Re: Miscellaneous CAMMAC issues
Sam Hartman <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
>>>>> "Simo" == Simo Sorce <[email protected]> writes: Simo> The reason why I proposed to use the long term key is that I Simo> want to be able to extract the CAMMAC and verify it Simo> independently. A session key binds it to the ticket and that Simo> would require to expose the session key if the internal Simo> validation service is separate from the receiving service. I want to strongly discourage extracting the CAMAC from the ticket. Authorization validation should take the ap-req AD restrictions and all AD into account. This is particularly true in the GSS context where you're trying to construct a name with all the appropriate name attributes. _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg