[19089] in Kerberos_V5_Development
Re: Proposal for using NAPTR/URI records
daemon@ATHENA.MIT.EDU (Nico Williams)
Mon Feb 23 23:59:15 2015
MIME-Version: 1.0
In-Reply-To: <1424742103.2604.91.camel@redhat.com>
Date: Mon, 23 Feb 2015 22:59:03 -0600
Message-ID: <CAK3OfOi8GEZrL7zTUYi1dHMgkUT-Ywrb4pxgGw4=Ftd-Vk14nA@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Nathaniel McCallum <npmccallum@redhat.com>
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
Using NAPTR certainly takes MS-KKDCP from the realm of curiosity that
might turn out to be very handy, to the realm that requires
significant security review and treading carefully.
Even just plain URI. The first thing that comes up is: OK, so I'm
discovering a proxy for a realm's KDCs, but how do I know what's safe
to expose to said proxy? Should I always use FAST w/ anon PKINIT?
What is the complete list of what will leak? When should DNSSEC be
required?
One might as well put capaths in DNS, with similar (further-reaching)
considerations.
Nico
--
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev