Re: AD review of draft-sakane-dhc-dhcpv6-kdc-option-13.txt
Shoichi Sakane <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
Stephen and Jeff, I have submitted the new version. Could you please let me know if you find a problem ? Thanks, Shoichi On 2/3/12 9:57 PM, Stephen Farrell wrote: > > Hiya, > > From my point of view this is fine to go ahead so > once you've submitted the new version and the chairs > are ok with that, I'll start IETF LC. > > Thanks for taking all those changes, > Cheers, > Stephen. > > On 02/02/2012 01:13 AM, Shoichi Sakane wrote: >> Stephen, Jeff, >> >>> > Editorials, please see the suggestions in the attached. Use >>> > rfcdiff to see what's what, I just edited the .txt file (which >>> > was *much* quicker than writing up each of the *many* editorial >>> > changes). >>> >>> Many thanks for taking the time to deal with this. >> >> I am grateful to you very much for your review and suggestions. >> 100% was merged. I will submit new version 14. >> >> I made a rfcdiff: >> >> http://www.tanu.org/~sakane/limited/kdc-option-14-SF-03.diff.html >> >> According to Jeff's suggestion, I replaced the word "server" into >> the explicit word except that the meaning is explicitly clear by >> the context in the sentence. >> >> Please check it if there is something wrong. >> >>> > - I have no idea what the 1st paragraph on p12 is meant to say. >>> > Please clarify. >>> This is a reference to a well-known attack on certain uses of Kerberos, >>> known as the "Zanarotti attack", originally described by Stan Zanarotti >>> at MIT back in the 1980's. Basically, an attacker typing a Kerberos >>> password to log in to a machine can collude with a bogus KDC to gain >>> unauthorized access, if the software verifying the password does not >>> have a shared secret with the KDC and correctly use it to validate the >>> obtained tickets. >>> >>> Describing this attack and how to defend against it in detail is out of >>> scope for the present document; however, it is appropriate to mention it >>> because the present document introduces a new way in which an attacker >>> might get a client to talk to a rogue KDC. >> >> Do you think that the document needs to refer somehitng about >> "Zanarotti attack" ? If so, could you give me a reference ? >> >> Many thanks, >> Shiochi >> > _______________________________________________ > ietf-krb-wg mailing list > [email protected] > https://lists.anl.gov/mailman/listinfo/ietf-krb-wg _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg