[18824] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: [kitten] Verified authorization data

daemon@ATHENA.MIT.EDU (Simo Sorce)
Wed Jun 11 12:17:40 2014

Message-ID: <1402503444.13617.1.camel@willson.usersys.redhat.com>
From: Simo Sorce <simo@redhat.com>
To: Peter Mogensen <apm@one.com>
Date: Wed, 11 Jun 2014 12:17:24 -0400
In-Reply-To: <539849AA.4000506@one.com>
Mime-Version: 1.0
Cc: "kitten@ietf.org" <kitten@ietf.org>, "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On Wed, 2014-06-11 at 14:20 +0200, Peter Mogensen wrote:
> The solution in AD-CAMMAC seems very complex too, requiring
> effectively calculating the entire EncTicketPart twice - and once for
> every present AD-CAMMAC present.

I am confused about this statement. The AD-CAMMAC draft specifies that
it contains a sequence of AD elements, that means you have only 1
AD-CAMMAC for all the AD data you want to protect. You check the whole
thing only once.

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York

_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post