[19090] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Proposal for using NAPTR/URI records

daemon@ATHENA.MIT.EDU (Simo Sorce)
Tue Feb 24 09:50:13 2015

Message-ID: <1424789388.13431.3.camel@willson.usersys.redhat.com>
From: Simo Sorce <simo@redhat.com>
To: Nico Williams <nico@cryptonector.com>
Date: Tue, 24 Feb 2015 09:49:48 -0500
In-Reply-To: <CAK3OfOi8GEZrL7zTUYi1dHMgkUT-Ywrb4pxgGw4=Ftd-Vk14nA@mail.gmail.com>
Mime-Version: 1.0
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On Mon, 2015-02-23 at 22:59 -0600, Nico Williams wrote:
> Using NAPTR certainly takes MS-KKDCP from the realm of curiosity that
> might turn out to be very handy, to the realm that requires
> significant security review and treading carefully.
> 
> Even just plain URI.  The first thing that comes up is: OK, so I'm
> discovering a proxy for a realm's KDCs, but how do I know what's safe
> to expose to said proxy?  Should I always use FAST w/ anon PKINIT?
> What is the complete list of what will leak?  When should DNSSEC be
> required?
> 
> One might as well put capaths in DNS, with similar (further-reaching)
> considerations.

I do not see how exposing KKDCP in DNS is any different from current DNS
SRV records, therefore I do not see why it requires additional security
considerations.

Can you explain ?

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York

_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post