[22876] in Kerberos
Re: TD-REQ_SEQ
daemon@ATHENA.MIT.EDU (Sam Hartman)
Tue Nov 23 12:56:25 2004
To: "Ahluwalia, Ish" <iahluwalia@sonusnet.com>
From: Sam Hartman <hartmans@mit.edu>
Date: Tue, 23 Nov 2004 12:55:54 -0500
In-Reply-To:
<A3863F3136CBC546A40A61BA9CBA9D930113D853@sonusmail03.sonusnet.com> (Ish
Ahluwalia's message of "Tue, 23 Nov 2004 07:55:10 -0500")
Message-ID: <tsloeho30wl.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
>>>>> "Ahluwalia," == Ahluwalia, Ish <iahluwalia@sonusnet.com> writes:
Ahluwalia,> It's actually part of a KRB_ERROR message as per
Ahluwalia,> Kerberos Specification (Revision 8). It contains the
Ahluwalia,> Sequence number contained in the AP_REQ. It's part of
Ahluwalia,> AppSpecificTypedData which can be used to bind a
Ahluwalia,> KRB-ERROR message to the sequence number from an
Ahluwalia,> authenticator. -----
Kerberos revisions 08 is a dead end; the IETF has decided not to go in
that direction for the Kerberos protocol. Please look at
draft-ietf-krb-wg-kerberos-clarifications and
draft-yu-kerberos-extensions instead.
--Sam
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos