-Encoding:MIME-Version; d=cisco.com; i=jsalowey@cisco.com; z=From:=22Joseph=20Salowey=20\(jsalowey\)=22=20<jsalowey@cisco.com> |Subject:RE=3A=20Follow=20up=20on=20Authorize=20Only=20issue; X=v=3Dcisco.com=3B=20h=3DObZ73vujEK3pOnVK5sX7aGBdRmQ=3D; b=lcXQGZYhHEpGogR4VQcF0UrnZIgeHKDr+VygJBOHaHo4ZZZRsfFRea6U7ux+fntN6KT+8SXG B1m1wXHRqEBwjh3yK55mqYpM6qqLgcDXC/9fKZA/NeBzMIxh9T09jOm7;
I agree with Avi, Glen and Alan.
> -----Original Message-----
> From: owner-radiusext@ops.ietf.org
> [mailto:owner-radiusext@ops.ietf.org] On Behalf Of Nelson, David
> Sent: Friday, July 21, 2006 1:44 PM
> To: isms@ietf.org; radiusext@ops.ietf.org
> Subject: RE: Follow up on Authorize Only issue
>
> > For the SSHSM usage case, the question is whether it is an
> > unacceptable security risk for a trusted NAS to be able to obtain
> > authorization information about a user that is not actually
> "present"
> > at the NAS?
>
> My interpretation is that three respondents (Glen, Alan, Avi)
> believe that the answer is "no". The existing RADIUS trust
> model collapses if the NAS has been compromised and does
> nefarious or foolish things.
>
> I'd like to determine if we have consensus on this position. If you
> *have* an opinion on this issue, please *respond* whether you
> agree or disagree with this assertion.
>
>
> --
> to unsubscribe send a message to
> radiusext-request@ops.ietf.org with the word 'unsubscribe' in
> a single line as the message text body.
> archive: <http://psg.com/lists/radiusext/>
>
--
to unsubscribe send a message to radiusext-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://psg.com/lists/radiusext/>