[18791] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Automatic FAST via Anonymous PKINIT

daemon@ATHENA.MIT.EDU (Nico Williams)
Mon Jun 2 15:52:38 2014

MIME-Version: 1.0
In-Reply-To: <1401737161.3521.29.camel@ipa.example.com>
Date: Mon, 2 Jun 2014 14:52:24 -0500
Message-ID: <CAK3OfOg=ywfx0WJsZReazy6W75_Z=_7a_=XopvQxOS2gGYX+ug@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Nathaniel McCallum <npmccallum@redhat.com>
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On Mon, Jun 2, 2014 at 2:26 PM, Nathaniel McCallum
<npmccallum@redhat.com> wrote:
> Even if we use FAST to encrypt all traffic, the temporary anonymous
> ticket will only be used for ASReq requests. #4 provides no benefit to
> "FAST all the time" apart from ASReqs. The only case where it does make
> sense is in a login system. And the login system should (generally) be a
> Kerberos service in its own right. This is precisely how SSSD works. No
> anonymous ticket is needed because the service has its own ticket which
> is managed in the SSSD ticket ccache.

Mobile devices might not be keyed, or if they are they might not have
stable hostnames (so don't insist on host-based client credentials for
them, or on their matching the client's IP address).

I agree that a per-session/user FAST armor ticket for protecting AS
_and_ TGS requests would be nice.  Greg's #4 is not incompatible with
that: a PAM / whatever can make sure to obtain such a ticket for the
user, and if none is available, then kinit/krb5_get_init_creds*() can
do it (though in the last case it'd be an anon PKINIT ticket).

Nico
--
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post