Re: #22
Michael Thomas <[email protected]> Fri, 04 Feb 2005 06:15:30 -0800
| Newsgroups | gmane.ietf.kink |
|---|---|
| Organization | Cisco Systems |
| Message-ID | <[email protected]> |
On Fri, 2005-02-04 at 04:11, Shoichi Sakane wrote: > > #22 [*] Kerberos PFS (section 6.8) > > > > Sec 6.8: "Kerberos in general does not provide PFS so it is somewhat > > questionable whether a system which is heavily relying on Kerberos > > benefits from PFS." First, that sounds like it might be Security > > Considerations material. Second, I don't follow; explain please? > > (Ken Raeburn) > > I agree with Ken about the first. the document has to describe this > issue in the security consideration even if the thing is not issue, > at least, the document says that is questionable. > > I don't understand what Ken meant. what don't you follow ? Well, it's pretty simple really: when you get tickets from the KDC, they aren't protected by PFS so using PFS later is pretty questionable. It's not useless, but it's not any huge win either. Until Kerberos itself supports PFS, people deploying KINK really ought not get worked up into a lather about turning on PFS to improve security since it's doesn't to any great degree. Mike
signature.asc
(application/pgp-signature, 307 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iQCVAwUAQgODgbMsDAj/Eq++AQJ0PAP+O5GxqizJALjfIC2LFtel4e+fx+5AbeMi NczRWrtnjtiUvwNLIJML+j4IbC8iWGQGkOTupUCdl7OHdWC9fdasDX71VZqxuqFy S0IAf8C39J2Yh6w1iO2jOTmG0FBqeD8nzB1of/JuEDZEXJZaoR1GYcvWTZi5ua9K H3PeEj7mpO0= =ibS+ -----END PGP SIGNATURE-----