[2392] in Kerberos

home help back first fref pref prev next nref lref last post

Kerberos V5 Questions (not in FAQ)

daemon@ATHENA.MIT.EDU (Jennifer Kay)
Tue Nov 24 17:08:16 1992

Date: 24 Nov 92 20:36:29 GMT
From: jennie+@cs.cmu.edu (Jennifer Kay)
To: kerberos@shelby.Stanford.EDU

I'm looking into the security of kerberos, and I've got some questions
that I can't find answers to in the FAQ, I hope someone here can help
me. I'd be happy to send my results to anyone who is interested, when
I get them written up.

Questions:

1) How fast can the TGS hand out tickets, and on what architecture is
that number based on?

2) Can anyone tell me how I can get a copy of the following document
from the FAQ:
  [8] C. Neumann and J. Kohl, "The Kerberos(tm) Network Authentication
  Service (V5)," April 1992.  Currently released as an Internet Draft.

3) Is there anything stopping a client from asking for two tickets for
the same service when it's not necessary?

4) I've got a copy of the second draft of kerberos v5 (6 Nov 89), has
the format of a ticket changed since that version?

5) If the client asks the TGS for two tickets fairly close together
(i.e. doesn't need to reauthenticate to the authentication server in
between), is the "authtime" in the two tickets the same. (just
verifying that I understand what the authtime is). 

6) is it the case that the starttime, endtime, and renew_till fields
of a ticket can be specified by the client (it appears that's what the
from, till, and rtime parts of the KRB_TGS_REQ message are for, am I
right?) 

Thanks very much!!

home help back first fref pref prev next nref lref last post