[19092] in Kerberos_V5_Development
Re: Proposal for using NAPTR/URI records
daemon@ATHENA.MIT.EDU (Nico Williams)
Tue Feb 24 12:15:14 2015
MIME-Version: 1.0
In-Reply-To: <CAK3OfOi7LbSBpXd0iyEsyeugk6wc7dfWtqv7JAVKzadt7AvQWw@mail.gmail.com>
Date: Tue, 24 Feb 2015 11:15:03 -0600
Message-ID: <CAK3OfOjxU5naun6BQE2AjwVdGNusEotgiZzanb+HNroMf4ui=g@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Simo Sorce <simo@redhat.com>
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
I should add that I'm assuming that an MITM wouldn't be able to get
away with modifying important bits of the protocol because we
authenticate all contents (or all that matters). So the main problem
would be information leaks and other problems with getting redirected,
such as (stretching here) changing the trust anchors that the AS'
PKINIT cert is to get validated to.
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev