[18792] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Automatic FAST via Anonymous PKINIT

daemon@ATHENA.MIT.EDU (Greg Hudson)
Mon Jun 2 15:59:58 2014

Message-ID: <538CD7A9.8020003@mit.edu>
Date: Mon, 02 Jun 2014 15:59:37 -0400
From: Greg Hudson <ghudson@mit.edu>
MIME-Version: 1.0
To: Nathaniel McCallum <npmccallum@redhat.com>, Benjamin Kaduk <kaduk@mit.edu>
In-Reply-To: <1401737161.3521.29.camel@ipa.example.com>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On 06/02/2014 03:26 PM, Nathaniel McCallum wrote:
> Even if we use FAST to encrypt all traffic, the temporary anonymous
> ticket will only be used for ASReq requests.

TGS requests do not need separate ticket armor to use FAST.  We have
been automatically making FAST TGS requests since 1.11, although we
don't currently do anything to enforce a FAST TGS response.  (And we
can't without additional protocol support, since Heimdal's KDC added
FAST negotiation without supporting FAST TGS.)
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post