[37263] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Constrained Delegation and PAC : Realm crossover

daemon@ATHENA.MIT.EDU (Rick van Rein)
Tue Oct 20 04:55:14 2015

Message-ID: <56260155.3080706@openfortress.nl>
Date: Tue, 20 Oct 2015 10:54:45 +0200
From: Rick van Rein <rick@openfortress.nl>
MIME-Version: 1.0
To: kerberos@mit.edu
In-Reply-To: <5624AB57.7030602@openfortress.nl>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Hi Simo,

> I guess I need to ask you for a detailed example of a transaction to
> understand what you are aiming to.

Gladly, thanks :)

An example of use I have in mind is a party owning a domain name, based on externally hosted components from online providers, all secured and linked together through Kerberos.  The domain name may provide basic mechanisms such as web, IMAP and SMTP.  The domain's KDC is either included in the domain package or taken in from an externally hosted service, or perhaps this is the one component hosted under own control (maybe using a dedicated Raspberry Pi distribution).

To assert his online identity, the domain owner can take in externally hosted services like XMPP and SIP.  And a Kerberos-protected WebMail may be taken in because of its user interface.  This WebMail service is interesting, because it requires access to IMAP and SMTP.  Since this WebMail is an external service, it should not be permitted more access than what it needs to function though.

I am wondering if constrained delegation can help the domain's clients to safely use the external WebMail service, with constrained delegation to limit the access from WebMail to IMAP and SMTP and nothing more.

Sorry if I'm not very good at reverse-engineering the security architecture from the MS-SFU, -KILE and -PAC documentation.  I also didn't find a HOWTO-styled instruction for this facility with an open source Kerberos.

Thanks!
 -Rick



________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post