Editor's note: These minutes have not been edited.
ONC RPC (ONCRPC) Working Group Minutes,
San Jose IETF, December 1996, reported by Steve Nahm (Sun Microsystems)
- The working group met in one session on Monday. Ted Tso (MIT) and
- Steve Nahm co-chaired the meeting.
- There are three RFCs currently at Proposed Standard:
- RFC1831: RPC: Remote Procedure Call Protocol
- Specification Version 2
- RFC1833: Binding Protocols for ONC RPC Version 2
- RFC1832: XDR: External Data Representation Standard
- Each of these were requested to be elevated to Draft Standard in
- September. After review by IESG, the core RPC specifications were held
- to be incomplete because they did not include a strong authentication
- mechanism. IESG required that such a mechanism be submitted prior to
- advancing the core RPC specifications. This requirement does not apply
- to XDR, and that document is currently pending advancement to Draft
- Standard.
- Other documents currently active:
- draft-ietf-oncrpc-remote-02.txt (RPC)
- draft-ietf-oncrpc-rpcbind-01.txt (RPC Binding)
- These are revisions to RFC1831 and RFC1833 based on Montreal WG input.
- There are no known outstanding WG issues with these documents, which
- was the specifications which were submitted for advancement to Draft
- Standard. IESG offered to recycle these specifications as Proposed
- Standards. The concensus of the working group was that this was not
- necessary, and the drafts would be resubmitted when the security
- specification is ready, unblocking the core RPC specifications for
- advancement to Draft Standard.
- draft-ietf-oncrpc-auth-02.txt (Authentication Mechanisms)
- There are no known outstanding issues with this document. It too is
- being withheld pending progress on the IESG requirement. This draft is
- intended to be submitted as an Informational RFC.
- draft-ietf-oncrpc-rpcsec_gss-01.txt (RPCSEC_GSS)
- Mike Eisler, Editor
- This draft is the basis for satisfying the IESG's requirement. It is
- discussed further below.
- The charter of this working was revised since the last meeting. The
- primary change was the addition of language to include work on
- developing a security mechanism which satisfies the IESG requirement.
- The working group believes that the RPCSEC_GSS mechanism satisfies this
- requirement, and the new timetable reflects this. Refer to the ONC RPC
- WG Charter for additional details.
- Mike Eisler presented a summary of the issues raised via the mailing
- list on draft-ietf-oncrpc-rpcsec_gss-01.txt (RPCSEC_GSS). His slides
- are included in the proceedings.
- The issues which Mike considers as RESOLVED are:
- 1) Clarify description of Context Management (section to
- emphasize "that the integrity check on an incoming message is to be
- validated before adjusting the receive window in response to the
- incoming message's sequence number."
- 2) Rename RPCSEC_GSS_NOCRED and RPCSEC_GSS_FAILED error code names to
- avoid confusion with GSS API's GSS_NO_CRED and GSS_FAILURE. Mike also
- agreed to try to define the mapping between specific GSS-level major
- status codes and the corresponding RPC layer error codes.
- 3) Clarify section language regarding generation of session
- handles. Mike omitted a "not" in the confusing sentence. He proposed
- that the offending sentence be deleted from section; the
- working group consensus agreed with this.
- 4) Clarify section 6.2 to explain that there is an attack possible
- where the attacker sends fake requests above the sequence number
- window, which will not be rejected by the sequence number check, but
- will force the server to validate the header checksum and fail. Mike
- agreed to clarify this section.
- Ted Tso led the review and discussion of the unresolved issues, using Mike's
- slides as the starting point.
- 1) John Linn had observed on the mailing list that there is no facility
- within RPCSEC_GSS to negotiate what GSS-API mechanism to use, so
- mechanism selection must be a) static; b) performed out-of-band or c)
- negotiated within the GSS layer. An anonymous commenter wrote to Mike
- Eisler that without a means to negotiate quality of protection (QOP) of
- authentication flavor, ONC RPC will not meet his needs.
- Marc Horowitz stated that negotiation of mechanism should be done
- within the GSS layer. John Linn clarified that he didn't mean to imply
- through his comment that there had to be a negotiation mechanism in the
- proposal. Ted stated that the CAT working group believes there is a
- potentially useful means to negotiate mechanism being implemented
- within GSS and that free code is available.
- The concensus of the working group was to not hold back draft due to
- this issue.
- 2) Several issues were raised regarding specification of QOP and
- service values. The initialization phase of RPCSEC_GSS allows the
- client to specify a QOP and service. John Linn asked on the mailing
- list whether the RPC layer is expected to choose these, or whether the
- relevant GSS mechanism ID will be reflected up to the
- user/application/caller of the RPC layer to allow it to select a QOP
- suitable to the prevailing mechanism. Mike explained that the API is
- expected to provide mechanism selection input/output to the client and
- server. He is willing update the draft to reflect this.
- Further discussion questioned the benefit of specifying the QOP and
- service in the init request. A simplifying proposal was made by Marc
- to drop QOP and service specification from rpc_gss_init_arg and to
- integrity protect seq_window using the "default" QOP in the final
- (GSS_S_COMPLETE) rpc_gss_init_res response. This addresses Barry
- Jaspan's suggestion that the seq_window be protected to avoid denial of
- service attacks that would use that field.
- The consensus was to do this.
- 3) Marc stated in mail to the list that the version negotiation
- procedure seems complex. He proposed to delete it. Mike supported
- this stating that we could invent a negotiation mechanism later when/if
- additional versions of RPCSEC_GSS are defined.
- Concensus was to do delete version negotiation.
- 4) Marc suggested in mail to the list that gss_wrap() be used for both
- integrity and encryption, rather than using gss_get_mic() for integrity
- and gss_wrap() for encryption. Mike stated that gss_get_mic() was used
- for integrity to avoid an unnecessary byte copy. Marc conceded the
- efficiency issue and was willing to drop this issue.
- 5) Marc stated in mail to the list that section 5.2.1 text is
- misleading and should be corrected. After discussion with those
- present, Mike agreed to correct the wording, dropping the phrase "for
- those mechanisms that require context creation messages."
- 6) Marc asked why gss_proc is not an enum. Mike agreed that it should
- be an enum.
- 7) Marc stated in mail to the list that V2 GSS-API names should be used
- by this draft. Mike queried Allison Mankin about the status of the
- GSS-API V2 draft. She said that it's in the queue, and that since the
- RPCSEC_GSS draft would be behind GSS-API in the RFC queue, it would be
- safe to use the V2 names.
- 8) Allison asked whether the working group believed that the issues
- raised by Keith Moore are resolved. Keith believes that the
- specification should state that certain mechanisms must be supported in
- order to be compliant.
- Marc felt that each RPC application will need to determine what is
- appropriate for it. What's right for one RPC application might not be
- right for everything else. John Linn said that the mechanism to use
- largely falls out of the operation environment in which the application
- is running.
- Allison said that she thinks we should specify a minimum level of
- security.
- Marc observed that we can't prevent insecurity at user's sites.
- Putting such a requirement into the specification may have an effect on
- vendors, but user don't have to use it.
- Ted proposed that we put a statement in the core RPC specs that
- implementation of RPCSEC_GSS standard is required. Allison asked if
- this meant specifying the actual mechanism to use (Kerberos, or public
- key, or something else).
- John stated that he would like to see statement like: "For Internet
- Standard purposes, implementation of RPCSEC_GSS under one or more
- GSS-API standard mechanisms."
- Allison asked, shouldn't we give specific advice to implementors as to
- how to approach this area? Ted said that this is largely an
- infrastructure issue. How can we give advice when we don't know what
- infrastructure is supported?
- Mike said that NFS would have to define the security mechanism it can
- use in its own specification.
- John asked how this issue has this been handled before? Ted said that
- IMAP POP3 use of GSS-API was specified in a separate RFC that made no
- statements about requirements.
- Roland Schemers asked if CAT could be requested to develop a
- lightweight GSS mechanism to avoid the infrastructure issue.
- Allison wants a statement in the core RPC specification that RPCSEC_GSS
- is required to be implemented. Then, the RPCSEC_GSS specification
- should state that when you reference it, you must also state what
- mechanism you support. Brent Callaghan, who is holding an NFS BOF
- later in IETF, agreed to raise this issue at the NFS BOF.
- Ted observed that even having a base set of mechanisms, you still may
- not have parties sharing a mechanism. He said that IESG should
- consider specifying what mechanisms are to be used within the
- Internet. Allison agreed that this would be a good idea.
- %!PS-Adobe-3.0
- %%Creator: Windows PSCRIPT
- %%Title: PowerPoint - OWGJOSE.PPT
- %%BoundingBox: 14 9 597 784
- %%DocumentNeededResources: (atend)
- %%DocumentSuppliedResources: (atend)
- %%Pages: (atend)
- %%BeginResource: procset Win35Dict 3 1
- /Win35Dict 290 dict def Win35Dict begin/bd{bind def}bind def/in{72
- mul}bd/ed{exch def}bd/ld{load def}bd/tr/translate ld/gs/gsave ld/gr
- /grestore ld/M/moveto ld/L/lineto ld/rmt/rmoveto ld/rlt/rlineto ld
- /rct/rcurveto ld/st/stroke ld/n/newpath ld/sm/setmatrix ld/cm/currentmatrix
- ld/cp/closepath ld/ARC/arcn ld/TR{65536 div}bd/lj/setlinejoin ld/lc
- /setlinecap ld/ml/setmiterlimit ld/sl/setlinewidth ld/scignore false
- def/sc{scignore{pop pop pop}{0 index 2 index eq 2 index 4 index eq
- and{pop pop 255 div setgray}{3{255 div 3 1 roll}repeat setrgbcolor}ifelse}ifelse}bd
- /FC{bR bG bB sc}bd/fC{/bB ed/bG ed/bR ed}bd/HC{hR hG hB sc}bd/hC{
- /hB ed/hG ed/hR ed}bd/PC{pR pG pB sc}bd/pC{/pB ed/pG ed/pR ed}bd/sM
- matrix def/PenW 1 def/iPen 5 def/mxF matrix def/mxE matrix def/mxUE
- matrix def/mxUF matrix def/fBE false def/iDevRes 72 0 matrix defaultmatrix
- dtransform dup mul exch dup mul add sqrt def/fPP false def/SS{fPP{
- /SV save def}{gs}ifelse}bd/RS{fPP{SV restore}{gr}ifelse}bd/EJ{gsave
- showpage grestore}bd/#C{userdict begin/#copies ed end}bd/FEbuf 2 string
- def/FEglyph(G )def/FE{1 exch{dup 16 FEbuf cvrs FEglyph exch 1 exch
- putinterval 1 index exch FEglyph cvn put}for}bd/SM{/iRes ed/cyP ed
- /cxPg ed/cyM ed/cxM ed 72 100 div dup scale dup 0 ne{90 eq{cyM exch
- 0 eq{cxM exch tr -90 rotate -1 1 scale}{cxM cxPg add exch tr +90 rotate}ifelse}{cyP
- cyM sub exch 0 ne{cxM exch tr -90 rotate}{cxM cxPg add exch tr -90
- rotate 1 -1 scale}ifelse}ifelse}{pop cyP cyM sub exch 0 ne{cxM cxPg
- add exch tr 180 rotate}{cxM exch tr 1 -1 scale}ifelse}ifelse 100 iRes
- div dup scale 0 0 transform .25 add round .25 sub exch .25 add round
- .25 sub exch itransform translate}bd/SJ{1 index 0 eq{pop pop/fBE false
- def}{1 index/Break ed div/dxBreak ed/fBE true def}ifelse}bd/ANSIVec[
- 16#0/grave 16#1/acute 16#2/circumflex 16#3/tilde 16#4/macron 16#5/breve
- 16#6/dotaccent 16#7/dieresis 16#8/ring 16#9/cedilla 16#A/hungarumlaut
- 16#B/ogonek 16#C/caron 16#D/dotlessi 16#27/quotesingle 16#60/grave
- 16#7C/bar 16#82/quotesinglbase 16#83/florin 16#84/quotedblbase 16#85
- /ellipsis 16#86/dagger 16#87/daggerdbl 16#88/circumflex 16#89/perthousand
- 16#8A/Scaron 16#8B/guilsinglleft 16#8C/OE 16#91/quoteleft 16#92/quoteright
- 16#93/quotedblleft 16#94/quotedblright 16#95/bullet 16#96/endash 16#97
- /emdash 16#98/tilde 16#99/trademark 16#9A/scaron 16#9B/guilsinglright
- 16#9C/oe 16#9F/Ydieresis 16#A0/space 16#A1/exclamdown 16#A4/currency
- 16#A5/yen 16#A6/brokenbar 16#A7/section 16#A8/dieresis 16#A9/copyright
- 16#AA/ordfeminine 16#AB/guillemotleft 16#AC/logicalnot 16#AD/hyphen
- 16#AE/registered 16#AF/macron 16#B0/degree 16#B1/plusminus 16#B2/twosuperior
- 16#B3/threesuperior 16#B4/acute 16#B5/mu 16#B6/paragraph 16#B7/periodcentered
- 16#B8/cedilla 16#B9/onesuperior 16#BA/ordmasculine 16#BB/guillemotright
- 16#BC/onequarter 16#BD/onehalf 16#BE/threequarters 16#BF/questiondown
- 16#C0/Agrave 16#C1/Aacute 16#C2/Acircumflex 16#C3/Atilde 16#C4/Adieresis
- 16#C5/Aring 16#C6/AE 16#C7/Ccedilla 16#C8/Egrave 16#C9/Eacute 16#CA
- /Ecircumflex 16#CB/Edieresis 16#CC/Igrave 16#CD/Iacute 16#CE/Icircumflex
- 16#CF/Idieresis 16#D0/Eth 16#D1/Ntilde 16#D2/Ograve 16#D3/Oacute 16#D4
- /Ocircumflex 16#D5/Otilde 16#D6/Odieresis 16#D7/multiply 16#D8/Oslash
- 16#D9/Ugrave 16#DA/Uacute 16#DB/Ucircumflex 16#DC/Udieresis 16#DD/Yacute
- 16#DE/Thorn 16#DF/germandbls 16#E0/agrave 16#E1/aacute 16#E2/acircumflex
- 16#E3/atilde 16#E4/adieresis 16#E5/aring 16#E6/ae 16#E7/ccedilla 16#E8
- /egrave 16#E9/eacute 16#EA/ecircumflex 16#EB/edieresis 16#EC/igrave
- 16#ED/iacute 16#EE/icircumflex 16#EF/idieresis 16#F0/eth 16#F1/ntilde
- 16#F2/ograve 16#F3/oacute 16#F4/ocircumflex 16#F5/otilde 16#F6/odieresis
- 16#F7/divide 16#F8/oslash 16#F9/ugrave 16#FA/uacute 16#FB/ucircumflex
- 16#FC/udieresis 16#FD/yacute 16#FE/thorn 16#FF/ydieresis ] def/reencdict
- 12 dict def/IsChar{basefontdict/CharStrings get exch known}bd/MapCh{dup
- IsChar not{pop/bullet}if newfont/Encoding get 3 1 roll put}bd/MapDegree{16#b0
- /degree IsChar{/degree}{/ring}ifelse MapCh}bd/MapBB{16#a6/brokenbar
- IsChar{/brokenbar}{/bar}ifelse MapCh}bd/ANSIFont{reencdict begin/newfontname
- ed/basefontname ed FontDirectory newfontname known not{/basefontdict
- basefontname findfont def/newfont basefontdict maxlength dict def basefontdict{exch
- dup/FID ne{dup/Encoding eq{exch dup length array copy newfont 3 1 roll
- put}{exch newfont 3 1 roll put}ifelse}{pop pop}ifelse}forall newfont
- /FontName newfontname put 127 1 159{newfont/Encoding get exch/bullet
- put}for ANSIVec aload pop ANSIVec length 2 idiv{MapCh}repeat MapDegree
- MapBB newfontname newfont definefont pop}if newfontname end}bd/SB{FC
- /ULlen ed/str ed str length fBE not{dup 1 gt{1 sub}if}if/cbStr ed
- /dxGdi ed/y0 ed/x0 ed str stringwidth dup 0 ne{/y1 ed/x1 ed y1 y1
- mul x1 x1 mul add sqrt dxGdi exch div 1 sub dup x1 mul cbStr div exch
- y1 mul cbStr div}{exch abs neg dxGdi add cbStr div exch}ifelse/dyExtra
- ed/dxExtra ed x0 y0 M fBE{dxBreak 0 BCh dxExtra dyExtra str awidthshow}{dxExtra
- dyExtra str ashow}ifelse fUL{x0 y0 M dxUL dyUL rmt ULlen fBE{Break
- add}if 0 mxUE transform gs rlt cyUL sl [] 0 setdash st gr}if fSO{x0
- y0 M dxSO dySO rmt ULlen fBE{Break add}if 0 mxUE transform gs rlt cyUL
- sl [] 0 setdash st gr}if n/fBE false def}bd/font{/name ed/Ascent ed
- 0 ne/fT3 ed 0 ne/fSO ed 0 ne/fUL ed/Sy ed/Sx ed 10.0 div/ori ed -10.0
- div/esc ed/BCh ed name findfont/xAscent 0 def/yAscent Ascent def/ULesc
- esc def ULesc mxUE rotate pop fT3{/esc 0 def xAscent yAscent mxUE transform
- /yAscent ed/xAscent ed}if [Sx 0 0 Sy neg xAscent yAscent] esc mxE
- rotate mxF concatmatrix makefont setfont [Sx 0 0 Sy neg 0 Ascent] mxUE
- mxUF concatmatrix pop fUL{currentfont dup/FontInfo get/UnderlinePosition
- known not{pop/Courier findfont}if/FontInfo get/UnderlinePosition get
- 1000 div 0 exch mxUF transform/dyUL ed/dxUL ed}if fSO{0 .3 mxUF transform
- /dySO ed/dxSO ed}if fUL fSO or{currentfont dup/FontInfo get/UnderlineThickness
- known not{pop/Courier findfont}if/FontInfo get/UnderlineThickness get
- 1000 div Sy mul/cyUL ed}if}bd/min{2 copy gt{exch}if pop}bd/max{2 copy
- lt{exch}if pop}bd/CP{/ft ed{{ft 0 eq{clip}{eoclip}ifelse}stopped{currentflat
- 1 add setflat}{exit}ifelse}loop}bd/patfont 10 dict def patfont begin
- /FontType 3 def/FontMatrix [1 0 0 -1 0 0] def/FontBBox [0 0 16 16]
- def/Encoding StandardEncoding def/BuildChar{pop pop 16 0 0 0 16 16
- setcachedevice 16 16 false [1 0 0 1 .25 .25]{pat}imagemask}bd end/p{
- /pat 32 string def{}forall 0 1 7{dup 2 mul pat exch 3 index put dup
- 2 mul 1 add pat exch 3 index put dup 2 mul 16 add pat exch 3 index
- put 2 mul 17 add pat exch 2 index put pop}for}bd/pfill{/PatFont patfont
- definefont setfont/ch(AAAA)def X0 64 X1{Y1 -16 Y0{1 index exch M ch
- show}for pop}for}bd/vert{X0 w X1{dup Y0 M Y1 L st}for}bd/horz{Y0 w
- Y1{dup X0 exch M X1 exch L st}for}bd/fdiag{X0 w X1{Y0 M X1 X0 sub dup
- rlt st}for Y0 w Y1{X0 exch M Y1 Y0 sub dup rlt st}for}bd/bdiag{X0 w
- X1{Y1 M X1 X0 sub dup neg rlt st}for Y0 w Y1{X0 exch M Y1 Y0 sub dup
- neg rlt st}for}bd/AU{1 add cvi 15 or}bd/AD{1 sub cvi -16 and}bd/SHR{pathbbox
- AU/Y1 ed AU/X1 ed AD/Y0 ed AD/X0 ed}bd/hfill{/w iRes 37.5 div round
- def 0.1 sl [] 0 setdash n dup 0 eq{horz}if dup 1 eq{vert}if dup 2 eq{fdiag}if
- dup 3 eq{bdiag}if dup 4 eq{horz vert}if 5 eq{fdiag bdiag}if}bd/F{/ft
- ed fm 256 and 0 ne{gs FC ft 0 eq{fill}{eofill}ifelse gr}if fm 1536
- and 0 ne{SHR gs HC ft CP fm 1024 and 0 ne{/Tmp save def pfill Tmp restore}{fm
- 15 and hfill}ifelse gr}if}bd/S{PenW sl PC st}bd/m matrix def/GW{iRes
- 12 div PenW add cvi}bd/DoW{iRes 50 div PenW add cvi}bd/DW{iRes 8 div
- PenW add cvi}bd/SP{/PenW ed/iPen ed iPen 0 eq iPen 6 eq or{[] 0 setdash}if
- iPen 1 eq{[DW GW] 0 setdash}if iPen 2 eq{[DoW GW] 0 setdash}if iPen
- 3 eq{[DW GW DoW GW] 0 setdash}if iPen 4 eq{[DW GW DoW GW DoW GW] 0
- setdash}if}bd/E{m cm pop tr scale 1 0 moveto 0 0 1 0 360 arc cp m sm}bd
- /AG{/sy ed/sx ed sx div 4 1 roll sy div 4 1 roll sx div 4 1 roll sy
- div 4 1 roll atan/a2 ed atan/a1 ed sx sy scale a1 a2 ARC}def/A{m cm
- pop tr AG m sm}def/P{m cm pop tr 0 0 M AG cp m sm}def/RRect{n 4 copy
- M 3 1 roll exch L 4 2 roll L L cp}bd/RRCC{/r ed/y1 ed/x1 ed/y0 ed/x0
- ed x0 x1 add 2 div y0 M x1 y0 x1 y1 r arcto 4{pop}repeat x1 y1 x0 y1
- r arcto 4{pop}repeat x0 y1 x0 y0 r arcto 4{pop}repeat x0 y0 x1 y0 r
- arcto 4{pop}repeat cp}bd/RR{2 copy 0 eq exch 0 eq or{pop pop RRect}{2
- copy eq{pop RRCC}{m cm pop/y2 ed/x2 ed/ys y2 x2 div 1 max def/xs x2
- y2 div 1 max def/y1 exch ys div def/x1 exch xs div def/y0 exch ys div
- def/x0 exch xs div def/r2 x2 y2 min def xs ys scale x0 x1 add 2 div
- y0 M x1 y0 x1 y1 r2 arcto 4{pop}repeat x1 y1 x0 y1 r2 arcto 4{pop}repeat
- x0 y1 x0 y0 r2 arcto 4{pop}repeat x0 y0 x1 y0 r2 arcto 4{pop}repeat
- m sm cp}ifelse}ifelse}bd/PP{{rlt}repeat}bd/OB{gs 0 ne{7 3 roll/y ed
- /x ed x y translate ULesc rotate x neg y neg translate x y 7 -3 roll}if
- sc B fill gr}bd/B{M/dy ed/dx ed dx 0 rlt 0 dy rlt dx neg 0 rlt cp}bd
- /CB{B clip n}bd/ErrHandler{errordict dup maxlength exch length gt
- dup{errordict begin}if/errhelpdict 12 dict def errhelpdict begin/stackunderflow(operand stack underflow)def
- /undefined(this name is not defined in a dictionary)def/VMerror(you have used up all the printer's memory)def
- /typecheck(operator was expecting a different type of operand)def
- /ioerror(input/output error occured)def end{end}if errordict begin
- /handleerror{$error begin newerror{/newerror false def showpage 72
- 72 scale/x .25 def/y 9.6 def/Helvetica findfont .2 scalefont setfont
- x y moveto(Offending Command = )show/command load{dup type/stringtype
- ne{(max err string)cvs}if show}exec/y y .2 sub def x y moveto(Error = )show
- errorname{dup type dup( max err string )cvs show( : )show/stringtype
- ne{( max err string )cvs}if show}exec errordict begin errhelpdict errorname
- known{x 1 add y .2 sub moveto errhelpdict errorname get show}if end
- /y y .4 sub def x y moveto(Stack =)show ostack{/y y .2 sub def x 1
- add y moveto dup type/stringtype ne{( max err string )cvs}if show}forall
- showpage}if end}def end}bd end
- SS
- 0 90 20 12 809 1100 300 SM
- 255 255 255 fC
- /fm 256 def
- gs 3001 2251 115 88 CB
- 3000 2250 115 88 B
- 1 F
- n
- gr
- 0 lc
- 0 lj
- 0 0 0 pC
- 6 25 SP
- gs 2654 1904 290 238 CB
- 2603 1853 315 263 B
- S
- n
- gr
- 32 0 0 100 100 0 0 0 89 /Times-Roman /font32 ANSIFont font
- 0 0 0 fC
- 2765 2149 50 (1) 50 SB
- 390 2149 306 (12/9/96) 306 SB
- 32 0 0 150 150 0 0 0 134 /Times-Roman /font32 ANSIFont font
- 900 311 1430 (ONC RPC WG Agenda) 1430 SB
- 32 0 0 100 100 0 0 0 89 /Times-Bold /font29 ANSIFont font
- 370 629 35 (\225) 35 SB
- 1 4 SJ
- 482 629 1260 (Assign scribe for this meeting) 1260 SB
- 32 0 0 100 100 0 0 0 89 /Times-Roman /font32 ANSIFont font
- 370 772 35 (\225) 35 SB
- 4 5 SJ
- 482 772 2362 (Introductions, Background, New Charter. Agenda Changes) 2362 SB
- 520 916 50 (\226) 50 SB
- 1 2 SJ
- 614 916 1195 (Steve Nahm <sxn@sun.com>) 1195 SB
- 370 1060 35 (\225) 35 SB
- 482 1060 1572 (Summary of RPCSEC_GSS discussion) 1572 SB
- 520 1204 50 (\226) 50 SB
- 2 2 SJ
- 614 1204 1358 (Mike Eisler <mre@eng.sun.com>) 1358 SB
- 370 1347 35 (\225) 35 SB
- 482 1347 1836 (Progress on outstanding RPCSEC_GSS items) 1836 SB
- 520 1491 50 (\226) 50 SB
- 1 2 SJ
- 614 1491 1057 (Ted Tso <tytso@mit.edu>) 1057 SB
- 370 1635 35 (\225) 35 SB
- 1 4 SJ
- 482 1635 1366 (Discussion of possible XDR work) 1366 SB
- 520 1779 50 (\226) 50 SB
- 4 2 SJ
- 614 1779 1745 (Keith Sklower <sklower@cs.berkeley.edu>) 1745 SB
- 370 1922 35 (\225) 35 SB
- 482 1922 436 (Next Steps) 436 SB
- %%PageResources: (atend)
- SS
- 0 90 20 12 809 1100 300 SM
- 255 255 255 fC
- /fm 256 def
- gs 3001 2251 115 88 CB
- 3000 2250 115 88 B
- 1 F
- n
- gr
- 0 lc
- 0 lj
- 0 0 0 pC
- 6 25 SP
- gs 2654 1904 290 238 CB
- 2603 1853 315 263 B
- S
- n
- gr
- 32 0 0 100 100 0 0 0 89 /Times-Roman /font32 ANSIFont font
- 0 0 0 fC
- 2765 2149 50 (2) 50 SB
- 390 2149 306 (12/9/96) 306 SB
- 32 0 0 150 150 0 0 0 134 /Times-Roman /font32 ANSIFont font
- 1027 282 1175 (ONCRPC WG Info) 1175 SB
- 32 0 0 100 100 0 0 0 89 /Times-Roman /font32 ANSIFont font
- 395 429 35 (\225) 35 SB
- 3 6 SJ
- 507 429 2141 (Charter: Standardize ONC RPC protocols \(TSV area\)) 2141 SB
- 395 572 35 (\225) 35 SB
- 507 572 630 (WG Co-Chairs:) 630 SB
- 1295 572 949 (Steve Nahm & Ted Tso) 949 SB
- 545 716 50 (\226) 50 SB
- 639 716 617 (Area Directors:) 617 SB
- 1295 716 1423 (Allison Mankin & Allyn Romanow) 1423 SB
- 395 860 35 (\225) 35 SB
- 1 1 SJ
- 507 860 741 (Outstanding drafts) 741 SB
- 545 980 50 (\226) 50 SB
- 1 1 SJ
- 639 980 791 (Proposed Standards) 791 SB
- 695 1123 35 (\225) 35 SB
- 770 1123 810 (RFC1831 - RPC V2) 810 SB
- 695 1267 35 (\225) 35 SB
- 1 6 SJ
- 770 1267 1910 (RFC1832 - XDR \(Submitted as Draft Standard\)) 1910 SB
- 695 1411 35 (\225) 35 SB
- 770 1411 908 (RFC 1833 - RPC Bind) 908 SB
- 395 1555 35 (\225) 35 SB
- 507 1555 458 (Online info) 458 SB
- 545 1698 50 (\226) 50 SB
- 639 1698 1353 (oncrpc-wg@sunroof.eng.sun.com) 1353 SB
- 32 0 0 100 100 0 0 0 89 /Times-Bold /font29 ANSIFont font
- 545 1842 50 (\226) 50 SB
- 639 1842 1772 (oncrpc-wg-request@sunroof.eng.sun.com) 1772 SB
- 32 0 0 100 100 0 0 0 89 /Times-Roman /font32 ANSIFont font
- 545 1986 50 (\226) 50 SB
- 2 2 SJ
- 639 1986 1803 (Archives at playground.sun.com:/pub/oncrpc) 1803 SB
- %%PageResources: (atend)
- SS
- 0 90 20 12 809 1100 300 SM
- 255 255 255 fC
- /fm 256 def
- gs 3001 2251 115 88 CB
- 3000 2250 115 88 B
- 1 F
- n
- gr
- 0 lc
- 0 lj
- 0 0 0 pC
- 6 25 SP
- gs 2654 1904 290 238 CB
- 2603 1853 315 263 B
- S
- n
- gr
- 32 0 0 100 100 0 0 0 89 /Times-Roman /font32 ANSIFont font
- 0 0 0 fC
- 2765 2149 50 (3) 50 SB
- 390 2149 306 (12/9/96) 306 SB
- 32 0 0 150 150 0 0 0 134 /Times-Roman /font32 ANSIFont font
- 767 311 1697 (New ONCRPC WG Charter) 1697 SB
- 32 0 0 100 100 0 0 0 89 /Times-Roman /font32 ANSIFont font
- 370 579 35 (\225) 35 SB
- 2 5 SJ
- 482 579 2001 (Standardize ONC RPC protocols existing practice) 2001 SB
- 370 722 35 (\225) 35 SB
- 1 8 SJ
- 482 722 2242 (Create security mechanism for ONC RPC that provides ) 2242 SB
- 32 0 0 100 100 0 0 0 89 /Times-Italic /font31 ANSIFont font
- 2725 722 78 (at) 78 SB
- 482 842 397 (minimum ) 397 SB
- 32 0 0 100 100 0 0 0 89 /Times-Roman /font32 ANSIFont font
- 1 1 SJ
- 880 842 841 (strong authentication) 841 SB
- 520 986 50 (\226) 50 SB
- 614 986 2159 (Core RPC specification blocked until submitted as PS) 2159 SB
- 520 1130 50 (\226) 50 SB
- 614 1130 2056 (RPCSEC_GSS provides auth, integrity and privacy) 2056 SB
- 370 1273 35 (\225) 35 SB
- 482 1273 405 (Timetable) 405 SB
- 520 1417 50 (\226) 50 SB
- 614 1417 275 (Feb 97) 275 SB
- 970 1417 1808 (Submit RPCSEC_GSS as Proposed Standard) 1808 SB
- 520 1561 50 (\226) 50 SB
- 614 1561 291 (Mar 97) 291 SB
- 1 6 SJ
- 970 1561 1704 (Submit core RPC specs as Draft Standards) 1704 SB
- 520 1705 50 (\226) 50 SB
- 614 1705 291 (Mar 97) 291 SB
- 970 1705 1664 (WG need not meet; mailing list monitors ) 1664 SB
- 3 4 SJ
- 970 1825 1141 (balance of std track progress) 1141 SB
- %%PageResources: (atend)
- SS
- 0 90 20 12 809 1100 300 SM
- 255 255 255 fC
- /fm 256 def
- gs 3001 2251 115 88 CB
- 3000 2250 115 88 B
- 1 F
- n
- gr
- 0 lc
- 0 lj
- 0 0 0 pC
- 6 25 SP
- gs 2654 1904 290 238 CB
- 2603 1853 315 263 B
- S
- n
- gr
- 32 0 0 100 100 0 0 0 89 /Times-Roman /font32 ANSIFont font
- 0 0 0 fC
- 2765 2149 50 (4) 50 SB
- 390 2149 306 (12/9/96) 306 SB
- 32 0 0 150 150 0 0 0 134 /Times-Roman /font32 ANSIFont font
- 946 299 1338 (ONC RPC WG Drafts) 1338 SB
- 32 0 0 100 100 0 0 0 89 /Times-Roman /font32 ANSIFont font
- 370 504 35 (\225) 35 SB
- 482 504 1387 (draft-ietf-oncrpc-rpcsec_gss-01.txt) 1387 SB
- 520 647 50 (\226) 50 SB
- 614 647 769 (Mike Eisler, Editor) 769 SB
- 370 791 35 (\225) 35 SB
- 482 791 1232 (draft-ietf-oncrpc-remote-02.txt) 1232 SB
- 520 935 50 (\226) 50 SB
- 614 935 1069 (No outstanding WG issues) 1069 SB
- 520 1079 50 (\226) 50 SB
- -2 2 SJ
- 614 1079 1363 (Blocked; awaiting RPCSEC_GSS) 1363 SB
- 370 1222 35 (\225) 35 SB
- 482 1222 1260 (draft-ietf-oncrpc-rpcbind-01.txt) 1260 SB
- 520 1366 50 (\226) 50 SB
- 614 1366 1069 (No outstanding WG issues) 1069 SB
- 520 1510 50 (\226) 50 SB
- -2 2 SJ
- 614 1510 1363 (Blocked; awaiting RPCSEC_GSS) 1363 SB
- 370 1654 35 (\225) 35 SB
- 482 1654 1127 (draft-ietf-oncrpc-auth-02.txt) 1127 SB
- 520 1797 50 (\226) 50 SB
- 614 1797 1069 (No outstanding WG issues) 1069 SB
- 520 1941 50 (\226) 50 SB
- 614 1941 1476 (Plan to submit as Informational RFC) 1476 SB
- SS
- 0 90 20 12 809 1100 300 SM
- 255 255 255 fC
- /fm 256 def
- gs 3001 2251 115 88 CB
- 3000 2250 115 88 B
- 1 F
- n
- gr
- 0 lc
- 0 lj
- 0 0 0 pC
- 6 25 SP
- gs 2654 1904 290 238 CB
- 2603 1853 315 263 B
- S
- n
- gr
- 32 0 0 100 100 0 0 0 89 /Times-Roman /font32 ANSIFont font
- 0 0 0 fC
- 2765 2149 50 (5) 50 SB
- 390 2149 306 (12/9/96) 306 SB
- 32 0 0 150 150 0 0 0 134 /Times-Roman /font32 ANSIFont font
- -1 1 SJ
- 1288 311 655 (Next Steps) 655 SB
- 32 0 0 100 100 0 0 0 89 /Times-Roman /font32 ANSIFont font
- 370 579 35 (\225) 35 SB
- 4 7 SJ
- 482 579 2226 (Publish current core RPC specs as recycle-in-grade PS?) 2226 SB
- 370 722 35 (\225) 35 SB
- 482 722 1680 (Publish Auth draft as Informational RFC?) 1680 SB
- 370 866 35 (\225) 35 SB
- 482 866 1847 (Submission of RPCSEC_GSS draft by Feb 97) 1847 SB
- end
- %%Pages: 5
- % TrueType font name key:
- % MSTT31c26b = 2617DTimes New RomanF00000064000001900000
- % MSTT31c26c = 2617DTimes New RomanF00000000000001900000
- % MSTT31c26d = 2617DTimes New RomanF00000064000002bc0000
- % MSTT31c26e = 2617DSystemF0007000f000002bc0000
- % MSTT31c26f = 2617DTimes New RomanF000000640000019000ff
- %%DocumentSuppliedResources: procset Win35Dict 3 1
- %%DocumentNeededResources: font Times-Bold
- %%+ font Times-Italic
- %%+ font Times-Roman
- %%EOF
- %!PS-Adobe-3.0
- %%Creator: Windows PSCRIPT
- %%Title: PowerPoint - OWGJOSE.PPT
- %%BoundingBox: 14 9 597 784
- %%DocumentNeededResources: (atend)
- %%DocumentSuppliedResources: (atend)
- %%Pages: (atend)
- %%BeginResource: procset Win35Dict 3 1
- /Win35Dict 290 dict def Win35Dict begin/bd{bind def}bind def/in{72
- mul}bd/ed{exch def}bd/ld{load def}bd/tr/translate ld/gs/gsave ld/gr
- /grestore ld/M/moveto ld/L/lineto ld/rmt/rmoveto ld/rlt/rlineto ld
- /rct/rcurveto ld/st/stroke ld/n/newpath ld/sm/setmatrix ld/cm/currentmatrix
- ld/cp/closepath ld/ARC/arcn ld/TR{65536 div}bd/lj/setlinejoin ld/lc
- /setlinecap ld/ml/setmiterlimit ld/sl/setlinewidth ld/scignore false
- def/sc{scignore{pop pop pop}{0 index 2 index eq 2 index 4 index eq
- and{pop pop 255 div setgray}{3{255 div 3 1 roll}repeat setrgbcolor}ifelse}ifelse}bd
- /FC{bR bG bB sc}bd/fC{/bB ed/bG ed/bR ed}bd/HC{hR hG hB sc}bd/hC{
- /hB ed/hG ed/hR ed}bd/PC{pR pG pB sc}bd/pC{/pB ed/pG ed/pR ed}bd/sM
- matrix def/PenW 1 def/iPen 5 def/mxF matrix def/mxE matrix def/mxUE
- matrix def/mxUF matrix def/fBE false def/iDevRes 72 0 matrix defaultmatrix
- dtransform dup mul exch dup mul add sqrt def/fPP false def/SS{fPP{
- /SV save def}{gs}ifelse}bd/RS{fPP{SV restore}{gr}ifelse}bd/EJ{gsave
- showpage grestore}bd/#C{userdict begin/#copies ed end}bd/FEbuf 2 string
- def/FEglyph(G )def/FE{1 exch{dup 16 FEbuf cvrs FEglyph exch 1 exch
- putinterval 1 index exch FEglyph cvn put}for}bd/SM{/iRes ed/cyP ed
- /cxPg ed/cyM ed/cxM ed 72 100 div dup scale dup 0 ne{90 eq{cyM exch
- 0 eq{cxM exch tr -90 rotate -1 1 scale}{cxM cxPg add exch tr +90 rotate}ifelse}{cyP
- cyM sub exch 0 ne{cxM exch tr -90 rotate}{cxM cxPg add exch tr -90
- rotate 1 -1 scale}ifelse}ifelse}{pop cyP cyM sub exch 0 ne{cxM cxPg
- add exch tr 180 rotate}{cxM exch tr 1 -1 scale}ifelse}ifelse 100 iRes
- div dup scale 0 0 transform .25 add round .25 sub exch .25 add round
- .25 sub exch itransform translate}bd/SJ{1 index 0 eq{pop pop/fBE false
- def}{1 index/Break ed div/dxBreak ed/fBE true def}ifelse}bd/ANSIVec[
- 16#0/grave 16#1/acute 16#2/circumflex 16#3/tilde 16#4/macron 16#5/breve
- 16#6/dotaccent 16#7/dieresis 16#8/ring 16#9/cedilla 16#A/hungarumlaut
- 16#B/ogonek 16#C/caron 16#D/dotlessi 16#27/quotesingle 16#60/grave
- 16#7C/bar 16#82/quotesinglbase 16#83/florin 16#84/quotedblbase 16#85
- /ellipsis 16#86/dagger 16#87/daggerdbl 16#88/circumflex 16#89/perthousand
- 16#8A/Scaron 16#8B/guilsinglleft 16#8C/OE 16#91/quoteleft 16#92/quoteright
- 16#93/quotedblleft 16#94/quotedblright 16#95/bullet 16#96/endash 16#97
- /emdash 16#98/tilde 16#99/trademark 16#9A/scaron 16#9B/guilsinglright
- 16#9C/oe 16#9F/Ydieresis 16#A0/space 16#A1/exclamdown 16#A4/currency
- 16#A5/yen 16#A6/brokenbar 16#A7/section 16#A8/dieresis 16#A9/copyright
- 16#AA/ordfeminine 16#AB/guillemotleft 16#AC/logicalnot 16#AD/hyphen
- 16#AE/registered 16#AF/macron 16#B0/degree 16#B1/plusminus 16#B2/twosuperior
- 16#B3/threesuperior 16#B4/acute 16#B5/mu 16#B6/paragraph 16#B7/periodcentered
- 16#B8/cedilla 16#B9/onesuperior 16#BA/ordmasculine 16#BB/guillemotright
- 16#BC/onequarter 16#BD/onehalf 16#BE/threequarters 16#BF/questiondown
- 16#C0/Agrave 16#C1/Aacute 16#C2/Acircumflex 16#C3/Atilde 16#C4/Adieresis
- 16#C5/Aring 16#C6/AE 16#C7/Ccedilla 16#C8/Egrave 16#C9/Eacute 16#CA
- /Ecircumflex 16#CB/Edieresis 16#CC/Igrave 16#CD/Iacute 16#CE/Icircumflex
- 16#CF/Idieresis 16#D0/Eth 16#D1/Ntilde 16#D2/Ograve 16#D3/Oacute 16#D4
- /Ocircumflex 16#D5/Otilde 16#D6/Odieresis 16#D7/multiply 16#D8/Oslash
- 16#D9/Ugrave 16#DA/Uacute 16#DB/Ucircumflex 16#DC/Udieresis 16#DD/Yacute
- 16#DE/Thorn 16#DF/germandbls 16#E0/agrave 16#E1/aacute 16#E2/acircumflex
- 16#E3/atilde 16#E4/adieresis 16#E5/aring 16#E6/ae 16#E7/ccedilla 16#E8
- /egrave 16#E9/eacute 16#EA/ecircumflex 16#EB/edieresis 16#EC/igrave
- 16#ED/iacute 16#EE/icircumflex 16#EF/idieresis 16#F0/eth 16#F1/ntilde
- 16#F2/ograve 16#F3/oacute 16#F4/ocircumflex 16#F5/otilde 16#F6/odieresis
- 16#F7/divide 16#F8/oslash 16#F9/ugrave 16#FA/uacute 16#FB/ucircumflex
- 16#FC/udieresis 16#FD/yacute 16#FE/thorn 16#FF/ydieresis ] def/reencdict
- 12 dict def/IsChar{basefontdict/CharStrings get exch known}bd/MapCh{dup
- IsChar not{pop/bullet}if newfont/Encoding get 3 1 roll put}bd/MapDegree{16#b0
- /degree IsChar{/degree}{/ring}ifelse MapCh}bd/MapBB{16#a6/brokenbar
- IsChar{/brokenbar}{/bar}ifelse MapCh}bd/ANSIFont{reencdict begin/newfontname
- ed/basefontname ed FontDirectory newfontname known not{/basefontdict
- basefontname findfont def/newfont basefontdict maxlength dict def basefontdict{exch
- dup/FID ne{dup/Encoding eq{exch dup length array copy newfont 3 1 roll
- put}{exch newfont 3 1 roll put}ifelse}{pop pop}ifelse}forall newfont
- /FontName newfontname put 127 1 159{newfont/Encoding get exch/bullet
- put}for ANSIVec aload pop ANSIVec length 2 idiv{MapCh}repeat MapDegree
- MapBB newfontname newfont definefont pop}if newfontname end}bd/SB{FC
- /ULlen ed/str ed str length fBE not{dup 1 gt{1 sub}if}if/cbStr ed
- /dxGdi ed/y0 ed/x0 ed str stringwidth dup 0 ne{/y1 ed/x1 ed y1 y1
- mul x1 x1 mul add sqrt dxGdi exch div 1 sub dup x1 mul cbStr div exch
- y1 mul cbStr div}{exch abs neg dxGdi add cbStr div exch}ifelse/dyExtra
- ed/dxExtra ed x0 y0 M fBE{dxBreak 0 BCh dxExtra dyExtra str awidthshow}{dxExtra
- dyExtra str ashow}ifelse fUL{x0 y0 M dxUL dyUL rmt ULlen fBE{Break
- add}if 0 mxUE transform gs rlt cyUL sl [] 0 setdash st gr}if fSO{x0
- y0 M dxSO dySO rmt ULlen fBE{Break add}if 0 mxUE transform gs rlt cyUL
- sl [] 0 setdash st gr}if n/fBE false def}bd/font{/name ed/Ascent ed
- 0 ne/fT3 ed 0 ne/fSO ed 0 ne/fUL ed/Sy ed/Sx ed 10.0 div/ori ed -10.0
- div/esc ed/BCh ed name findfont/xAscent 0 def/yAscent Ascent def/ULesc
- esc def ULesc mxUE rotate pop fT3{/esc 0 def xAscent yAscent mxUE transform
- /yAscent ed/xAscent ed}if [Sx 0 0 Sy neg xAscent yAscent] esc mxE
- rotate mxF concatmatrix makefont setfont [Sx 0 0 Sy neg 0 Ascent] mxUE
- mxUF concatmatrix pop fUL{currentfont dup/FontInfo get/UnderlinePosition
- known not{pop/Courier findfont}if/FontInfo get/UnderlinePosition get
- 1000 div 0 exch mxUF transform/dyUL ed/dxUL ed}if fSO{0 .3 mxUF transform
- /dySO ed/dxSO ed}if fUL fSO or{currentfont dup/FontInfo get/UnderlineThickness
- known not{pop/Courier findfont}if/FontInfo get/UnderlineThickness get
- 1000 div Sy mul/cyUL ed}if}bd/min{2 copy gt{exch}if pop}bd/max{2 copy
- lt{exch}if pop}bd/CP{/ft ed{{ft 0 eq{clip}{eoclip}ifelse}stopped{currentflat
- 1 add setflat}{exit}ifelse}loop}bd/patfont 10 dict def patfont begin
- /FontType 3 def/FontMatrix [1 0 0 -1 0 0] def/FontBBox [0 0 16 16]
- def/Encoding StandardEncoding def/BuildChar{pop pop 16 0 0 0 16 16
- setcachedevice 16 16 false [1 0 0 1 .25 .25]{pat}imagemask}bd end/p{
- /pat 32 string def{}forall 0 1 7{dup 2 mul pat exch 3 index put dup
- 2 mul 1 add pat exch 3 index put dup 2 mul 16 add pat exch 3 index
- put 2 mul 17 add pat exch 2 index put pop}for}bd/pfill{/PatFont patfont
- definefont setfont/ch(AAAA)def X0 64 X1{Y1 -16 Y0{1 index exch M ch
- show}for pop}for}bd/vert{X0 w X1{dup Y0 M Y1 L st}for}bd/horz{Y0 w
- Y1{dup X0 exch M X1 exch L st}for}bd/fdiag{X0 w X1{Y0 M X1 X0 sub dup
- rlt st}for Y0 w Y1{X0 exch M Y1 Y0 sub dup rlt st}for}bd/bdiag{X0 w
- X1{Y1 M X1 X0 sub dup neg rlt st}for Y0 w Y1{X0 exch M Y1 Y0 sub dup
- neg rlt st}for}bd/AU{1 add cvi 15 or}bd/AD{1 sub cvi -16 and}bd/SHR{pathbbox
- AU/Y1 ed AU/X1 ed AD/Y0 ed AD/X0 ed}bd/hfill{/w iRes 37.5 div round
- def 0.1 sl [] 0 setdash n dup 0 eq{horz}if dup 1 eq{vert}if dup 2 eq{fdiag}if
- dup 3 eq{bdiag}if dup 4 eq{horz vert}if 5 eq{fdiag bdiag}if}bd/F{/ft
- ed fm 256 and 0 ne{gs FC ft 0 eq{fill}{eofill}ifelse gr}if fm 1536
- and 0 ne{SHR gs HC ft CP fm 1024 and 0 ne{/Tmp save def pfill Tmp restore}{fm
- 15 and hfill}ifelse gr}if}bd/S{PenW sl PC st}bd/m matrix def/GW{iRes
- 12 div PenW add cvi}bd/DoW{iRes 50 div PenW add cvi}bd/DW{iRes 8 div
- PenW add cvi}bd/SP{/PenW ed/iPen ed iPen 0 eq iPen 6 eq or{[] 0 setdash}if
- iPen 1 eq{[DW GW] 0 setdash}if iPen 2 eq{[DoW GW] 0 setdash}if iPen
- 3 eq{[DW GW DoW GW] 0 setdash}if iPen 4 eq{[DW GW DoW GW DoW GW] 0
- setdash}if}bd/E{m cm pop tr scale 1 0 moveto 0 0 1 0 360 arc cp m sm}bd
- /AG{/sy ed/sx ed sx div 4 1 roll sy div 4 1 roll sx div 4 1 roll sy
- div 4 1 roll atan/a2 ed atan/a1 ed sx sy scale a1 a2 ARC}def/A{m cm
- pop tr AG m sm}def/P{m cm pop tr 0 0 M AG cp m sm}def/RRect{n 4 copy
- M 3 1 roll exch L 4 2 roll L L cp}bd/RRCC{/r ed/y1 ed/x1 ed/y0 ed/x0
- ed x0 x1 add 2 div y0 M x1 y0 x1 y1 r arcto 4{pop}repeat x1 y1 x0 y1
- r arcto 4{pop}repeat x0 y1 x0 y0 r arcto 4{pop}repeat x0 y0 x1 y0 r
- arcto 4{pop}repeat cp}bd/RR{2 copy 0 eq exch 0 eq or{pop pop RRect}{2
- copy eq{pop RRCC}{m cm pop/y2 ed/x2 ed/ys y2 x2 div 1 max def/xs x2
- y2 div 1 max def/y1 exch ys div def/x1 exch xs div def/y0 exch ys div
- def/x0 exch xs div def/r2 x2 y2 min def xs ys scale x0 x1 add 2 div
- y0 M x1 y0 x1 y1 r2 arcto 4{pop}repeat x1 y1 x0 y1 r2 arcto 4{pop}repeat
- x0 y1 x0 y0 r2 arcto 4{pop}repeat x0 y0 x1 y0 r2 arcto 4{pop}repeat
- m sm cp}ifelse}ifelse}bd/PP{{rlt}repeat}bd/OB{gs 0 ne{7 3 roll/y ed
- /x ed x y translate ULesc rotate x neg y neg translate x y 7 -3 roll}if
- sc B fill gr}bd/B{M/dy ed/dx ed dx 0 rlt 0 dy rlt dx neg 0 rlt cp}bd
- /CB{B clip n}bd/ErrHandler{errordict dup maxlength exch length gt
- dup{errordict begin}if/errhelpdict 12 dict def errhelpdict begin/stackunderflow(operand stack underflow)def
- /undefined(this name is not defined in a dictionary)def/VMerror(you have used up all the printer's memory)def
- /typecheck(operator was expecting a different type of operand)def
- /ioerror(input/output error occured)def end{end}if errordict begin
- /handleerror{$error begin newerror{/newerror false def showpage 72
- 72 scale/x .25 def/y 9.6 def/Helvetica findfont .2 scalefont setfont
- x y moveto(Offending Command = )show/command load{dup type/stringtype
- ne{(max err string)cvs}if show}exec/y y .2 sub def x y moveto(Error = )show
- errorname{dup type dup( max err string )cvs show( : )show/stringtype
- ne{( max err string )cvs}if show}exec errordict begin errhelpdict errorname
- known{x 1 add y .2 sub moveto errhelpdict errorname get show}if end
- /y y .4 sub def x y moveto(Stack =)show ostack{/y y .2 sub def x 1
- add y moveto dup type/stringtype ne{( max err string )cvs}if show}forall
- showpage}if end}def end}bd end
- SS
- 0 0 20 11 809 1100 300 SM
- 255 255 255 fC
- /fm 256 def
- gs 2251 3001 88 115 CB
- 2250 3000 88 115 B
- 1 F
- n
- gr
- /fm 256 def
- gs 879 660 267 415 CB
- 879 661 268 416 B
- 1 F
- n
- gr
- 0 lc
- 0 lj
- 0 0 0 pC
- 6 7 SP
- gs 879 660 267 415 CB
- 763 544 326 467 B
- S
- n
- gr
- 32 0 0 29 29 0 0 0 26 /Times-Roman /font32 ANSIFont font
- 0 0 0 fC
- gs 879 660 267 415 CB
- 1043 1020 15 (1) 15 SB
- gr
- gs 879 660 267 415 CB
- 347 1020 30 (12) 29 SB
- 376 1020 61 (/9/96) 61 SB
- gr
- 32 0 0 44 44 0 0 0 39 /Times-Roman /font32 ANSIFont font
- gs 879 660 267 415 CB
- 497 481 420 (ONC RPC WG Agenda) 420 SB
- gr
- 32 0 0 29 29 0 0 0 26 /Times-Bold /font29 ANSIFont font
- gs 879 660 267 415 CB
- 341 574 10 (\225) 10 SB
- gr
- gs 879 660 267 415 CB
- 4 4 SJ
- 374 574 366 (Assign scribe for this meeting) 366 SB
- gr
- 32 0 0 29 29 0 0 0 26 /Times-Roman /font32 ANSIFont font
- gs 879 660 267 415 CB
- 341 616 10 (\225) 10 SB
- gr
- gs 879 660 267 415 CB
- 374 616 695 (Introductions, Background, New Charter. Agenda Changes) 695 SB
- gr
- gs 879 660 267 415 CB
- 385 658 15 (\226) 15 SB
- gr
- gs 879 660 267 415 CB
- 1 2 SJ
- 412 658 350 (Steve Nahm <sxn@sun.com>) 350 SB
- gr
- gs 879 660 267 415 CB
- 341 700 10 (\225) 10 SB
- gr
- gs 879 660 267 415 CB
- 2 3 SJ
- 374 700 458 (Summary of RPCSEC_GSS discussion) 458 SB
- gr
- gs 879 660 267 415 CB
- 385 742 15 (\226) 15 SB
- gr
- gs 879 660 267 415 CB
- 1 2 SJ
- 412 742 398 (Mike Eisler <mre@eng.sun.com>) 398 SB
- gr
- gs 879 660 267 415 CB
- 341 785 10 (\225) 10 SB
- gr
- gs 879 660 267 415 CB
- 3 4 SJ
- 374 785 535 (Progress on outstanding RPCSEC_GSS items) 535 SB
- gr
- gs 879 660 267 415 CB
- 385 827 15 (\226) 15 SB
- gr
- gs 879 660 267 415 CB
- 1 2 SJ
- 412 827 309 (Ted Tso <tytso@mit.edu>) 309 SB
- gr
- gs 879 660 267 415 CB
- 341 869 10 (\225) 10 SB
- gr
- gs 879 660 267 415 CB
- 2 4 SJ
- 374 869 399 (Discussion of possible XDR work) 399 SB
- gr
- gs 879 660 267 415 CB
- 385 911 15 (\226) 15 SB
- gr
- gs 879 660 267 415 CB
- 1 2 SJ
- 412 911 512 (Keith Sklower <sklower@cs.berkeley.edu>) 512 SB
- gr
- gs 879 660 267 415 CB
- 341 953 10 (\225) 10 SB
- gr
- gs 879 660 267 415 CB
- 1 1 SJ
- 374 953 127 (Next Steps) 127 SB
- gr
- 255 255 255 fC
- /fm 256 def
- gs 880 660 1279 415 CB
- 879 661 1281 416 B
- 1 F
- n
- gr
- 6 7 SP
- gs 880 660 1279 415 CB
- 763 544 1339 467 B
- S
- n
- gr
- 0 0 0 fC
- gs 880 660 1279 415 CB
- 2056 1020 15 (2) 15 SB
- gr
- gs 880 660 1279 415 CB
- 1360 1020 30 (12) 29 SB
- 1389 1020 61 (/9/96) 61 SB
- gr
- 32 0 0 44 44 0 0 0 39 /Times-Roman /font32 ANSIFont font
- gs 880 660 1279 415 CB
- 1547 472 345 (ONCRPC WG Info) 345 SB
- gr
- 32 0 0 29 29 0 0 0 26 /Times-Roman /font32 ANSIFont font
- gs 880 660 1279 415 CB
- 1361 515 10 (\225) 10 SB
- gr
- gs 880 660 1279 415 CB
- 3 6 SJ
- 1394 515 626 (Charter: Standardize ONC RPC protocols \(TSV area\)) 626 SB
- gr
- gs 880 660 1279 415 CB
- 1361 557 10 (\225) 10 SB
- gr
- gs 880 660 1279 415 CB
- 1394 557 183 (WG Co-Chairs:) 183 SB
- gr
- gs 880 660 1279 415 CB
- 1 4 SJ
- 1625 557 278 (Steve Nahm & Ted Tso) 278 SB
- gr
- gs 880 660 1279 415 CB
- 1405 599 15 (\226) 15 SB
- gr
- gs 880 660 1279 415 CB
- 1432 599 181 (Area Directors:) 181 SB
- gr
- gs 880 660 1279 415 CB
- 1625 599 417 (Allison Mankin & Allyn Romanow) 417 SB
- gr
- gs 880 660 1279 415 CB
- 1361 642 10 (\225) 10 SB
- gr
- gs 880 660 1279 415 CB
- 1394 642 218 (Outstanding drafts) 218 SB
- gr
- gs 880 660 1279 415 CB
- 1405 677 15 (\226) 15 SB
- gr
- gs 880 660 1279 415 CB
- -1 1 SJ
- 1432 677 233 (Proposed Standards) 233 SB
- gr
- gs 880 660 1279 415 CB
- 1449 719 10 (\225) 10 SB
- gr
- gs 880 660 1279 415 CB
- 2 3 SJ
- 1471 719 235 (RFC1831 - RPC V2) 235 SB
- gr
- gs 880 660 1279 415 CB
- 1449 761 10 (\225) 10 SB
- gr
- gs 880 660 1279 415 CB
- 2 6 SJ
- 1471 761 559 (RFC1832 - XDR \(Submitted as Draft Standard\)) 559 SB
- gr
- gs 880 660 1279 415 CB
- 1449 803 10 (\225) 10 SB
- gr
- gs 880 660 1279 415 CB
- 3 4 SJ
- 1471 803 263 (RFC 1833 - RPC Bind) 263 SB
- gr
- gs 880 660 1279 415 CB
- 1361 845 10 (\225) 10 SB
- gr
- gs 880 660 1279 415 CB
- -1 1 SJ
- 1394 845 135 (Online info) 135 SB
- gr
- gs 880 660 1279 415 CB
- 1405 888 15 (\226) 15 SB
- gr
- gs 880 660 1279 415 CB
- 1432 888 30 (on) 29 SB
- 1461 888 97 (crpc-wg) 96 SB
- 1557 888 38 (@s) 39 SB
- 1596 888 30 (un) 29 SB
- 1625 888 40 (roo) 39 SB
- 1664 888 166 (f.eng.sun.com) 166 SB
- gr
- 32 0 0 29 29 0 0 0 26 /Times-Bold /font29 ANSIFont font
- gs 880 660 1279 415 CB
- 1405 930 15 (\226) 15 SB
- gr
- gs 880 660 1279 415 CB
- 1432 930 517 (oncrpc-wg-request@sunroof.eng.sun.com) 517 SB
- gr
- 32 0 0 29 29 0 0 0 26 /Times-Roman /font32 ANSIFont font
- gs 880 660 1279 415 CB
- 1405 972 15 (\226) 15 SB
- gr
- gs 880 660 1279 415 CB
- -2 2 SJ
- 1432 972 533 (Archives at playground.sun.com:/pub/oncrpc) 533 SB
- gr
- 255 255 255 fC
- /fm 256 def
- gs 879 660 267 1285 CB
- 879 661 268 1286 B
- 1 F
- n
- gr
- 6 7 SP
- gs 879 660 267 1285 CB
- 763 544 326 1337 B
- S
- n
- gr
- 0 0 0 fC
- gs 879 660 267 1285 CB
- 1043 1890 15 (3) 15 SB
- gr
- gs 879 660 267 1285 CB
- 347 1890 30 (12) 29 SB
- 376 1890 61 (/9/96) 61 SB
- gr
- 32 0 0 44 44 0 0 0 39 /Times-Roman /font32 ANSIFont font
- gs 879 660 267 1285 CB
- 457 1351 499 (New ONCRPC WG Charter) 499 SB
- gr
- 32 0 0 29 29 0 0 0 26 /Times-Roman /font32 ANSIFont font
- gs 879 660 267 1285 CB
- 341 1429 10 (\225) 10 SB
- gr
- gs 879 660 267 1285 CB
- 2 5 SJ
- 374 1429 585 (Standardize ONC RPC protocols existing practice) 585 SB
- gr
- gs 879 660 267 1285 CB
- 341 1471 10 (\225) 10 SB
- gr
- gs 879 660 267 1285 CB
- 3 8 SJ
- 374 1471 655 (Create security mechanism for ONC RPC that provides ) 655 SB
- gr
- 32 0 0 29 29 0 0 0 26 /Times-Italic /font31 ANSIFont font
- gs 879 660 267 1285 CB
- 1032 1471 23 (at) 23 SB
- gr
- gs 879 660 267 1285 CB
- 374 1506 116 (minimum ) 116 SB
- gr
- 32 0 0 29 29 0 0 0 26 /Times-Roman /font32 ANSIFont font
- gs 879 660 267 1285 CB
- 490 1506 248 (strong authentication) 248 SB
- gr
- gs 879 660 267 1285 CB
- 385 1549 15 (\226) 15 SB
- gr
- gs 879 660 267 1285 CB
- 3 7 SJ
- 412 1549 630 (Core RPC specification blocked until submitted as PS) 630 SB
- gr
- gs 879 660 267 1285 CB
- 385 1591 15 (\226) 15 SB
- gr
- gs 879 660 267 1285 CB
- 1 5 SJ
- 412 1591 602 (RPCSEC_GSS provides auth, integrity and privacy) 602 SB
- gr
- gs 879 660 267 1285 CB
- 341 1633 10 (\225) 10 SB
- gr
- gs 879 660 267 1285 CB
- 374 1633 119 (Timetable) 119 SB
- gr
- gs 879 660 267 1285 CB
- 385 1675 15 (\226) 15 SB
- gr
- gs 879 660 267 1285 CB
- 412 1675 81 (Feb 97) 81 SB
- gr
- gs 879 660 267 1285 CB
- 2 4 SJ
- 517 1675 527 (Submit RPCSEC_GSS as Proposed Standard) 527 SB
- gr
- gs 879 660 267 1285 CB
- 385 1717 15 (\226) 15 SB
- gr
- gs 879 660 267 1285 CB
- 412 1717 86 (Mar 97) 86 SB
- gr
- gs 879 660 267 1285 CB
- 3 6 SJ
- 517 1717 497 (Submit core RPC specs as Draft Standards) 497 SB
- gr
- gs 879 660 267 1285 CB
- 385 1759 15 (\226) 15 SB
- gr
- gs 879 660 267 1285 CB
- 412 1759 86 (Mar 97) 86 SB
- gr
- gs 879 660 267 1285 CB
- 517 1759 486 (WG need not meet; mailing list monitors ) 486 SB
- gr
- gs 879 660 267 1285 CB
- 517 1794 336 (balance of std track progress) 336 SB
- gr
- 255 255 255 fC
- /fm 256 def
- gs 880 660 1279 1285 CB
- 879 661 1281 1286 B
- 1 F
- n
- gr
- 6 7 SP
- gs 880 660 1279 1285 CB
- 763 544 1339 1337 B
- S
- n
- gr
- 0 0 0 fC
- gs 880 660 1279 1285 CB
- 2056 1890 15 (4) 15 SB
- gr
- gs 880 660 1279 1285 CB
- 1360 1890 30 (12) 29 SB
- 1389 1890 61 (/9/96) 61 SB
- gr
- 32 0 0 44 44 0 0 0 39 /Times-Roman /font32 ANSIFont font
- gs 880 660 1279 1285 CB
- 1523 1347 393 (ONC RPC WG Drafts) 393 SB
- gr
- 32 0 0 29 29 0 0 0 26 /Times-Roman /font32 ANSIFont font
- gs 880 660 1279 1285 CB
- 1354 1407 10 (\225) 10 SB
- gr
- gs 880 660 1279 1285 CB
- 1387 1407 25 (dr) 24 SB
- 1411 1407 120 (aft-ietf-on) 119 SB
- 1530 1407 71 (crpc-r) 70 SB
- 1600 1407 52 (pcse) 53 SB
- 1653 1407 28 (c_) 27 SB
- 1680 1407 37 (gss) 38 SB
- 1718 1407 10 (-) 9 SB
- 1727 1407 68 (01.txt) 68 SB
- gr
- gs 880 660 1279 1285 CB
- 1398 1449 15 (\226) 15 SB
- gr
- gs 880 660 1279 1285 CB
- 1 2 SJ
- 1425 1449 225 (Mike Eisler, Editor) 225 SB
- gr
- gs 880 660 1279 1285 CB
- 1354 1491 10 (\225) 10 SB
- gr
- gs 880 660 1279 1285 CB
- 1387 1491 25 (dr) 24 SB
- 1411 1491 120 (aft-ietf-on) 119 SB
- 1530 1491 71 (crpc-r) 70 SB
- 1600 1491 97 (emote-0) 96 SB
- 1696 1491 30 (2.t) 31 SB
- 1727 1491 15 (x) 14 SB
- 1741 1491 8 (t) 8 SB
- gr
- gs 880 660 1279 1285 CB
- 1398 1534 15 (\226) 15 SB
- gr
- gs 880 660 1279 1285 CB
- 2 3 SJ
- 1425 1534 312 (No outstanding WG issues) 312 SB
- gr
- gs 880 660 1279 1285 CB
- 1398 1576 15 (\226) 15 SB
- gr
- gs 880 660 1279 1285 CB
- 3 2 SJ
- 1425 1576 396 (Blocked; awaiting RPCSEC_GSS) 396 SB
- gr
- gs 880 660 1279 1285 CB
- 1354 1618 10 (\225) 10 SB
- gr
- gs 880 660 1279 1285 CB
- 1387 1618 25 (dr) 24 SB
- 1411 1618 120 (aft-ietf-on) 119 SB
- 1530 1618 71 (crpc-r) 70 SB
- 1600 1618 81 (pcbind) 80 SB
- 1680 1618 40 (-01) 39 SB
- 1719 1618 7 (.) 8 SB
- 1727 1618 23 (tx) 22 SB
- 1749 1618 8 (t) 9 SB
- gr
- gs 880 660 1279 1285 CB
- 1398 1660 15 (\226) 15 SB
- gr
- gs 880 660 1279 1285 CB
- 2 3 SJ
- 1425 1660 312 (No outstanding WG issues) 312 SB
- gr
- gs 880 660 1279 1285 CB
- 1398 1702 15 (\226) 15 SB
- gr
- gs 880 660 1279 1285 CB
- 3 2 SJ
- 1425 1702 396 (Blocked; awaiting RPCSEC_GSS) 396 SB
- gr
- gs 880 660 1279 1285 CB
- 1354 1744 10 (\225) 10 SB
- gr
- gs 880 660 1279 1285 CB
- 1387 1744 25 (dr) 24 SB
- 1411 1744 120 (aft-ietf-on) 119 SB
- 1530 1744 89 (crpc-au) 88 SB
- 1618 1744 63 (th-02) 62 SB
- 1680 1744 7 (.) 8 SB
- 1688 1744 23 (tx) 22 SB
- 1710 1744 8 (t) 9 SB
- gr
- gs 880 660 1279 1285 CB
- 1398 1787 15 (\226) 15 SB
- gr
- gs 880 660 1279 1285 CB
- 2 3 SJ
- 1425 1787 312 (No outstanding WG issues) 312 SB
- gr
- gs 880 660 1279 1285 CB
- 1398 1829 15 (\226) 15 SB
- gr
- gs 880 660 1279 1285 CB
- 2 5 SJ
- 1425 1829 431 (Plan to submit as Informational RFC) 431 SB
- gr
- 255 255 255 fC
- /fm 256 def
- gs 879 659 267 2155 CB
- 879 661 268 2155 B
- 1 F
- n
- gr
- 6 7 SP
- gs 879 659 267 2155 CB
- 763 544 326 2206 B
- S
- n
- gr
- 0 0 0 fC
- gs 879 659 267 2155 CB
- 1043 2759 15 (5) 15 SB
- gr
- gs 879 659 267 2155 CB
- 347 2759 30 (12) 29 SB
- 376 2759 61 (/9/96) 61 SB
- gr
- 32 0 0 44 44 0 0 0 39 /Times-Roman /font32 ANSIFont font
- gs 879 659 267 2155 CB
- 610 2220 192 (Next Steps) 192 SB
- gr
- 32 0 0 29 29 0 0 0 26 /Times-Roman /font32 ANSIFont font
- gs 879 659 267 2155 CB
- 341 2298 10 (\225) 10 SB
- gr
- gs 879 659 267 2155 CB
- 2 7 SJ
- 374 2298 652 (Publish current core RPC specs as recycle-in-grade PS?) 652 SB
- gr
- gs 879 659 267 2155 CB
- 341 2340 10 (\225) 10 SB
