Re: AD review of draft-sakane-dhc-dhcpv6-kdc-option-13.txt

Shoichi Sakane <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
Stephen and Jeff,

I have submitted the new version.
Could you please let me know if you find a problem ?

Thanks,
Shoichi

On 2/3/12 9:57 PM, Stephen Farrell wrote:
>
> Hiya,
>
>  From my point of view this is fine to go ahead so
> once you've submitted the new version and the chairs
> are ok with that, I'll start IETF LC.
>
> Thanks for taking all those changes,
> Cheers,
> Stephen.
>
> On 02/02/2012 01:13 AM, Shoichi Sakane wrote:
>> Stephen, Jeff,
>>
>>> > Editorials, please see the suggestions in the attached. Use
>>> > rfcdiff to see what's what, I just edited the .txt file (which
>>> > was *much* quicker than writing up each of the *many* editorial
>>> > changes).
>>>
>>> Many thanks for taking the time to deal with this.
>>
>> I am grateful to you very much for your review and suggestions.
>> 100% was merged. I will submit new version 14.
>>
>> I made a rfcdiff:
>>
>> http://www.tanu.org/~sakane/limited/kdc-option-14-SF-03.diff.html
>>
>> According to Jeff's suggestion, I replaced the word "server" into
>> the explicit word except that the meaning is explicitly clear by
>> the context in the sentence.
>>
>> Please check it if there is something wrong.
>>
>>> > - I have no idea what the 1st paragraph on p12 is meant to say.
>>> > Please clarify.
>>> This is a reference to a well-known attack on certain uses of Kerberos,
>>> known as the "Zanarotti attack", originally described by Stan Zanarotti
>>> at MIT back in the 1980's. Basically, an attacker typing a Kerberos
>>> password to log in to a machine can collude with a bogus KDC to gain
>>> unauthorized access, if the software verifying the password does not
>>> have a shared secret with the KDC and correctly use it to validate the
>>> obtained tickets.
>>>
>>> Describing this attack and how to defend against it in detail is out of
>>> scope for the present document; however, it is appropriate to mention it
>>> because the present document introduces a new way in which an attacker
>>> might get a client to talk to a rogue KDC.
>>
>> Do you think that the document needs to refer somehitng about
>> "Zanarotti attack" ? If so, could you give me a reference ?
>>
>> Many thanks,
>> Shiochi
>>
> _______________________________________________
> ietf-krb-wg mailing list
> [email protected]
> https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.