[18792] in Kerberos_V5_Development
Re: Automatic FAST via Anonymous PKINIT
daemon@ATHENA.MIT.EDU (Greg Hudson)
Mon Jun 2 15:59:58 2014
Message-ID: <538CD7A9.8020003@mit.edu>
Date: Mon, 02 Jun 2014 15:59:37 -0400
From: Greg Hudson <ghudson@mit.edu>
MIME-Version: 1.0
To: Nathaniel McCallum <npmccallum@redhat.com>, Benjamin Kaduk <kaduk@mit.edu>
In-Reply-To: <1401737161.3521.29.camel@ipa.example.com>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On 06/02/2014 03:26 PM, Nathaniel McCallum wrote:
> Even if we use FAST to encrypt all traffic, the temporary anonymous
> ticket will only be used for ASReq requests.
TGS requests do not need separate ticket armor to use FAST. We have
been automatically making FAST TGS requests since 1.11, although we
don't currently do anything to enforce a FAST TGS response. (And we
can't without additional protocol support, since Heimdal's KDC added
FAST negotiation without supporting FAST TGS.)
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev