Re: [kitten] draft-perez-krb-wg-gss-preauth
Greg Hudson <ghudson@mit.edu> Mon, 02 August 2021 16:23 UTC
Return-Path: <ghudson@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
by ietfa.amsl.com (Postfix) with ESMTP id 46BC83A0BF1;
Mon, 2 Aug 2021 09:23:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.199
X-Spam-Level:
X-Spam-Status: No, score=-4.199 tagged_above=-999 required=5
tests=[BAYES_00=-1.9, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_MED=-2.3,
SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44])
by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id 70GhfmexVXUn; Mon, 2 Aug 2021 09:23:28 -0700 (PDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11])
(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
(No client certificate requested)
by ietfa.amsl.com (Postfix) with ESMTPS id 407313A0BEF;
Mon, 2 Aug 2021 09:23:27 -0700 (PDT)
Received: from [18.30.9.158] ([18.30.9.158]) (authenticated bits=0)
(User authenticated as ghudson@ATHENA.MIT.EDU)
by outgoing.mit.edu (8.14.7/8.12.4) with ESMTP id 172GNOcC025208
(version=TLSv1/SSLv3 cipher=AES128-GCM-SHA256 bits=128 verify=NOT);
Mon, 2 Aug 2021 12:23:25 -0400
To: Luke Howard <lukeh=40padl.com@dmarc.ietf.org>,
"kitten@ietf.org" <kitten@ietf.org>
Cc: Alejandro Perez Mendez <alex@um.es>
References: <919B7645-005D-417B-AF1E-EDF165E94BAC@padl.com>
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <24346b50-09d5-f4b6-f5fe-7790809a7fe7@mit.edu>
Date: Mon, 2 Aug 2021 12:23:24 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101
Thunderbird/78.7.1
MIME-Version: 1.0
In-Reply-To: <919B7645-005D-417B-AF1E-EDF165E94BAC@padl.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/IR2XpqU4UjuqlMaSHQYww1jCZvg>
Subject: Re: [kitten] draft-perez-krb-wg-gss-preauth
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>,
<mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>,
<mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Aug 2021 16:23:32 -0000
On 8/1/21 9:37 AM, Luke Howard wrote: > I’m working on an implementation > of draft-perez-krb-wg-gss-preauth-02.txt for Heimdal. > > Is this something the working group would consider adopting? I'm not writing to support adoption, but I did have a note on the draft. PA-GSS contains a state object which has similar protections as is needed for PA-FX-COOKIE (see https://web.mit.edu/kerberos/krb5-latest/doc/formats/cookie.html and note the additional binding of the client principal to the cookie encryption key). It might facilitate sharing to just handle the state via PA-FX-COOKIE rather than baking it into the preauth mech.
- [kitten] draft-perez-krb-wg-gss-preauth Luke Howard
- Re: [kitten] draft-perez-krb-wg-gss-preauth Benjamin Kaduk
- Re: [kitten] draft-perez-krb-wg-gss-preauth Luke Howard
- Re: [kitten] draft-perez-krb-wg-gss-preauth Benjamin Kaduk
- Re: [kitten] draft-perez-krb-wg-gss-preauth Luke Howard
- Re: [kitten] draft-perez-krb-wg-gss-preauth Greg Hudson
- Re: [kitten] draft-perez-krb-wg-gss-preauth Luke Howard
- Re: [kitten] draft-perez-krb-wg-gss-preauth Luke Howard
- Re: [kitten] draft-perez-krb-wg-gss-preauth Greg Hudson
- Re: [kitten] draft-perez-krb-wg-gss-preauth Luke Howard