From owner-ietf-ipsra@mail.vpnc.org  Wed Jun  5 05:54:13 2002
Received: from above.proper.com (mail.proper.com [208.184.76.45])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id FAA24670
	for <ipsra-archive@odin.ietf.org>; Wed, 5 Jun 2002 05:54:13 -0400 (EDT)
Received: by above.proper.com (8.11.6/8.11.3) id g559aO123369
	for ietf-ipsra-bks; Wed, 5 Jun 2002 02:36:24 -0700 (PDT)
Received: from prv-mail25.provo.novell.com (prv-mail25.provo.novell.com [137.65.81.121])
	by above.proper.com (8.11.6/8.11.3) with ESMTP id g559aMg23363
	for <ietf-ipsra@vpnc.org>; Wed, 5 Jun 2002 02:36:22 -0700 (PDT)
Received: from INET-PRV1-MTA by prv-mail25.provo.novell.com
	with Novell_GroupWise; Wed, 05 Jun 2002 03:36:17 -0600
Message-Id: <scfd8731.045@prv-mail25.provo.novell.com>
X-Mailer: Novell GroupWise Internet Agent 6.0.2 Beta
Date: Wed, 05 Jun 2002 03:36:01 -0600
From: "Haripriya S" <SHARIPRIYA@novell.com>
To: <ietf-ipsra@vpnc.org>
Subject: PIC and LDAP authentication
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Sender: owner-ietf-ipsra@mail.vpnc.org
Precedence: bulk
List-Archive: <http://www.vpnc.org/ietf-ipsra/mail-archive/>
List-ID: <ietf-ipsra.vpnc.org>
List-Unsubscribe: <mailto:ietf-ipsra-request@vpnc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


Hi,

The introduction to the draft specifies that it can be used for legacy
password based authentication like LDAP Radius etc. to bootstrap IKE.
But EAP does not allow cleartext authentication, and only allows for
digest, one-time password or generic tokencard. Since LDAP V3 basic
authentication defines cleartext, many LDAP servers may not have
implemented digest authentication etc. Should PIC provide some way to do
cleartext authentication also? What do others think?

Thanks,
Haripriya


From owner-ietf-ipsra@mail.vpnc.org  Mon Jun 17 18:31:04 2002
Received: from above.proper.com (mail.proper.com [208.184.76.45])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA21864
	for <ipsra-archive@odin.ietf.org>; Mon, 17 Jun 2002 18:31:03 -0400 (EDT)
Received: by above.proper.com (8.11.6/8.11.3) id g5HL9cb00294
	for ietf-ipsra-bks; Mon, 17 Jun 2002 14:09:38 -0700 (PDT)
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by above.proper.com (8.11.6/8.11.3) with ESMTP id g5HL9an00290
	for <ietf-ipsra@vpnc.org>; Mon, 17 Jun 2002 14:09:37 -0700 (PDT)
Received: from CNRI.Reston.VA.US (localhost [127.0.0.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA19979;
	Mon, 17 Jun 2002 17:08:55 -0400 (EDT)
Message-Id: <200206172108.RAA19979@ietf.org>
To: IETF-Announce: ;
Cc: ietf-ipsra@vpnc.org
From: The IESG <iesg-secretary@ietf.org>
SUBJECT: Last Call: Requirements for IPsec Remote Access Scenarios to 
	   Informational
Reply-to: iesg@ietf.org
Date: Mon, 17 Jun 2002 17:08:55 -0400
Sender: owner-ietf-ipsra@mail.vpnc.org
Precedence: bulk
List-Archive: <http://www.vpnc.org/ietf-ipsra/mail-archive/>
List-ID: <ietf-ipsra.vpnc.org>
List-Unsubscribe: <mailto:ietf-ipsra-request@vpnc.org?body=unsubscribe>



The IESG has received a request from the IP Security Remote Access 
Working Group to consider Requirements for IPsec Remote Access 
Scenarios <draft-ietf-ipsra-reqmts-05.txt> as a Informational.  

The IESG plans to make a decision in the next few weeks, and solicits
final comments on this action.  Please send any comments to the 
iesg@ietf.org or ietf@ietf.org mailing lists by July 1, 2002.

Files can be obtained via 
http://www.ietf.org/internet-drafts/draft-ietf-ipsra-reqmts-05.txt





From owner-ietf-ipsra@mail.vpnc.org  Thu Jun 27 08:51:18 2002
Received: from above.proper.com (mail.proper.com [208.184.76.45])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA15364
	for <ipsra-archive@odin.ietf.org>; Thu, 27 Jun 2002 08:51:17 -0400 (EDT)
Received: from localhost (localhost [[UNIX: localhost]])
	by above.proper.com (8.11.6/8.11.3) id g5RCX1C29936
	for ietf-ipsra-bks; Thu, 27 Jun 2002 05:33:01 -0700 (PDT)
Received: from sj-msg-core-1.cisco.com (sj-msg-core-1.cisco.com [171.71.163.11])
	by above.proper.com (8.11.6/8.11.3) with ESMTP id g5RCX0w29928
	for <ietf-ipsra@vpnc.org>; Thu, 27 Jun 2002 05:33:00 -0700 (PDT)
Received: from sj-msg-av-3.cisco.com (sj-msg-av-3.cisco.com [171.69.17.42])
	by sj-msg-core-1.cisco.com (8.12.2/8.12.2) with ESMTP id g5RCWLdg023536;
	Thu, 27 Jun 2002 05:32:21 -0700 (PDT)
Received: from cisco.com (localhost [127.0.0.1])
	by sj-msg-av-3.cisco.com (8.12.2/8.12.2) with SMTP id g5RCWJnR011792;
	Thu, 27 Jun 2002 05:32:20 -0700 (PDT)
Message-ID: <3D1B0563.1A160E15@cisco.com>
Date: Thu, 27 Jun 2002 14:30:27 +0200
From: "W. Mark Townsley" <townsley@cisco.com>
X-Mailer: Mozilla 4.76 [en]C-CCK-MCD   (Windows NT 5.0; U)
X-Accept-Language: en
MIME-Version: 1.0
To: iesg@ietf.org, ietf-ipsra@vpnc.org
Subject: Re: Last Call: Requirements for IPsec Remote Access Scenarios to 
 Informational
References: <200206172108.RAA19979@ietf.org>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-ipsra@mail.vpnc.org
Precedence: bulk
List-Archive: <http://www.vpnc.org/ietf-ipsra/mail-archive/>
List-ID: <ietf-ipsra.vpnc.org>
List-Unsubscribe: <mailto:ietf-ipsra-request@vpnc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit



I have a number of comments on draft-ietf-ipsra-reqmts-05.txt which I would like
to see addressed before advancement. I interspersed these within the text of the
34 page draft, and instead of sending the whole document to the list, provided a
link for interested parties to consult:

http://www.townsley.net/mark/ipsra-comments.txt

Please find my comments marked with ****

Thanks,

- Mark

The IESG wrote:
> 
> The IESG has received a request from the IP Security Remote Access
> Working Group to consider Requirements for IPsec Remote Access
> Scenarios <draft-ietf-ipsra-reqmts-05.txt> as a Informational.
> 
> The IESG plans to make a decision in the next few weeks, and solicits
> final comments on this action.  Please send any comments to the
> iesg@ietf.org or ietf@ietf.org mailing lists by July 1, 2002.
> 
> Files can be obtained via
> http://www.ietf.org/internet-drafts/draft-ietf-ipsra-reqmts-05.txt


