[18835] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: [kitten] Verified authorization data

daemon@ATHENA.MIT.EDU (Peter Mogensen)
Thu Jun 12 08:55:43 2014

Message-ID: <5399A341.3070104@one.com>
Date: Thu, 12 Jun 2014 14:55:29 +0200
From: Peter Mogensen <apm@one.com>
MIME-Version: 1.0
To: Simo Sorce <simo@redhat.com>
In-Reply-To: <1402577232.22737.26.camel@willson.usersys.redhat.com>
Cc: "kitten@ietf.org" <kitten@ietf.org>, "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On 2014-06-12 14:47, Simo Sorce wrote:
> On Thu, 2014-06-12 at 09:12 +0200, Peter Mogensen wrote:
>> Sure... any solution to the S4U2proxy use case would require protecting
>> the ticket and attached authdata, which the KDC has to trust against
>> service tampering.
>
> Sorry, no, the binding to the specific ticket is not a requirement for
> s4u2proxy. The only requirement there is the KDC MAC which could be done
> the same way as the SVC MAC.


Doesn't that depend on what any authdata plugin at the KDC might need to 
do with any authdata in the evidence ticket when processing the 
S4U2proxy TGS?
Such authdata in the evidence ticket could be something which the KDC 
would be in a position to verify in the principal database and issue a 
fresh copy.
But it could also be that the KDC had to trust the authdata in the 
evidence ticket at copy that information into the issued ticket.
In that case, you would need to protect against a service inserting 
authdata from another ticket into the evidence ticket.

/Peter

_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post