- gr
- gs 879 659 267 2155 CB
- 1 5 SJ
- 374 2340 492 (Publish Auth draft as Informational RFC?) 492 SB
- gr
- gs 879 659 267 2155 CB
- 341 2382 10 (\225) 10 SB
- gr
- gs 879 659 267 2155 CB
- 2 6 SJ
- 374 2382 539 (Submission of RPCSEC_GSS draft by Feb 97) 539 SB
- gr
- 612 792 1 FMBEGINPAGE
- 72 212.67 720 222.67 R
- 7 X
- 0 K
- V
- 90 252 702 702 R
- V
- 0 36 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt) 98.98 678 T
- (Summary of discussion and issues) 94.93 582 T
- (Mike Eisler, Document Editor) 146.96 486 T
- (mre@Eng.Sun.Com) 227.45 390 T
- %%EndPage: "1" 2
- %%Page: "2" 2
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 2) 689.45 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- 90 252 702 702 R
- 7 X
- 0 K
- V
- 0 24 Q
- 0 X
- (\245) 90 640 T
- (Negotiation of mechanism - unresolved) 108 640 T
- (\245) 90 595 T
- (Specification of QOP/Service values - unresolved) 108 595 T
- (\245) 90 550 T
- -2.23 (Denial of service of attacks using sequence numbers) 108 550 P
- (- unresolved) 108 521 T
- (\245) 90 476 T
- (Clarify integrity check wording - resolved) 108 476 T
- (\245) 90 431 T
- (RPCSEC_GSS vs. GSS errors - resolved) 108 431 T
- (\245) 90 386 T
- (Generation of session handles - resolved) 108 386 T
- (\245) 90 341 T
- (Version negotiation - unresolved) 108 341 T
- (\245) 90 296 T
- (gss_get_mic\050\051 vs. gss_wrap\050\051 - unresolved) 108 296 T
- %%EndPage: "2" 3
- %%Page: "3" 3
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 3) 689.45 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- 90 252 702 702 R
- 7 X
- 0 K
- V
- 0 24 Q
- 0 X
- (\245) 90 686 T
- (section 6.2 - flooding attacks - resolved) 108 686 T
- (\245) 90 641 T
- (section 5.2.1 - context creation messages -) 108 641 T
- (unresolved) 108 612 T
- (\245) 90 567 T
- (data type of gss_proc - resolved) 108 567 T
- (\245) 90 522 T
- (GSS-API V1 references vs. GSS-API V2 - unresolved) 108 522 T
- %%EndPage: "3" 4
- %%Page: "4" 4
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 4) 689.45 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- 90 252 702 702 R
- 7 X
- 0 K
- V
- 0 24 Q
- 0 X
- (Negotiation of mechanism) 246.06 686 T
- (\245) 90 640 T
- (John Linn: \322no facility at the rpcsec_gss layer to) 108 640 T
- (transport or negotiate GSS-API mechanism) 108 611 T
- (identifiers, mechanism selection must either \050a\051 be) 108 582 T
- (static, \050b\051 be performed out-of-band, or \050c\051 be) 108 553 T
- (negotiated within the GSS layer\323) 108 524 T
- (\245) 90 479 T
- (Anonymous: \322... ONC RPC model doesn't stretch) 108 479 T
- -0.95 (very well to include models such as negotiated QOS) 108 450 P
- (or authentication flavor.... if you don't add such) 108 421 T
- (improvements to ONC RPC, there's little attracting) 108 392 T
- (me to ONC over the alternatives.\323) 108 363 T
- 2 F
- (\245) 90 318 T
- (Are the above issues serious enough to hold back) 108 318 T
- (the ID?) 108 289 T
- %%EndPage: "4" 5
- %%Page: "5" 5
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 5) 689.45 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- 90 252 702 702 R
- 7 X
- 0 K
- V
- 0 24 Q
- 0 X
- (Specification of QOP/SERVICE values) 180.05 686 T
- (\245) 90 640 T
- (John: \322is it expected that any such QOP values will) 108 640 T
- -0.05 (be sourced within the RPC layer, or instead that the) 108 611 P
- (relevant GSS mechanism ID will be reflected up to) 108 582 T
- -0.75 (the RPC caller so that it's equipped to undertake the) 108 553 P
- (responsibility of selecting QOPs suitable to the) 108 524 T
- (prevailing mechanism?\323) 108 495 T
- 2 F
- (\245) 90 450 T
- -1.4 (The API is expected to provide mechanism selection) 108 450 P
- (input/output to the client and server. The ID can be) 108 421 T
- (updated to reflect this.) 108 392 T
- 0 F
- (\245) 90 347 T
- (John: \322Use of \322default\323 would be simplifying here,) 108 347 T
- (and is probably to be preferred where/if possible\323) 108 318 T
- %%EndPage: "5" 6
- %%Page: "6" 6
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 6) 689.45 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- 90 252 702 702 R
- 7 X
- 0 K
- V
- 2 24 Q
- 0 X
- (\245) 90 686 T
- -1.98 (Proposal: When the client doesn\325t know what QOP to) 108 686 P
- (use, \322default\323 should be specified in the ID) 108 657 T
- 0 F
- (\245) 90 612 T
- -2.35 (Marc Horowitz: Method of imposing QOP/service has) 108 612 P
- (problems:) 108 583 T
- 3 22 Q
- (-) 126 545.33 T
- (\322client has to \322guess\323 in rpc_gss_init_arg\323) 144 545.33 T
- (-) 126 510.33 T
- (\322field is not protected in any way\323) 144 510.33 T
- (-) 126 475.33 T
- (proposes: \322including the required qop and service values) 144 475.33 T
- (in the final \050GSS_S_COMPLETE\051 rpc_gss_init_res, and) 144 451.33 T
- (using gssapi to protect this information.\323) 144 427.33 T
- 2 24 Q
- (\245) 90 386 T
- -0.53 (The intent of feature in the ID was that clients would) 108 386 P
- -1.39 (pick the QOP from an out-of-band name service. The) 108 357 P
- (server \050e.g. NFS\051 may not know what the right QOP) 108 328 T
- (is until the client accesses a specific resource.) 108 299 T
- %%EndPage: "6" 7
- %%Page: "7" 7
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 7) 689.45 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- 90 252 702 702 R
- 7 X
- 0 K
- V
- 2 24 Q
- 0 X
- (\245) 90 686 T
- (Is including the required QOP in the response) 108 686 T
- (redundant? If GSS-API is used to protect the data,) 108 657 T
- (then the QOP is encoded in the results of the GSS-) 108 628 T
- (API operation.) 108 599 T
- 0 F
- (\245) 90 554 T
- (Marc: \322why have the service/QOP\323 in the protocol?) 108 554 T
- (\245) 90 509 T
- (Marc: \322it seems more and more to me like dropping) 108 509 T
- -0.72 (the QOP/service stuff from the init phase is the right) 108 480 P
- (answer.\323) 108 451 T
- 2 F
- (\245) 90 406 T
- (It may be possible to remove this from the protocol) 108 406 T
- (and still achieve the desired effect. However, the) 108 377 T
- (next discussion point from Barry Jaspan raises an) 108 348 T
- (issue, leaving this still a point of contention.) 108 319 T
- %%EndPage: "7" 8
- %%Page: "8" 8
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 8) 689.45 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- 90 252 702 702 R
- 7 X
- 0 K
- V
- 0 24 Q
- 0 X
- (Denial of service of attacks using) 206.04 686 T
- (sequence numbers) 286.69 640 T
- (\245) 90 594 T
- (Barry Jaspan: suggests \322the seq_window also be) 108 594 T
- (protected when communicated to the client\323) 108 565 T
- 2 F
- (\245) 90 520 T
- (This is reasonable. However, if we delete QOP/) 108 520 T
- (integrity negotiation from the protocol, what QOP) 108 491 T
- (and what service does the server use to protect) 108 462 T
- (seq_window?) 108 433 T
- (\245) 90 388 T
- (Proposal: leave QOP/service in the protocol, and) 108 388 T
- (protect the service/seq_window when) 108 359 T
- (communicated back to the client with GSS-API) 108 330 T
- %%EndPage: "8" 9
- %%Page: "9" 9
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 9) 689.45 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- 90 252 702 702 R
- 7 X
- 0 K
- V
- 0 24 Q
- 0 X
- (Clarify integrity check wording) 220.72 686 T
- (\245) 90 640 T
- (John: description of Context Management \050sec.) 108 640 T
- (\051 should emphasize: \322that the integrity check) 108 611 T
- (on an incoming message is to be validated before) 108 582 T
- (adjusting the receive window in response to the) 108 553 T
- (incoming message's sequence number\323) 108 524 T
- 2 F
- (\245) 90 479 T
- -1.09 (Agreed, though if the sequence number is below the) 108 479 P
- (window, the request can be dropped without the) 108 450 T
- (integrity check.) 108 421 T
- %%EndPage: "9" 10
- %%Page: "10" 10
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 10) 683.89 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- 90 252 702 702 R
- 7 X
- 0 K
- V
- 0 24 Q
- 0 X
- (RPCSEC_GSS vs. GSS errors) 227.36 686 T
- (\245) 90 640 T
- (John: RPCSEC_GSS_NOCRED and) 108 640 T
- (RPCSEC_GSS_FAILED are similar in name to GSS-) 108 611 T
- (GSS-API major statuses GSS_NO_CRED and) 108 582 T
- -0.3 (GSS_FAILURE, but apparently different in meaning.) 108 553 P
- (Should the RPCSEC_GSS_* codes be renamed?) 108 524 T
- 2 F
- (\245) 90 479 T
- (They will be renamed since they definitely mean) 108 479 T
- (different things.) 108 450 T
- 0 F
- (\245) 90 405 T
- (John: \322is it possible and useful to define the) 108 405 T
- (mapping between specific GSS-level major status) 108 376 T
- (codes and the corresponding RPC layer error?\323) 108 347 T
- 2 F
- (\245) 90 302 T
- (An attempt will be made to define these mappings.) 108 302 T
- %%EndPage: "10" 11
- %%Page: "11" 11
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 11) 683.89 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- 90 252 702 702 R
- 7 X
- 0 K
- V
- 0 24 Q
- 0 X
- (Generation of session handles) 221.38 686 T
- (\245) 90 640 T
- (Marc: Regarding sec., it states: The server) 108 640 T
- (must generate handles such that they will be) 108 611 T
- (generated again for the same pair of client and) 108 582 T
- (server principals.) 108 553 T
- 3 18 Q
- (-) 126 520 T
- (\322What if there are two simultaneous connections from the same client) 144 520 T
- (to the same server?\323) 144 500 T
- (-) 126 472 T
- (\322GSSAPI requires that mechanisms protect context setup against) 144 472 T
- (replay attacks\323) 144 452 T
- 2 24 Q
- (\245) 90 412 T
- (There should have been a \322not\323 between \322will\323 and) 108 412 T
- (\322be\323.) 108 383 T
- (\245) 90 338 T
- (Proposal: for simplicity, delete the offending) 108 338 T
- (sentences from section 108 309 T
- %%EndPage: "11" 12
- %%Page: "12" 12
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 12) 683.89 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- 90 252 702 702 R
- 7 X
- 0 K
- V
- 0 24 Q
- 0 X
- (Version negotiation) 284.04 686 T
- (\245) 90 640 T
- (Marc: \322The version negotiation procedure seems) 108 640 T
- (unnecessarily complex.\323) 108 611 T
- (\245) 90 566 T
- (Marc: \322In the case when the client and server both) 108 566 T
- (support the same protocol version \050which will be) 108 537 T
- -0.44 (most of the time\051, it would be useful to be able to do) 108 508 P
- (an aggressive setup, where instead of asking for a) 108 479 T
- -2.13 (protocol version, the first message for that version is) 108 450 P
- (sent.\323) 108 421 T
- 2 F
- (\245) 90 376 T
- -1.03 (Agreed. Since the server-side of version negotiation) 108 376 P
- (must be stateless, the server doesn\325t care.) 108 347 T
- (\245) 90 302 T
- (Proposal: Since version negotiation is contentious,) 108 302 T
- (and since we at only verison1, delete version) 108 273 T
- %%EndPage: "12" 13
- %%Page: "13" 13
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 13) 683.89 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- -2.17 (negotiation from the specification, reserve version 0,) 108 686 P
- (and if versions are added in the future, re-visit) 108 657 T
- (version negotiation then.) 108 628 T
(draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) Slide 14

Mike Eisler, Document Editor
- (gss_get_mic\050\051 vs. gss_wrap\050\051) 228.7 686 T
- (\245) 90 640 T
- -1.09 (Marc: The protocol in the ID uses \322gss_get_mic\050\051 for) 108 640 P
- -0.39 (integrity, and gss_wrap\050\051 for encryption. it would be) 108 611 P
- (simpler... to use gss_wrap in both cases, with the) 108 582 T
- (conf_req flag set accordingly\323) 108 553 T
- (\245) 90 508 T
- (This will introduce an unnecessary byte copy that) 108 508 T
- (gss_wrap will incur when conf_req is zero.) 108 479 T
(draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) Slide 15
- (Slide 15) 683.89 749.33 T
Mike Eisler, Document Editor
- (\245) 90 686 T
- (Marc: Perhaps both modes should be allowed, as) 108 686 T
- (there is talk about extending GSS-API to use an) 108 657 T
- (application buffer.) 108 628 T
- (\245) 90 583 T
- (This extension won\325t eliminate the byte copy. Have) 108 583 T
- (two ways to do integrity is protocol bloat and by) 108 554 T
- (consequence, ONCRPC-API bloat. Why would an) 108 525 T
- (ONC-RPC programmer pick a \322wrapped-integrity\323) 108 496 T
- (service if the documentation warned that this) 108 467 T
- (consumed a byte copy?) 108 438 T
(draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) Slide 16
- (Slide 16) 683.89 749.33 T
Mike Eisler, Document Editor
- (section 6.2 - flooding attacks) 231.38 686 T
- (\245) 90 640 T
- (Marc: \322Section 6.2 goes through some effort to) 108 640 T
- (demonstrate that there are no flooding attacks) 108 611 T
- (possible. There is a trivial attack where the attacker) 108 582 T
- (sends fake requests above the window. These will) 108 553 T
- -1.38 (not be rejected due to the sequence number \050since it) 108 524 P
- (must increase\051, forcing the server to validate the) 108 495 T
- (header checksum and fail.\323) 108 466 T
- (\245) 90 421 T
- (The ID does, albeit not clearly, acknowledge this.) 108 421 T
- (\245) 90 376 T
- (Proposal: Clarify section 6.2.) 108 376 T
(draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) Slide 17
- (Slide 17) 683.89 749.33 T
Mike Eisler, Document Editor
- 0 K
- V
- 0 24 Q
- 0 X
- (section 5.2.1 - context creation messages) 159.37 686 T
- (\245) 90 640 T
- -1.09 (Marc: Section 5.2.1 says: The first RPC request from) 108 640 P
- (the client to the server initiates context creation for) 108 611 T
- (those mechanisms that require context creation) 108 582 T
- (messages. \322All mechanisms will generate at least) 108 553 T
- (one token requiring a context creation message\323) 108 524 T
- 2 F
- (\245) 90 479 T
- (The GSS-API v2 specification \050draft-ietf-cat-gssv2-) 108 479 T
- (08.txt\051 seems to imply that an initial call to) 108 450 T
- (GSS_Init_sec_context can return) 108 421 T
- (GSS_S_COMPLETE. Is there a problem with calling) 108 392 T
- (GSS_Accept_sec_context\050\051 on a token created with) 108 363 T
- (a GSS_Init_sec_context call returning) 108 334 T
- (GSS_S_COMPLETE?) 108 305 T
- %%EndPage: "17" 18
- %%Page: "18" 18
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 18) 683.89 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- 90 252 702 702 R
- 7 X
- 0 K
- V
- 0 24 Q
- 0 X
- (data type of gss_proc) 272.04 686 T
- (\245) 90 640 T
- (Marc: \322gss_proc is an unsigned int instead of an) 108 640 T
- (enum. Why?\323) 108 611 T
- 2 F
- (\245) 90 566 T
- -0.53 (Proposal: redefine gss_proc as an enumerated type.) 108 566 P
- %%EndPage: "18" 19
- %%Page: "19" 19
- 612 792 1 FMBEGINPAGE
- 72 746 720 756 R
- 7 X
- 0 K
- V
- 1 10 Q
- 0 X
- (draft-ietf-oncrpc-rpcsec_gss-01.txt: summary of discussion and issues) 241.32 749.33 T
- (Slide 19) 683.89 749.33 T
- 72 212.67 720 222.67 R
- 7 X
- V
- 0 X
- (Mike Eisler, Document Editor) 331.58 216 T
- 72 234 720 711 18 RR
- 7 X
- 4 K
- V
- 0.5 H
- 0 Z
- 0 X
- N
- 90 252 702 702 R
- 7 X
- 0 K
- V
- 0 24 Q
- 0 X
- (GSS-API V1 references vs. GSS-API V2) 174.03 686 T
- (\245) 90 640 T
- (Marc: \322the draft should use [GSS-API] v2 function) 108 640 T
- (names, not v1 function names\323) 108 611 T
- 2 F
- (\245) 90 566 T
- (It wasn\325t clear if referencing another ID was) 108 566 T
- (appropriate.) 108 537 T
- (\245) 90 492 T
- (Proposal: change the names to use GSS-API V2) 108 492 T
- -0.5 (function names. Change them back to V1 if the GSS-) 108 463 P
- (API V2 is not an RFC by the time the rpcsec_gss ID) 108 434 T
- (is published as its own RFC.) 108 405 T
- %%EndPage: "19" 20
