[7839] in Kerberos

home help back first fref pref prev next nref lref last post

Re: destruction of Kerberos credentials upon logout

daemon@ATHENA.MIT.EDU (Sam Hartman)
Thu Aug 22 18:29:27 1996

To: "Donald T. Davis" <don@cam.ov.com>
Cc: kerberos@MIT.EDU
From: Sam Hartman <hartmans@MIT.EDU>
Date: 22 Aug 1996 18:12:44 -0400
In-Reply-To: "Donald T. Davis"'s message of Wed, 21 Aug 1996 19:07:48 -0400

>>>>> ""Donald" == "Donald T Davis" <don@cam.ov.com> writes:

    "Donald> I think it's worth pointing out that the problem is that
    "Donald> post-logout processes need delegated credentials.  krb
    "Donald> already has a mechanism for leaving reduced-potency
    "Donald> credentials behind at logout, so that persistent
    "Donald> processes can use them for accesses of restricted scope.
    "Donald> that's what v5 tickets' authorization_data field is for:
    "Donald> to limit the accesses that the tickets are able to
    "Donald> authenticate. if an authorization mechanism were in place
    "Donald> to fill the authz_data field, and if kerberized
    "Donald> applications knew how to enforce the authz_data's
    "Donald> restrictions, the resulting delagated tickets _could_
    "Donald> persist after logout, even by default, without much harm.
    "Donald> then, the logout procedure would clean up non-delegated
    "Donald> tickets, but might leave most delegated tickets in place.
    "Donald> because of their reduced potency, the delegated
    "Donald> credentials would not be very attractive to thieves.

	This is really great in theory, but I can't see applying it to
my logout job load.  The kind of tickets I tend to have are host
tickets in order to use rsh to execute commands on remote hosts,
tickets to access AFS, and that's about it.  All of these appear to be
potentially interesting targets.

    "Donald> 				-don davis, boston

home help back first fref pref prev next nref lref last post