Re: AD Review: draft-ietf-kink-kink [starting at section 5]

Ken Raeburn <[email protected]> Sat, 29 Jan 2005 00:13:31 -0500
Newsgroups gmane.ietf.kink
Message-ID <[email protected]>
On Jan 28, 2005, at 21:19, Sam Hartman wrote:
> Section 5.1.5:
>
> [**] Please Consider how this works in the cross-realm case.
> I.E. make sure you end up with the right ticket on the right side.  I
> believe this text assumes that you need a ticket in a realm close to
> the client; I think that for things to work you actually need a realm
> close to the server.  Work through the message flows and make sure the
> KDC doing the decryption actually has the necessary keys and then
> adjust the document if necessary so the right KDC is used.

In working this through, I suggest attention also be paid to whether 
anything happening is specific to KINK, or if we're just working 
through issues of cross-realm user-to-user authentication that 
rfc1510/clarifications might not have explained adequately.  (We use 
user-to-user rarely enough in most situations, I don't know if anyone's 
actually using it in the cross-realm case.)

Ken