[19091] in Kerberos_V5_Development
Re: Proposal for using NAPTR/URI records
daemon@ATHENA.MIT.EDU (Nico Williams)
Tue Feb 24 11:34:54 2015
MIME-Version: 1.0
In-Reply-To: <1424789388.13431.3.camel@willson.usersys.redhat.com>
Date: Tue, 24 Feb 2015 10:34:39 -0600
Message-ID: <CAK3OfOi7LbSBpXd0iyEsyeugk6wc7dfWtqv7JAVKzadt7AvQWw@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Simo Sorce <simo@redhat.com>
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On Tue, Feb 24, 2015 at 8:49 AM, Simo Sorce <simo@redhat.com> wrote:
> On Mon, 2015-02-23 at 22:59 -0600, Nico Williams wrote:
> > [...]
>
> I do not see how exposing KKDCP in DNS is any different from current DNS
> SRV records, therefore I do not see why it requires additional security
> considerations.
>
> Can you explain ?
Check out this thread (all of it, particularly Viktor D.'s and Sam
H.'s comments):
https://www.ietf.org/mail-archive/web/ietf/current/msg91915.html
It's not that it can't be done. But that it requires care.
Again, if I use a locally-configured proxy, or a proxy that is
co-located with the KDCs of the target realm, then no problem. If I
use a DNS RRset that could point to a different host, and to boot I
don't use DNSSEC, then I now I have a problem.
OTOH, it's probably not a big deal, we just need to think through the
security considerations:
- TGS exchanges leak little information about the client principal
(mostly the Ticket they are using, and in the case of user2user
Kerberos, the user2user TGT of the peer).
- AS exchanges leak the cname and crealm, but could be tunneled in
FAST w/ anon PKINIT, yielding protection for the cname, but not much
protection for the crealm (since, after all, if we're talking to an
MITM, they could have used a different host:port for each realm for
which they saw a query for a proxy).
- anything else?
BTW, the better forum for this is the KITTEN WG list.
Nico
--
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev