Re: [kitten] draft-ietf-kitten-cammac kdc-verifier omission
Greg Hudson <ghudson@mit.edu> Thu, 12 February 2015 21:21 UTC
Return-Path: <ghudson@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1])
by ietfa.amsl.com (Postfix) with ESMTP id 7CD011A1A39
for <kitten@ietfa.amsl.com>; Thu, 12 Feb 2015 13:21:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5
tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001,
T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44])
by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id j5RlJ20pQ-OS for <kitten@ietfa.amsl.com>;
Thu, 12 Feb 2015 13:21:26 -0800 (PST)
Received: from dmz-mailsec-scanner-2.mit.edu (dmz-mailsec-scanner-2.mit.edu
[18.9.25.13])
(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
(No client certificate requested)
by ietfa.amsl.com (Postfix) with ESMTPS id 644671A1A12
for <kitten@ietf.org>; Thu, 12 Feb 2015 13:21:26 -0800 (PST)
X-AuditID: 1209190d-f792d6d000001fc7-1b-54dd1955283f
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39])
(using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits))
(Client did not present a certificate)
by dmz-mailsec-scanner-2.mit.edu (Symantec Messaging Gateway) with SMTP id
8B.F6.08135.5591DD45; Thu, 12 Feb 2015 16:21:25 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11])
by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id t1CLLJJm026248;
Thu, 12 Feb 2015 16:21:19 -0500
Received: from [18.101.8.113] (vpn-18-101-8-113.mit.edu [18.101.8.113])
(authenticated bits=0) (User authenticated as ghudson@ATHENA.MIT.EDU)
by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t1CLLHiQ003065
(version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT);
Thu, 12 Feb 2015 16:21:19 -0500
Message-ID: <54DD194D.2010201@mit.edu>
Date: Thu, 12 Feb 2015 16:21:17 -0500
From: Greg Hudson <ghudson@mit.edu>
User-Agent: Mozilla/5.0 (X11; Linux x86_64;
rv:31.0) Gecko/20100101 Thunderbird/31.4.0
MIME-Version: 1.0
To: Benjamin Kaduk <kaduk@mit.edu>
References: <x7d7fvo404h.fsf@equal-rites.mit.edu>
<alpine.GSO.1.10.1502121341360.3953@multics.mit.edu>
In-Reply-To: <alpine.GSO.1.10.1502121341360.3953@multics.mit.edu>
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: 8bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrHIsWRmVeSWpSXmKPExsUixG6nrhsqeTfE4Ms0IYujm1exODB6LFny
kymAMYrLJiU1J7MstUjfLoEro/HwP5aCRs6KxUffsjcwrmXvYuTkkBAwkVjStIEFwhaTuHBv
PRuILSSwmEliY1diFyMXkL2RUWL1gR5WCOcIk0TLtGZWkCpeATWJP9PfgtksAqoS929PB+tm
E1CWWL9/K9hUUYEwie+bdzBD1AtKnJz5BCwuIqAksfhsC1g9s4CwxIXte8HmCAu4SBx48IIR
4oo0iRe3P4NdyingKNG97DtUvZ7Ejuu/WCFseYnmrbOZJzAKzkKyYhaSsllIyhYwMq9ilE3J
rdLNTczMKU5N1i1OTszLSy3SNdLLzSzRS00p3cQIClZOSd4djO8OKh1iFOBgVOLhDTC+EyLE
mlhWXJl7iFGSg0lJlLed726IEF9SfkplRmJxRnxRaU5q8SFGCQ5mJRFe9Y9A5bwpiZVVqUX5
MClpDhYlcd5NP/hChATSE0tSs1NTC1KLYLIyHBxKErxGEkBDBYtS01Mr0jJzShDSTBycIMN5
gIa/Fgeq4S0uSMwtzkyHyJ9iVJQS5/0HkhAASWSU5sH1wpLJK0ZxoFeEeXNAVvAAExFc9yug
wUxAgyfOuA0yuCQRISXVwOjr8HGL3/aumo02cd2zzlWzelx31+MXu5R/UXd7//2KxXIH7jfs
WLIw2z3Kyfrbu2ebX7Aalm9d7xgVZJlX8vfjb/O0qsktpveDjFZemXFyr95v/R1GE7x9LFPs
dU2S59tK/o55aVl7VHXq1y0PfNdpbY998VWyTVC0Z8qT0p1uqWf7QhSqopRYijMSDbWYi4oT
Aa1394ABAwAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/Ye63TpJgrf8uz3gFgrBD_TbubIg>
Cc: kitten@ietf.org
Subject: Re: [kitten] draft-ietf-kitten-cammac kdc-verifier omission
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>,
<mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>,
<mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Feb 2015 21:21:29 -0000
On 02/12/2015 01:47 PM, Benjamin Kaduk wrote: > Do you want to come up with a concrete proposal for new text? Sure. In section 8 (Security Considerations), replace "two exceptions" with "three exceptions," and add a third item to the list: --- 3. If the ticket server principal is a cross-realm TGS from a different realm, the CAMMAC's kdc-verifier cannot be validated because the checksum was made using the other realm's local TGS key. If the CAMMAC's svc-verifier is valid, the CAMMAC contents can be safely assumed to have originated from the other realm. The KDC SHOULD NOT blindly copy CAMMAC elements originating from another realm, but MAY choose to filter, transform, and propagate elements according to policy rules, and MAY place a kdc-verifier in the new CAMMAC containing the resulting authorization data elements. --- I use MUST NOT instead of SHOULD NOT because a KDC might be in a subsidiary relationship to a higher-security realm. By "cross-realm TGS from a different realm," I mean an incoming cross-realm krbtgt principal like "krbtgt/MYKDCREALM@FOREIGNREALM," but I don't see a need to spell that out.
- [kitten] draft-ietf-kitten-cammac kdc-verifier om… Greg Hudson
- Re: [kitten] draft-ietf-kitten-cammac kdc-verifie… Benjamin Kaduk
- Re: [kitten] draft-ietf-kitten-cammac kdc-verifie… Greg Hudson
- Re: [kitten] draft-ietf-kitten-cammac kdc-verifie… Tom Yu
- Re: [kitten] draft-ietf-kitten-cammac kdc-verifie… Greg Hudson
- Re: [kitten] draft-ietf-kitten-cammac kdc-verifie… Benjamin Kaduk
- Re: [kitten] draft-ietf-kitten-cammac kdc-verifie… Simo Sorce
- Re: [kitten] draft-ietf-kitten-cammac kdc-verifie… Benjamin Kaduk
- Re: [kitten] draft-ietf-kitten-cammac kdc-verifie… Tom Yu
- Re: [kitten] draft-ietf-kitten-cammac kdc-verifie… Simo Sorce
- Re: [kitten] draft-ietf-kitten-cammac kdc-verifie… Tom Yu