Re: Miscellaneous CAMMAC issues

Jeffrey Hutzelman <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
On Wed, 2012-02-15 at 13:42 -0500, Greg Hudson wrote:
> On 02/15/2012 01:10 PM, Jeffrey Hutzelman wrote:
> > You keep saying that, but it is not true.  A service can print a ticket
> > for itself whenever it wants, not only when using S4U2Proxy.  A "normal"
> > TGS request is authenticated by a TGT, but a request to modify a ticket
> > is authenticated only by the ticket to be modified, which means that any
> > data signed by either the ticket session key or the service's long-term
> > key cannot be trusted by the KDC.
> 
> I hadn't considered renewal/validation of service tickets.  (Which is
> rare, but probably not so rare that we can throw it away.)

The important thing is that it can be done at all.  Security can't
depend on the attacker never bothering to attack. :-)

> If the KDC needs to re-sign CAMMACs during renewal/validation, then it
> does need a way to verify that it originated them.  Otherwise the target
> service could get the KDC to help it forge a trusted-svc-signature on
> arbitrary authdata elements.
> 
> I'm not sure whether the current drafts require the CAMMAC to be
> re-signed on renewal/validation.

Well, it'd have to be re-signed if its contents change.  And there's at
least some likelyhood it would need to be re-signed in this case if it
is anchored to the ticket.

-- Jeff

_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.