Network Working Group Y. Bernet
Request for Comments: 2872 R. Pabbati
Category: Standards Track Microsoft
June 2000
Application and Sub Application Identity Policy Element for Use with RSVP
1. Overview
RSVP aware network elements may act as policy enforcement points (PEPs). These work together with policy decision points (PDPs) to enforce QoS policy. Briefly, PEPs extract policy information from RSVP signaling requests and compare the information against information stored by a PDP in a (possibly remotely located) policy database or directory. A policy decision is made based on the results of the comparison. One type of policy information describes the application on behalf of which an RSVP signaling request is generated. When application policy information is available, network administrators are able to manage QoS based on application type. So, for example, a network administrator may establish a policy that prioritizes known mission- critical applications over games.
Bernet & Pabbati Standards Track [Page 1]
RFC 2872 Application Identifiers for RSVP June 2000
This memo describes a structure for a policy element that can be used to identify application traffic flows. The policy element includes a number of attributes, one of which is a policy locator. This policy locator includes the following hierarchically ordered sub-elements (in descending levels of hierarchy):
2. Simple Application Identity Policy Element Structure
General application identity policy elements are defined in [RFC2752]. These are policy elements with a P-type of AUTH_APP. Following the policy element header is a list of authentication attributes.
Bernet & Pabbati Standards Track [Page 2]
RFC 2872 Application Identifiers for RSVP June 2000
0 1 2 3
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| PE Length (8) | P-type = AUTH_APP |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Attribute Length | A-type = | Sub-type = |
| | POLICY_LOCATOR| ASCII_DN |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Application policy locator attribute data in X.500 DN format |
| (see below) |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Attribute Length | A-type = | Sub-type = |
| | CREDENTIAL | ASCII_ID |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Application name as ASCII string |
| (e.g. SAP.EXE) |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
The following keywords are recommended although others MAY be used:Key Attribute -------------- GUID Globally Unique Identifier (optional)APP Application Name VER Application Version Number SAPP Sub Application (optional)
Bernet & Pabbati Standards Track [Page 3]
RFC 2872 Application Identifiers for RSVP June 2000 3. Security ConsiderationsThe proposed simple policy element does not guarantee that element is indeed associated with the application it claims to be associated with. In order to provide such guarantees, it is necessary to sign applications. Signed application policy elements may be proposed at a future date. Note that, typically, the application policy element will be included in an RSVP message with an encrypted and authenticated user policy element. A level of security is provided by trusting the application policy element only if the user policy element is trusted.
4. References
[RFC2205] Braden, R., Zhang, L., Berson, L., Herzog, S. and S. Jamin,
5. Acknowledgments
Thanks to Tim Moore, Shai Mohaban, Andrew Smith, Ulrich Homann and other contributors to the IETF's RAP WG for their input.
Bernet & Pabbati Standards Track [Page 4]
RFC 2872 Application Identifiers for RSVP June 2000 6. Authors' AddressesYoram Bernet Microsoft One Microsoft Way Redmond, WA 98052
Bernet & Pabbati Standards Track [Page 5]
RFC 2872 Application Identifiers for RSVP June 2000 7. Full Copyright StatementCopyright (C) The Internet Society (2000). All Rights Reserved.