[22810] in Kerberos
mechanisms for restricting/throttling kerberos transactions
daemon@ATHENA.MIT.EDU (Albert Lunde)
Thu Nov 4 12:47:06 2004
Message-Id: <6.0.0.22.2.20041104112212.01b46060@hecky.it.northwestern.edu>
Date: Thu, 04 Nov 2004 11:40:12 -0600
To: kerberos@mit.edu
From: Albert Lunde <Albert-Lunde@northwestern.edu>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Errors-To: kerberos-bounces@mit.edu
I'd like to know what mechanisms may exist for restricting kerberos
transactions.
I'm interested in:
1) restricting by source domain/IP
2) rate-limiting for a given source IP
3) denying access to IPs with a large number of failures
(with whitelist exceptions for known/trusted servers)
I'm interested in both generic MIT-compatible kerberos and kerberos using
Active Directory.
Our first concern is with limiting the scope of password-guessing attacks,
though there are probably some other applications.
(We are moving away from direct use of Kerberos on the desktop, and mainly
using it in server-to-server transactions, with SSL for the last hop. This
makes IP restriction conceivable, though I'm not sure how much it will help
us, or if it's feasible in the software and protocols involved. If we adopt
a WebISO system based on Kerberos, things might change.)
--
Albert Lunde Albert-Lunde@northwestern.edu (new address)
Albert-Lunde@nwu.edu (old address)
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos