Re: #22

Michael Thomas <[email protected]> Tue, 08 Feb 2005 15:17:29 -0800
Newsgroups gmane.ietf.kink
Organization Cisco Systems
Message-ID <[email protected]>
On Tue, 2005-02-08 at 13:48, Bill Sommerfeld wrote:
> On Tue, 2005-02-08 at 16:24, Sam Hartman wrote:
> > >>>>> "Michael" == Michael Thomas <[email protected]> writes:
> > 
> >     Michael> Well, it's pretty simple really: when you get tickets
> >     Michael> from the KDC, they aren't protected by PFS so using PFS
> >     Michael> later is pretty questionable. It's not useless, but it's
> >     Michael> not any huge win either. Until Kerberos itself supports
> >     Michael> PFS, people deploying KINK really ought not get worked up
> >     Michael> into a lather about turning on PFS to improve security
> >     Michael> since it's doesn't to any great degree.
> > 
> > I'm confused.  I thought the point of PFS was to make it impossible to
> > recover session data .  How does the fact that the KDC does not do PFS
> > decrease the value of PFS for Kink?
> 
> I'm also confused by Michael's remarks, but, as I recall, one of the 
> motivations for KINK was to do IPsec SA setup with lower CPU overhead
> by avoiding public key operations.   If you add in a D-H exchange for PFS, 
> you blow away that motivation and this winds up looking like a strange
> way to build a GSS-authenticated IKE..

This all comes down to what constitutes a "session". I'd
argue that it would be a lot better if Kerberos "sessions" (ie, tickets
and their lifetimes) provided the notion of PFS since 
that would cover every protocol that implements kerberos
authentication instead of the piecemeal approach that 
each kerberos application needs to deal with PFS itself. 
That and the place that I'd think you _really_ want PFS
is for the AS-REQ/AS-REP since that's where the most
vulnerable piece of information is exchanged (ie, the
password). 

In fact, I'd be willing to wager that KINK is the _only_ 
Kerberized application that has any notion of PFS right now
which really illustrates why if people think that PFS is
important, it ought to be done up a level.

But.. we are where we are. If the editorial comment is 
really causing mass hysteria, then we should just take
it out because it doesn't affect anything about KINK.

		Mike
signature.asc (application/pgp-signature, 307 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iQCVAwUAQglIibMsDAj/Eq++AQJd1gP9EbLb+TUcp7V+jyLofrE9MYuowy+B4IHN
djVFLHQrZDecgGiV/bFBphgopz9UjkijnDr35ApslGYFgfy1mFG+Ps4JnnMYW3U6
ALKR+AVHd4YzkSwoci4siEEXZZTc9BZ6TxA5m4OoolLqUu//bUIvNMunZsPqYUst
xb+i95NRRik=
=ZT63
-----END PGP SIGNATURE-----