Re: [kitten] WGLC on draft-ietf-krb-wg-cammac-08

"Zheng, Kai" <kai.zheng@intel.com> Tue, 08 July 2014 07:59 UTC

Return-Path: <kai.zheng@intel.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4470B1A0B09 for <kitten@ietfa.amsl.com>; Tue, 8 Jul 2014 00:59:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.552
X-Spam-Level:
X-Spam-Status: No, score=-7.552 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iBVoMqc8gIu4 for <kitten@ietfa.amsl.com>; Tue, 8 Jul 2014 00:59:39 -0700 (PDT)
Received: from mga01.intel.com (mga01.intel.com [192.55.52.88]) by ietfa.amsl.com (Postfix) with ESMTP id AACF51A0B07 for <kitten@ietf.org>; Tue, 8 Jul 2014 00:59:39 -0700 (PDT)
Received: from fmsmga002.fm.intel.com ([10.253.24.26]) by fmsmga101.fm.intel.com with ESMTP; 08 Jul 2014 00:59:39 -0700
X-ExtLoop1: 1
X-IronPort-AV: E=Sophos;i="5.01,624,1400050800"; d="scan'208";a="566587645"
Received: from fmsmsx106.amr.corp.intel.com ([10.19.9.37]) by fmsmga002.fm.intel.com with ESMTP; 08 Jul 2014 00:59:05 -0700
Received: from fmsmsx157.amr.corp.intel.com (10.18.116.73) by FMSMSX106.amr.corp.intel.com (10.19.9.37) with Microsoft SMTP Server (TLS) id 14.3.123.3; Tue, 8 Jul 2014 00:59:05 -0700
Received: from shsmsx104.ccr.corp.intel.com (10.239.4.70) by FMSMSX157.amr.corp.intel.com (10.18.116.73) with Microsoft SMTP Server (TLS) id 14.3.123.3; Tue, 8 Jul 2014 00:59:05 -0700
Received: from shsmsx103.ccr.corp.intel.com ([169.254.4.210]) by SHSMSX104.ccr.corp.intel.com ([169.254.5.122]) with mapi id 14.03.0123.003; Tue, 8 Jul 2014 15:58:58 +0800
From: "Zheng, Kai" <kai.zheng@intel.com>
To: Shawn M Emery <shawn.emery@oracle.com>, "kitten@ietf.org" <kitten@ietf.org>
Thread-Topic: [kitten] WGLC on draft-ietf-krb-wg-cammac-08
Thread-Index: AQHPmm6RUB80BlquYEiOnctz7pGb45uVyPnA
Date: Tue, 08 Jul 2014 07:58:58 +0000
Message-ID: <8D5F7E3237B3ED47B84CF187BB17B666118FB2BB@SHSMSX103.ccr.corp.intel.com>
References: <53799133.70201@oracle.com> <53BB8362.3010605@oracle.com>
In-Reply-To: <53BB8362.3010605@oracle.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.239.127.40]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/kitten/H2Hno9zqry1skDaPl5xbUF_2uF0
Subject: Re: [kitten] WGLC on draft-ietf-krb-wg-cammac-08
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Jul 2014 07:59:41 -0000

Could I post a minor comment? I'm just a beginning learner so apologize if I'm doing bad here and please kindly point me elsewhere, thanks. 

Regarding the following:
===
However, protocol extensions such as Constrained Delegation (S4U2Proxy
   [MS-SFU]) require that a service present to the KDC a service ticket
   that the service received from a client, as evidence that the client
   authenticated to the service.  In the S4U2Proxy extension, the KDC
   uses the evidence ticket as the basis for issuing a derivative ticket
   that the service can then use to impersonate the client.
===
Looks like the issue this draft targets to address mainly comes from MS-S4U2Proxy. As said in the MS-S4U doc, the S4U extension is intended to
be used when the user authenticates to the service in some way other than by using Kerberos. And in the S4U2Proxy flow,  service 1 requests
a service ticket to service 2 on behalf of the named user using a forwardable service ticket (or evidence ticket mentioned here). This forwardable 
service ticket might have been obtained by a KRB_AP_REQ and come from the user client (the case mentioned here), or by an S4U2self request (ignored 
here). IMHO, it might be better to rephrase the following sentence to make it more accurate.
===
... require that a service present to the KDC a service ticket that the service received from a client
===

Regards,
Kai

-----Original Message-----
From: Kitten [mailto:kitten-bounces@ietf.org] On Behalf Of Shawn M Emery
Sent: Tuesday, July 08, 2014 1:37 PM
To: kitten@ietf.org
Subject: [kitten] WGLC on draft-ietf-krb-wg-cammac-08

This message officially starts the kitten Working Group Last Call for the following document:
   
   Kerberos Authorization Data Container Authenticated by Multiple MACs
   http://tools.ietf.org/html/draft-ietf-krb-wg-cammac-08

The Working Group Last Call for this document starts today, on Monday, 7th of July and will end on Monday, 21st of July.

Please send any comments to the kitten mailing list or directly to the chairs.  Even if you reviewed this document and found no issues then please provide this feed-back.

Thank you,

Shawn Emery
kitten co-chair
--

_______________________________________________
Kitten mailing list
Kitten@ietf.org
https://www.ietf.org/mailman/listinfo/kitten