[4059] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

[krbdev.mit.edu #1407] KDC should not check transited policy on

daemon@ATHENA.MIT.EDU (Sam Hartman via RT)
Thu Apr 3 11:09:44 2003

Date: Thu, 3 Apr 2003 11:09:34 -0500 (EST)
Message-Id: <rt-1407-5610.18.9892564153247@krbdev.mit.edu>
In-Reply-To: <rt-1407@krbdev.mit.edu>
From: "Sam Hartman via RT" <rt-comment@krbdev.mit.edu>
To: krb5-prs@mit.edu
Reply-To: rt-comment@krbdev.mit.edu
Errors-To: krb5-bugs-bounces@mit.edu



Section 1.1 of Kerberos clarifications recommends that even if the KDC
is doing transited policy checking, only the KDC closest to the
application should do so.  I propose that we make krb5_rd_req have an
option to turn TP checking into a non-fatal condition and use this
option to avoid doing TP checking on intermediate KDCs.

I don't think this should be a 1.3 feature although I would like to
see it in 1.3.1.

_______________________________________________
krb5-bugs mailing list
krb5-bugs@mit.edu
http://mailman.mit.edu/mailman/listinfo/krb5-bugs

home help back first fref pref prev next nref lref last post