Re: AD Review: draft-ietf-kink-kink [starting at section 5]
Ken Raeburn <[email protected]> Sat, 29 Jan 2005 00:13:31 -0500
| Newsgroups | gmane.ietf.kink |
|---|---|
| Message-ID | <[email protected]> |
On Jan 28, 2005, at 21:19, Sam Hartman wrote: > Section 5.1.5: > > [**] Please Consider how this works in the cross-realm case. > I.E. make sure you end up with the right ticket on the right side. I > believe this text assumes that you need a ticket in a realm close to > the client; I think that for things to work you actually need a realm > close to the server. Work through the message flows and make sure the > KDC doing the decryption actually has the necessary keys and then > adjust the document if necessary so the right KDC is used. In working this through, I suggest attention also be paid to whether anything happening is specific to KINK, or if we're just working through issues of cross-realm user-to-user authentication that rfc1510/clarifications might not have explained adequately. (We use user-to-user rarely enough in most situations, I don't know if anyone's actually using it in the cross-realm case.) Ken