[18833] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: [kitten] Verified authorization data

daemon@ATHENA.MIT.EDU (Peter Mogensen)
Thu Jun 12 03:12:25 2014

Message-ID: <539952CC.8020703@one.com>
Date: Thu, 12 Jun 2014 09:12:12 +0200
From: Peter Mogensen <apm@one.com>
MIME-Version: 1.0
To: Simo Sorce <simo@redhat.com>
In-Reply-To: <1402506490.13617.9.camel@willson.usersys.redhat.com>
Cc: "kitten@ietf.org" <kitten@ietf.org>, "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On 2014-06-11 19:08, Simo Sorce wrote:
>> Still... the whole EncTicketPart has to be constructed and DER-encoded
>> twice to add a kdc-verifier.
>
> That is done to bind the CAMMAC to a specific ticket, it is an
> additional protection that you probably want for your use case too.

Sure... any solution to the S4U2proxy use case would require protecting 
the ticket and attached authdata, which the KDC has to trust against 
service tampering.
As the cammac draft says:
"...assuring the KDC that a malicious service has not substituted a 
mismatched CAMMAC received from another ticket."

But if the kdc-verifier was placed out side the EncTicketPart, then that 
would also provide that protection and not require computing the ticket 
twice - right?


/Peter



_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post