ad-assurance - RE: [AD-Assurance] RE: [aac] Assurance Cookbook: February 2014 Interpretation Sections
Subject: Meeting the InCommon Assurance profile criteria using Active Directory
List archive
RE: [AD-Assurance] RE: [aac] Assurance Cookbook: February 2014 Interpretation Sections
Chronological Thread
- From: Eric Goodman <>
- To: "" <>
- Subject: RE: [AD-Assurance] RE: [aac] Assurance Cookbook: February 2014 Interpretation Sections
- Date: Wed, 19 Mar 2014 16:37:07 +0000
- Accept-language: en-US
I understand what you are saying. My notes from the meeting just don’t agree with you. :) They clearly state I’m supposed to be asking a question.
I can just incorporate your simplification of my language, but still leave it as a question or indicate that it a statement that we want confirmed. I agree your presentation is much more straightforward than
mine in any case. (If we agree this is the case, we should probably call it out in the Cookbook somewhere for clarity). That said, I see risk in suggesting alignment with the language in NIST 800-63. Alignment would rule out use of NTLMv2 (implicitly) and Windows Kerberos with user-selected passwords (explicitly), not just NTLMv1.
So I wouldn’t go so far as to recommend that the AAC seek to match the 800-63 requirements if we want silver credentials to be able to exist in ADs. Shall I make the change to use David’s language minus the recommendation for alignment? I’ll still have to look a bit to see where we’d add language in the Cookbook to add this assertion/distinction (NTLMv1 being a good idea, not a compliance issue). I’m thinking it would go somewhere in the discussion
of the “general issues”, but haven’t looked that closely yet. --- Eric From: [mailto:]
On Behalf Of David Walker Eric,
David On 03/18/2014 03:45 PM, Eric Goodman wrote:
|
- Re: [AD-Assurance] RE: [aac] Assurance Cookbook: February 2014 Interpretation Sections, Ann West, 03/12/2014
- RE: [AD-Assurance] RE: [aac] Assurance Cookbook: February 2014 Interpretation Sections, Eric Goodman, 03/18/2014
- Re: [AD-Assurance] RE: [aac] Assurance Cookbook: February 2014 Interpretation Sections, David Walker, 03/18/2014
- RE: [AD-Assurance] RE: [aac] Assurance Cookbook: February 2014 Interpretation Sections, Eric Goodman, 03/19/2014
- Re: [AD-Assurance] RE: [aac] Assurance Cookbook: February 2014 Interpretation Sections, David Walker, 03/19/2014
- RE: [AD-Assurance] RE: [aac] Assurance Cookbook: February 2014 Interpretation Sections, Eric Goodman, 03/19/2014
- Re: [AD-Assurance] RE: [aac] Assurance Cookbook: February 2014 Interpretation Sections, David Walker, 03/18/2014
- RE: [AD-Assurance] RE: [aac] Assurance Cookbook: February 2014 Interpretation Sections, Eric Goodman, 03/18/2014
Archive powered by MHonArc 2.6.16.