Re: #22

Michael Thomas <[email protected]> Fri, 04 Feb 2005 06:15:30 -0800
Newsgroups gmane.ietf.kink
Organization Cisco Systems
Message-ID <[email protected]>
On Fri, 2005-02-04 at 04:11, Shoichi Sakane wrote:
> > #22 [*] Kerberos PFS (section 6.8)
> > 
> > 	Sec 6.8: "Kerberos in general does not provide PFS so it is somewhat 
> > 	questionable whether a system which is heavily relying on Kerberos 
> > 	benefits from PFS."  First, that sounds like it might be Security 
> > 	Considerations material.  Second, I don't follow; explain please?
> > 	(Ken Raeburn)
> 
> I agree with Ken about the first.  the document has to describe this
> issue in the security consideration even if the thing is not issue,
> at least, the document says that is questionable.
> 
> I don't understand what Ken meant.  what don't you follow ?

Well, it's pretty simple really: when you get tickets from
the KDC, they aren't protected by PFS so using PFS later
is pretty questionable. It's not useless, but it's not any
huge win either. Until Kerberos itself supports PFS, people
deploying KINK really ought not get worked up into a lather
about turning on PFS to improve security since it's doesn't
to any great degree.

		Mike
signature.asc (application/pgp-signature, 307 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iQCVAwUAQgODgbMsDAj/Eq++AQJ0PAP+O5GxqizJALjfIC2LFtel4e+fx+5AbeMi
NczRWrtnjtiUvwNLIJML+j4IbC8iWGQGkOTupUCdl7OHdWC9fdasDX71VZqxuqFy
S0IAf8C39J2Yh6w1iO2jOTmG0FBqeD8nzB1of/JuEDZEXJZaoR1GYcvWTZi5ua9K
H3PeEj7mpO0=
=ibS+
-----END PGP SIGNATURE-----