[18830] in Kerberos_V5_Development
Re: Automatic FAST via Anonymous PKINIT
daemon@ATHENA.MIT.EDU (Nico Williams)
Wed Jun 11 14:51:19 2014
MIME-Version: 1.0
In-Reply-To: <1402509832.2955.23.camel@ipa.example.com>
Date: Wed, 11 Jun 2014 13:51:08 -0500
Message-ID: <CAK3OfOjF9GqFevmRbb4FJtm5HsF9aOTsB9bmpCEK6tGjgpT5BQ@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Nathaniel McCallum <npmccallum@redhat.com>
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On Wed, Jun 11, 2014 at 1:03 PM, Nathaniel McCallum
<npmccallum@redhat.com> wrote:
> On Wed, 2014-06-11 at 13:52 -0400, Greg Hudson wrote:
>> If the KDC knows that the principal cannot authenticate using PKINIT, I
>> don't think it should offer PKINIT at all. Right now, the MIT KDC
>> doesn't know what principals have client certificates issued to them (if
>> any), so it offers PKINIT to all principals if the KDC is configured
>> with a KDC cert. But that's an implementation issue.
>
> Are you suggesting that PKINIT shouldn't be offered even when anonymous
> PKINIT is supported? Put otherwise, that the client should try anonymous
> PKINIT even when not offered it?
It should be offered when the cname is the anon cname, if the AS
supports anon PKINIT.
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev