Re: [kitten] [EXTERNAL] Re: Windows Intent to revive and implement IAKerb draft-ietf-kitten-iakerb-03

"Steve Syfuhs (AP)" <Steve.Syfuhs@microsoft.com> Tue, 21 February 2023 17:44 UTC

Return-Path: <Steve.Syfuhs@microsoft.com>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 731BCC15C509 for <kitten@ietfa.amsl.com>; Tue, 21 Feb 2023 09:44:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id C_pUwvzM235R for <kitten@ietfa.amsl.com>; Tue, 21 Feb 2023 09:44:12 -0800 (PST)
Received: from BN3PR00CU001-vft-obe.outbound.protection.outlook.com (mail-eastus2azlp170100001.outbound.protection.outlook.com [IPv6:2a01:111:f403:c110::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7AD94C15170B for <kitten@ietf.org>; Tue, 21 Feb 2023 09:44:12 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=kCg+bqm7a0ZV9BbnSAqiYJ8v3nh9W3SPyfhNBFvx8nxVeSjHHADswRIhc+rIQLer3ZZem0500bRACAswcZ7nlgm3pbxyq9swmi44gc2mLJ1DZnjSNnqWkDRaEt0A5/dBIxBIEZMWifmPs9FxsoMufYbA77q+qDox48z5CgJ7KBgkXQ99aiwIJT2kbilZCScSj2CeOFwgrx+thuQy26YkMx/VbZKprGxOpJ4Eabni+gvtgRqb4ByUrYjt0bpIELb1c8O67ioO3OOAU1W47BywZBj1GzSRXRYwnzXG/fN2VB2OeipzAKPSy9gPNRblt581MiznUASQErBGxq/99amhpg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=9Rczh09zj2fYq0jhC6T6qkY46e1ReGv+OScbu5OQM50=; b=K6BlGeurFEcC4Ox4PSH4NPTfFrmoiY6iRpZRxxe3u2Ja8duhllTxTqTqfbgM7omcud1ySqPA7Kct3e/fo1zt8boSafmNxZUAxxB74GrgLK6TU25KWO+R0u1gIfK1eRWFR+1XCjCONKzfYLA40osoXV4w8iTjfy25wW9hwvTYBmgWIXiKi2zfQ4u/vMR/DRY/YUnZjJvFEX/jRIQVQzkEiQ8w8FJlCZMOiH6d44C8pUTZKtPzK5akv1egyo4k/O2QtSSTDxhTnOe8yhioruJFzi4vNHguk7THrJ//jA5klbZVTl9WMjud8OZ/7gXrpnrQyKWXlWBBmXI36u3lPxQAaA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=9Rczh09zj2fYq0jhC6T6qkY46e1ReGv+OScbu5OQM50=; b=Zo2NqZsU/JiDBsqWGwC7nxniftC79ngyPfaH6HrGG8neaYue26cM0coc0/30aZc5f2fVo9z5Ak1mR9Saz0vHu+yHicASUe+ZUtcNl0JA7QJe4csa1qHOIZGtpQ53philk+mZEYcozBU0s2yGx6W2HiOyQAbog+Zu+SKAS3O86o4=
Received: from MW4PR21MB1970.namprd21.prod.outlook.com (2603:10b6:303:70::14) by MN2PR21MB1503.namprd21.prod.outlook.com (2603:10b6:208:1f7::23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6156.4; Tue, 21 Feb 2023 17:44:08 +0000
Received: from MW4PR21MB1970.namprd21.prod.outlook.com ([fe80::5e00:89be:2491:e25]) by MW4PR21MB1970.namprd21.prod.outlook.com ([fe80::5e00:89be:2491:e25%8]) with mapi id 15.20.6156.004; Tue, 21 Feb 2023 17:44:05 +0000
From: "Steve Syfuhs (AP)" <Steve.Syfuhs@microsoft.com>
To: Nico Williams <nico@cryptonector.com>
CC: Luke Howard Bentata <lukeh@padl.com>, "kitten@ietf.org" <kitten@ietf.org>
Thread-Topic: [kitten] [EXTERNAL] Re: Windows Intent to revive and implement IAKerb draft-ietf-kitten-iakerb-03
Thread-Index: AQHZRIkZIwXtHRqIbEa9KZa+XVqqD67Wq+wAgABFUgCAAaD9AIAAArEAgAAshICAAAu+gIAA0M7wgAANhYCAAAJ04A==
Date: Tue, 21 Feb 2023 17:44:05 +0000
Message-ID: <MW4PR21MB197051A332E7DD85FFB91EE69CA59@MW4PR21MB1970.namprd21.prod.outlook.com>
