WG15 RGSEC Action Item Report Tokyo 1994 May 10 WG15 N488 Response to Danish delegation documents WG15 N304 and WG15 N379 RESPONSE In response to the Danish "NO" vote on the NP for the POSIX Security Amendment (N379), and on the objections to the POSIX 1003.6 Draft 12 distribution (N304), RGSEC makes the following comments. RGSEC agrees with the POSIX Security Working Group opinion that the inclusion of authentication interfaces in the P1003.1e and P1003.2c draft standards is beyond the scope of those documents. 9945-1 does not include the concept of a "user", only the concept of a user ID. Thus, there was no basis upon which an authentication API could be proposed. There is significant overlap in this area with the work of the POSIX administration working group. RGSEC agrees with the Danish comments that authentication APIs should be addressed by 9945. However, RGSEC does not want to hold up the completion of the current POSIX Security Amendment to try to resolve these issues. Additionally, there is ongoing work in the Internet Engineering Task Force (IETF Generic Security Serives API - GSSAPI) and at the US NAtional Institute of Science and Technology (the NIST Common Authentication Technology - CAT - initiative), and RGSEC recommends that WG15 advis the POSIX Security Working Group to wait until these other efforts are more mature rather than duplicating effort. It should be noted that the POSIX Security Working Group has identified a group of people who are willing to undertake the development of a POSIX API in the area of authentication, and has submitted a PAR to PASC to perform this work. RGSEC encourages the Danish delegation to have any interested parties in Denmark contact the POSIX Security Working Group CoChair to ensure that their concerns are being addressed, and to also help in the creation of the standard if appropriate. The POSIX Security Working Group CoChair is: Jon F. Spencer DataGeneral Corporation 62 T.W. Alexander Drive, MS 119 Research Triangle Park, NC 27709 USA +1-919-248-6246 FAX +1-919-248-6108 spencer@rtp.dg.com