[18780] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Automatic FAST via Anonymous PKINIT

daemon@ATHENA.MIT.EDU (Nico Williams)
Wed May 21 17:23:49 2014

MIME-Version: 1.0
In-Reply-To: <1400612350.31402.62.camel@ipa.example.com>
Date: Wed, 21 May 2014 16:23:33 -0500
Message-ID: <CAK3OfOhRPOLaS83o=NGaAiCS9_ruR++XNKPo-GubQrZpL81=iA@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Nathaniel McCallum <npmccallum@redhat.com>
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On Tue, May 20, 2014 at 1:59 PM, Nathaniel McCallum
<npmccallum@redhat.com> wrote:
> === CLIENT TRUST ===
>
> Using other methods of establishing the FAST channel imply an already
> established trust between the client and the server. In the case of
> SSSD, for instance, the client has already been added to the FreeIPA
> realm. This added level of trust is necessary because, unlike
> non-preauth Kerberos, long term secrets are going over the wire. When
> using Anonymous PKINIT, this trust takes the form of trusting a
> certificate's CA chain. We have discussed four approaches with MIT.

One more possible method for establishing trust would be for the user
to convey it via their realm name, something like:

foouser@+MYREALM

or

foouser@WELLKNOWN:FAST:MYREALM

I like the first because it's easy to use, though technically it is
camping, but I don't think I care in this case.

This has the added benefit that setting +MYREALM as a default/user
realm in krb5.conf is all that would have to be done to configure FAST
support.  Unfortunately this would probably break things like Java
JGSS, so never mind this part.

Nico
--
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post