References: <eb9fa7a4-a00d-f388-27aa-3624df8ce4f2@secure-endpoints.com> <MW4PR21MB197060FB388E7922FAADEB079CA19@MW4PR21MB1970.namprd21.prod.outlook.com> <6cb6f5ddfc7b9b150b4eef72db5a3f3b9566fd80.camel@redhat.com> <20230219194355.36139173DDE@pb-smtp2.pobox.com> <Y/K2IEhX6c+b05Ye@gmail.com> <Y/QT7BxdTHq0RYTz@gmail.com> <7064A9EB-EB01-426C-9BED-AFB97FA93551@padl.com> <Y/Q7hdTOF1HaxQKM@gmail.com> <Y/RFX4XywCAlhCeB@gmail.com> <MW4PR21MB197087AF4BB7632B0DF662619CA59@MW4PR21MB1970.namprd21.prod.outlook.com> <Y/T/3wwBIMZ+2mf6@gmail.com>
In-Reply-To: <Y/T/3wwBIMZ+2mf6@gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ActionId=0f6fafb4-5319-4fa2-b6aa-e6fe8bc44a2d; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=true; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=Internal; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2023-02-21T17:39:57Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47;
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=microsoft.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: MW4PR21MB1970:EE_|MN2PR21MB1503:EE_
x-ms-office365-filtering-correlation-id: 8856e65e-55a4-4389-2024-08db14333a51
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: Zdg+7/j8O3iAwYhX1LlOidafjlR+4HSJ9WEPZ9OLOmvAhvg2+UEnRYjnroFoUHG6Oe0o7RqivTcj79exAI0/5GPDLAkDAD6t1XIU2Stj4GMutqY18dsxjAmB7emB2tz5InlthJxPByM+5UUbS2uNphBWYmpwcKChcLiiRO9F5Isag2Et6vfqcPnKLOkGsgh/XHGP00ORJRiO1KETbR48fnjJwiW6lgvzoEScvFnZQE294Z2c9Vkg1AMAG8FF+urZXu9byUXuRDTybxBHPIAf3kkym4CQthuxkOQ3sTQO6RLtfIwNYZjWROy1q++lb+FnWAZP5CGOFk/eMOFshil7YwutOfGriOZxZ20vhmoPt8o9NfrSQKW63O/9krUUwEZcJeZP1a3fIoVJB6uZkHYpQSRagW8cocY7j+3EkOKB7m22daiRH3XWNIMfGQNgFo/972ELwu9GguT7vrFzVHeKX3IQyrj0mxnNXbxm6I/ovepS/T9OeLIceCqYG2si6HZ1waFa4PSOaRtyel63f9rWaoqXyrMLhBHRCCFIDS+26kchrz3ZXphu5eEgI2BC7UptQMLEOG7yaJYdVtybqTAyiOlVs9XZ15d+duTo72HSiefyZUUA0a+Xk/Kp7BV2H5Ot8+7tyEVz3MvR/3kV6cuohnvGlmoC2xz2IoEDaySJVmQfrOSFme5jNu0v5fGW0Hyvq9t0HqWUrC/u053wBcglrRL7mON8YVFHSKJsC8R+xF4LamglHa7cpoAcJ5lo4ey0wmb4OvRsybx1YMPsg4Mq7g==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MW4PR21MB1970.namprd21.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230025)(4636009)(136003)(396003)(366004)(346002)(376002)(39860400002)(451199018)(41300700001)(33656002)(76116006)(66946007)(66556008)(8676002)(66476007)(6916009)(4326008)(66446008)(64756008)(6506007)(53546011)(38100700002)(82950400001)(82960400001)(38070700005)(86362001)(5660300002)(52536014)(55016003)(8936002)(186003)(9686003)(122000001)(71200400001)(7696005)(10290500003)(478600001)(966005)(83380400001)(316002)(2906002)(8990500004)(54906003); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: tkCd+sDWJZ9JYBiZCg8WAftz8m1poxN05ugSyebiNHvhCAdOZLYeJYpc8yPcEVGhjD9OdShcT5oQHg3Ris+Y2ksVd+n6iz46Clv/jTx2wzQyrskIhDIQtkJRVwseKHtEC1y4J6tLZO70UhDH5easTm4542rePb2bW2bdj/l18ZVqlPI4Ga4CkpPmCvFKvuj2nIaUWgQafT+KA9MruT/wkQAPNUv81XU9xrPw7xO0Zpcm7/wLgx8AYoxwKcPvroGeyHil+NrZQaA2ODx2gSJ3Q4EcnPyxTBC2cYcoUSqHD3RLCuWEZjvvR0MgeXvBeM5pKcPzvdentUFOGBKf/uKi5CYzTwTjLG+A/f0srSu3MwV0ZohxbM4z4sszG4nZPnrmp5w1xeppCfFqtZQS4iEzxEY/GNQILPtFFWuIjeqRcoiiNAIZSTt+ySPPrGalHIovsEJXnB74oTVuBj3rCEDd8WxcZRYszI0eDqB2t4cyYvBYFygOrxCC7jqv4OzTaLAaqu4tKuK9H2YsXH7KTYsNvKUnznZHt7mMckTruvjab8dm41pbHmvy0tk9Jeklk7fj7QLhlA6kNu/S+5MA1B6zhQNZjTpJ0V/RuFJeKNYfiUETmCctNvsAdReHFAmuZiHlfXIxEy7GRSr9PCLIY/U3o7iCDwYzvB2rIN2yP73ipo/2h4TILJG3k3mOD1xxlKfzmO21aWLZw1iegYEUF8Wt0845fl9dh/WfIyCKcysyhmxjcQIzufdo3ims4ytClsudKEdcvuN/z6mpixs0CuDKGTkQDLT6wT/1Mo4XXSsH991HwDjeD/yZhBFmUG9BxYTcYsqki4fhgyxK4phzJ0kE9omD+FXeAJp6igzohs3Phq6Oetoolu0KQf1wjohVxJ6CmoxJYOcQrOhtB1KHEi629k+hSAEMXTz3/Ei4XR0R02bJ4PEo0+g3OeC7qCSBsQ5bWtVZrtc2QhpaCNVlC9a6Kcy+UzJj0YLjrhUqBd43/fWDtkVhiGVbQnbl86K75M5bxzzgSR0SJLsix+DEKNqwQ4WeoHYiOpWFVo/Dkw3XNR4U3Rs60AlJIrh21mDfmr88+geDh5DYFx2aktJE4veLSXGclh30jQSK2Uf0vVJLS3tw400Pti1oYBY7k+o9xM1HYncQ51386bRaJ6dZF3mBckqQOAYQUYAJ0fNXtqZFEcDt/UNaZp4HaIe7ZC4FsF8XrySjvyvSQQD3yV9lthiwKQZVR2V8Zhr5+MvIwfcj0mSFQy7BuD7k4c+ALdMvCOkLvbZ6CatUhCOckPDim9SIg7kKlz7xZnIlJcrwceYGuUBS/FydHesnwA3GcOk4axk0PXMRS1IDSWe4B/m+INsMrZ7F0bFmi6E+uyiZyC/xHKhsXGbU38LGLlQkIcwmP1j2h6xPBi8QB37T/3acuUBCATccD3SBe6RZqm0Vb5SNnPBq0XROyWZqLFLxvyjCYjizGF2NHnhOA/GwjihXpyA8hLPd3zJDn12NsaZ/qb+Y941UFdDuNRFvi6r6WvzXM/HsQaTmy8NmV9V+1W1XVmvEfQ+mvMYPq1sj8HNqa0UJuC7J8vqDFUJwj3GGKM/FGrESCgnArbESmrm92jcfBKucaID2dFHoQBo1D2h2JYQgqPWb3D7IXRpsCQyzz5XUWdrM
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MW4PR21MB1970.namprd21.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8856e65e-55a4-4389-2024-08db14333a51
X-MS-Exchange-CrossTenant-originalarrivaltime: 21 Feb 2023 17:44:05.6402 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: kC6m+DIo3MdhSXnVaUUSBr78pc6/ZUACLRBjSG0S7KMv6BKLKq41iGNEMyJcdA/Bffmuk76ylPs1UG3xMMSmtQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR21MB1503
Archived-At: <https://mailarchive.ietf.org/arch/msg/kitten/n6sWTjToQ57mLyOGAl4kKTALGMk>
Subject: Re: [kitten] [EXTERNAL] Re: Windows Intent to revive and implement IAKerb draft-ietf-kitten-iakerb-03
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Feb 2023 17:44:16 -0000

Here's a useful overview: https://syfuhs.net/how-managed-service-accounts-in-active-directory-work

Here's the derivation logic: https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/9cd2fc5e-7305-4fb8-b233-2a60bc3eec68

Here's how we generate the key generically: https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-gkdi/5d373568-dd68-499b-bd06-a3ce16ca7117

Obviously the AD/Windows-specific stuff wouldn't be appropriate to apply to a public spec, but the gist of it might be useful.

-----Original Message-----
From: Nico Williams <nico@cryptonector.com> 
Sent: Tuesday, February 21, 2023 9:31 AM
To: Steve Syfuhs (AP) <Steve.Syfuhs@microsoft.com>
Cc: Luke Howard Bentata <lukeh@padl.com>; kitten@ietf.org
Subject: Re: [kitten] [EXTERNAL] Re: Windows Intent to revive and implement IAKerb draft-ietf-kitten-iakerb-03

On Tue, Feb 21, 2023 at 04:44:15PM +0000, Steve Syfuhs (AP) wrote:
> You might also consider Active Directory's (group) managed service 
> accounts. At least the group keying mechanism.

Where would I learn more about that?

Nico
--