[kitten] Proposal to change requirements for anonymous TGS requests

Greg Hudson <ghudson@MIT.EDU> Fri, 22 November 2013 17:10 UTC

Return-Path: <ghudson@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E45C1AE14D for <kitten@ietfa.amsl.com>; Fri, 22 Nov 2013 09:10:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.126
X-Spam-Level:
X-Spam-Status: No, score=-3.126 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.525, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0jAVXxjwSXAG for <kitten@ietfa.amsl.com>; Fri, 22 Nov 2013 09:10:48 -0800 (PST)
Received: from dmz-mailsec-scanner-6.mit.edu (dmz-mailsec-scanner-6.mit.edu [18.7.68.35]) by ietfa.amsl.com (Postfix) with ESMTP id EC9531ADFE2 for <kitten@ietf.org>; Fri, 22 Nov 2013 09:10:47 -0800 (PST)
X-AuditID: 12074423-b7f2b6d000000ce1-48-528f9010cd50
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-6.mit.edu (Symantec Messaging Gateway) with SMTP id 84.28.03297.0109F825; Fri, 22 Nov 2013 12:10:40 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id rAMHAdnD005410 for <kitten@ietf.org>; Fri, 22 Nov 2013 12:10:40 -0500
Received: from localhost (equal-rites.mit.edu [18.18.1.59]) (authenticated bits=0) (User authenticated as ghudson@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id rAMHAcT1032735 for <kitten@ietf.org>; Fri, 22 Nov 2013 12:10:39 -0500
From: Greg Hudson <ghudson@MIT.EDU>
To: kitten@ietf.org
Date: Fri, 22 Nov 2013 12:10:18 -0500
Message-ID: <x7da9gw1hxh.fsf@equal-rites.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFlrGIsWRmVeSWpSXmKPExsUixCmqrSswoT/IoGWVvMXRzatYHBg9liz5 yRTAGMVlk5Kak1mWWqRvl8CVsWriMvaCPq6KriVNrA2Mb9m7GDk5JARMJK5MOskKYYtJXLi3 nq2LkYtDSGA2k8S+3o2sEM5xRomrp+8yQTgdTBJXb65hBGlhE1CWOHj2GwuILSIgLLF76ztm EFtYwFli2YU9QHEODhYBVYnrC9VBwrwChhJ//z9lh7AFJU7OfALWyiygJXHj30umCYw8s5Ck ZiFJLWBkWsUom5JbpZubmJlTnJqsW5ycmJeXWqRrppebWaKXmlK6iREUHOwuyjsY/xxUOsQo wMGoxMO7w7IvSIg1say4MvcQoyQHk5Io75S+/iAhvqT8lMqMxOKM+KLSnNTiQ4wSHMxKIrzJ 9UA53pTEyqrUonyYlDQHi5I47y0O+yAhgfTEktTs1NSC1CKYrAwHh5IE70yQoYJFqempFWmZ OSUIaSYOTpDhPEDDm0FqeIsLEnOLM9Mh8qcYFaXEeYNBEgIgiYzSPLheWPS+YhQHekWYdwVI FQ8w8uG6XwENZgIazC7ZDTK4JBEhJdXAyHzNIObFtbKm1QqXnof/s+yLWxLTKRGQyOvxrDFo T8D9CyflFLbHXVq0c4ek+mdPPc2K93v33lDuyG2bP3Nm6p3nxb8X/Vxk65P0cmd80C4p8epd dTITH903/uL9Z5IlW8RmxR0WK316RVZXOz1T6q86e0+OOzCI6b+3jubT0zqVnf8eHLx5Qoml OCPRUIu5qDgRAG0mZPu5AgAA
Subject: [kitten] Proposal to change requirements for anonymous TGS requests
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 22 Nov 2013 17:10:49 -0000

Since I believe we plan to re-issue RFC 6112 to address the KeyExchange
vs. KEYEXCHANGE error, I would like to bring up another issue which I
noticed today.  Section 4.2 says:

   If the ticket in the PA-TGS-REQ of the TGS request is an anonymous
   one, the anonymous KDC option MUST be set in the request.  Otherwise,
   the KDC MUST return a KRB-ERROR message with the code
   KDC_ERR_BADOPTION.

MIT krb5 does not comply with this requirement on the client side and
does not check it in the KDC.  We can change that on the client, but in
general this requirement seems totally unnecessary, and the KDC side of
it seems to be a clear violation of RFC 2119 section 6.  I propose
changing this text in the re-issued RFC to:

   If the ticket in the PA-TGS-REQ of the TGS request is an anonymous
   one, the anonymous KDC option SHOULD be set in the request.

So the first MUST becomes a SHOULD, and the second sentence goes away.
If people feel that there should be a rationale for the SHOULD, I would
suggest this text instead:

   If the ticket in the PA-TGS-REQ of the TGS request is an anonymous
   one, the anonymous KDC option SHOULD be set in the request, as a
   previous version of this specification required the KDC to reject the
   TGS request otherwise.