Credential Delegation Protocol specification: Request for CommentsThis document will act as RFC centre for the Credential Delegation Protocol specification Proposed Recommendation v1.0. Review period: 2008 September 26 – 2008 October 24 In order to add a comment to the document, please edit this page and add your comment to the list below (include your WikiName so authors can contact you for further information). When the author(s) of the document have considered the comment, they will provide a response after the comment. Discussions about any of the comments or responses should be conducted on the GWS mailing list, grid@ivoa.net.Comments from the community
RayPlante
In IVOA protocols, a client must delegate credentials before calling a service that needs to use delegated credentials. The client can find out the need for delegation from the service registration.
The delegation process is enabled via a set of four service components that are each accessible via a URL which we refer to as web resources.
BobHanischI also had difficulty parsing this document, and agree with Ray's suggestions about changing the formatting and structure. Not being an expert in this area, though, I wonder if the document is even necessary. It refers to a Globus and IETF specification as its basis. If this is a subset of those specifications, wouldn't it be easier just to say what subset it is? What is unique to this specification, and where does it diverge from existing practice in other standards? And why? Can't we just say that IVOA Credential Delegation is handled in accord with IETF x.x, Globus whatever, with the following (hopefully short list of) restrictions and/or deviations? 29 Sept 2008 The relevant IETF standard is RFC3820 "Internet X.509 Public Key Infrastructure (PKI): Proxy Certificate Profile". It defines what is in the proxy certificates, not how to get one into the service of choice. The normative text concerning the format and content of the proxies in the document under review does as you ask: it refers to the RFC and details only the special use for IVOA. Although our protocol is inspired by the Globus one, and uses the good ideas of the latter, it's a separate thing. Our protocol defines a REST service; the Globus one is a SOAP service. Our protocol does not require changes to the protocols (DAL etc.) which which it is mixed; the Globus one requires the addition of an extra parameters of those protocols. Our delegation protocol does not require elaborate authentication of the act of delegation itself; the Globus one requires authentication operations that are not standard either for IVOA or the rest of the Globus Toolkit. Basically, the Globus protocol wasn't suitable for IVOA so a new one was devised. It can't usefully be specified as a delta on the Globus standard. If it is useful, I can list in the introduction that things that were found undesirable in the Globus delegation protocol and the motivations for designing our own. -- GuyRixon - 20 Oct 2008TCG Review (from 21/09/2009 to 16/10/2009)During the TCG review, Working and Interest Group chairs should add their comments under their name:Applications (Tom McGlynn, Mark Taylor)Data Access Layer (Keith Noddle, Jesus Salgado)Data Model (Mireille Louys, Anita Richards)Grid & Web Services (Matthew Graham, Paul Harrison)Registry (Ray Plante, Aurelien Stebe)Semantics (Sebastien Derriere, Norman Gray)VOEvent (Rob Seaman, Alasdair Allan)VO Query Language (Pedro Osuna, Yuji Shirasaki)VOTable (Francois Ochsenbein)Standard and Processes (Francoise Genova)Astro RG (Masatoshi Ohishi)Data Curation & Preservation (Bob Hanisch) | ||||||||
Added: | ||||||||
> > | I have no particular comments on content at this point. I do note, however, that I had problems with viewing the document itself. The Word version came across with extraneous boxes, the HTML version displays with strange characters, and the PDF version displays properly for me only after I download it and display it locally. I wonder if anyone else sees similar problems. | |||||||
Theory (Herve Wozniak, Claudio Gheller)TCG (Christophe Arviset, Severin Gaudet)<--
<--
|