On Mon, Oct 03, 2011 at 01:21:11PM +0100, Roland C. Dowdeswell wrote:
> Well, given that the historical best practices for Kerberos tickets
> was to put addresses in them, I think that we can see that they
> were not meant to be shared between computers without actually
> being explicitly forwarded from one computer to the other.
(Strictly speaking, addresses belong to interfaces not to computers. As
well as a computer may have multiple interfaces, even an address could
be shared between computers in some setups.)
Tickets can anyway contain multiple addresses so this is no hinder for
distributing a ticket, besides knowing the relevant addresses at the
time of its creation.
So this is actually unrelated to the choice between addressbound and
addressless tickets.
In general I avoid taking "usual Kerberos practices" for granted. Kerberos
is kind of an extreme example of widely spread misunderstood deployments.
[Think f.i. of the idea to give all applications on a host the same
Kerberos configuration (not really bad, mostly inconvenient) and also
the same keytab file (which is really bad but... well... suggested by
the API and documentation). So even if something really was meant to
be used in a certain way (how do we know for sure?), it does not imply
that the way is the best one, not even that it is recommendable.]
Regards,
Rune
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.