ad-assurance - [AD-Assurance] RE: AD Silver Comment - AAC Response
Subject: Meeting the InCommon Assurance profile criteria using Active Directory
List archive
- From: "Capehart,Jeffrey D" <>
- To: "" <>
- Subject: [AD-Assurance] RE: AD Silver Comment - AAC Response
- Date: Tue, 1 Apr 2014 14:54:07 +0000
- Accept-language: en-US
Wow, yes, very interesting responses. My take: 1)
Protected channels aren’t required? That’s pretty generous, probably a lot more loose than many of us have been thinking, but it will make it easier for AD. That could open the door for Eduroam, Radius,
and perhaps some other protocols. 2)
Well, we were thinking the protocol was the key, but with statement #1, is that a moot issue other than a best practice recommendation? 3)
Seems to agree with the thinking behind 1 & 2. So, based on a lot of this interpretation, it really seems like it would be a good idea to call out some best practices in the cookbook. Perhaps something like a minimal level to meet Silver would be X, but
an improved/better/stronger level would be to do some other things (NTLMv2, etc.) Without being a party to the actual AAC discussions, it is difficult to know for certain that they understand all the risks involved. I only say that because a decision made just reading the emailed questions
may miss some technical nuances like password v. hash v. encrypted challenge, etc. that we have been struggling with as to what will comply. I think that having to keep a list of approved protocols would be a nightmare, something no one wants to have to do. So perhaps that falls under the risk assessment or some other part of the IAP, but is really
left up to each implementer to decide. Also I keep coming back to wondering what the next iteration of the IAP will look like considering all the questions and problems we have had. Keeping it vague gives a lot of flexibility but could make it where
two silver institutions have quite different protection levels for their secrets. Thank you for sharing Eric, and all your work putting the questions together! Jeff From: [mailto:]
On Behalf Of Eric Goodman Hi all, Interesting response on question number one. The others are pretty much as we expect. I haven't had a chance to process how the first response might change the Cookbook, but didn't want to wait to share with the list. --- Eric
|
- [AD-Assurance] Fwd: AD Silver Comment - AAC Response, Eric Goodman, 04/01/2014
- [AD-Assurance] RE: AD Silver Comment - AAC Response, Capehart,Jeffrey D, 04/01/2014
- Re: [AD-Assurance] RE: AD Silver Comment - AAC Response, David Walker, 04/01/2014
- RE: [AD-Assurance] RE: AD Silver Comment - AAC Response, Eric Goodman, 04/01/2014
- RE: [AD-Assurance] RE: AD Silver Comment - AAC Response, Capehart,Jeffrey D, 04/01/2014
- RE: [AD-Assurance] RE: AD Silver Comment - AAC Response, Eric Goodman, 04/01/2014
- Re: [AD-Assurance] RE: AD Silver Comment - AAC Response, David Walker, 04/02/2014
- RE: [AD-Assurance] RE: AD Silver Comment - AAC Response, Eric Goodman, 04/02/2014
- Re: [AD-Assurance] RE: AD Silver Comment - AAC Response, David Walker, 04/02/2014
- RE: [AD-Assurance] RE: AD Silver Comment - AAC Response, Curry, Warren, 04/02/2014
- Re: [AD-Assurance] RE: AD Silver Comment - AAC Response, David Walker, 04/02/2014
- RE: [AD-Assurance] RE: AD Silver Comment - AAC Response, Eric Goodman, 04/01/2014
- RE: [AD-Assurance] RE: AD Silver Comment - AAC Response, Capehart,Jeffrey D, 04/01/2014
- RE: [AD-Assurance] RE: AD Silver Comment - AAC Response, Eric Goodman, 04/01/2014
- Re: [AD-Assurance] RE: AD Silver Comment - AAC Response, David Walker, 04/01/2014
- [AD-Assurance] RE: AD Silver Comment - AAC Response, Capehart,Jeffrey D, 04/01/2014
Archive powered by MHonArc 2.6.16.