[19089] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Proposal for using NAPTR/URI records

daemon@ATHENA.MIT.EDU (Nico Williams)
Mon Feb 23 23:59:15 2015

MIME-Version: 1.0
In-Reply-To: <1424742103.2604.91.camel@redhat.com>
Date: Mon, 23 Feb 2015 22:59:03 -0600
Message-ID: <CAK3OfOi8GEZrL7zTUYi1dHMgkUT-Ywrb4pxgGw4=Ftd-Vk14nA@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Nathaniel McCallum <npmccallum@redhat.com>
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

Using NAPTR certainly takes MS-KKDCP from the realm of curiosity that
might turn out to be very handy, to the realm that requires
significant security review and treading carefully.

Even just plain URI.  The first thing that comes up is: OK, so I'm
discovering a proxy for a realm's KDCs, but how do I know what's safe
to expose to said proxy?  Should I always use FAST w/ anon PKINIT?
What is the complete list of what will leak?  When should DNSSEC be
required?

One might as well put capaths in DNS, with similar (further-reaching)
considerations.

Nico
--
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post