[36635] in Kerberos

home help back first fref pref prev next nref lref last post

RE: PPTP / L2TP with Kerberos -- what specs does it follow?

daemon@ATHENA.MIT.EDU (Nordgren, Bryce L -FS)
Sun Nov 30 13:57:25 2014

From: "Nordgren, Bryce L -FS" <bnordgren@fs.fed.us>
To: Rick van Rein <rick@openfortress.nl>,
        Ken Hornstein <kenh@cmf.nrl.navy.mil>
Date: Sun, 30 Nov 2014 18:57:04 +0000
Message-ID: <82E7C9A01FD0764CACDD35D10F5DFB6E75C8A3@001FSN2MPN1-044.001f.mgd2.msft.net>
In-Reply-To: <F41D7A89-73C8-4E74-A22B-15AA9F36CE2C@openfortress.nl>
Content-Language: en-US
MIME-Version: 1.0
Cc: "kerberos@mit.edu" <kerberos@mit.edu>
Content-Type: text/plain; charset="utf-8"
Errors-To: kerberos-bounces@mit.edu
Content-Transfer-Encoding: 8bit

> >    Domain controllers and AD FS servers should never be exposed
> >    directly to the Internet and should only be reachable through the
> >    VPN connection.
>
> This is a very general statement, and is too broad to conclude that the
> Kerberos5 p[ao]rt should be confined to a LAN.

Kerberos is not a complete identity solution. You would also need to expose the LDAP p[ao]rt which parcels out a few user attributes (name, email, something like an SID or UID/GID...) Otherwise you have to synchronize two pieces of an identity solution run by two different organizations/people.

My understanding is that most AD trusts involve much more than just Kerberos, are two way and are transitive. There's no middle ground between "isolated" and "at the mercy of all comers."

> The modern keyword “mobility” springs to mind… And of course “SSO” as a
> clinching argument for users…

Kerberos is not a good cross-organization SSO solution, and if you're not talking cross-organization, why are you talking about off-LAN operations? :) Nico's new PKCROSS draft may change that.

Bryce




This electronic message contains information generated by the USDA solely for the intended recipients. Any unauthorized interception of this message or the use or disclosure of the information it contains may violate the law and subject the violator to civil or criminal penalties. If you believe you have received this message in error, please notify the sender and delete the email immediately.

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos


home help back first fref pref prev next nref lref last post