[18793] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Automatic FAST via Anonymous PKINIT

daemon@ATHENA.MIT.EDU (Benjamin Kaduk)
Mon Jun 2 17:07:45 2014

Date: Mon, 2 Jun 2014 17:07:30 -0400 (EDT)
From: Benjamin Kaduk <kaduk@mit.edu>
To: Nathaniel McCallum <npmccallum@redhat.com>
In-Reply-To: <1401737161.3521.29.camel@ipa.example.com>
Message-ID: <alpine.GSO.1.10.1406021706150.25244@multics.mit.edu>
MIME-Version: 1.0
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On Mon, 2 Jun 2014, Nathaniel McCallum wrote:

> Even if we use FAST to encrypt all traffic, the temporary anonymous
> ticket will only be used for ASReq requests. #4 provides no benefit to

Right.

> "FAST all the time" apart from ASReqs. The only case where it does make
> sense is in a login system. And the login system should (generally) be a
> Kerberos service in its own right. This is precisely how SSSD works. No
> anonymous ticket is needed because the service has its own ticket which
> is managed in the SSSD ticket ccache.

I expect that there are a lot different deployment models for kerberos, 
not all of which involve the login manager managing everything.  What you 
describe is certainly true for the case that SSSD is trying to solve; I 
don't have a good sense for what fraction of deployments it represents.

-Ben
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post