Re: Miscellaneous CAMMAC issues

Sam Hartman <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
>>>>> "Simo" == Simo Sorce <[email protected]> writes:


    Simo> The reason why I proposed to use the long term key is that I
    Simo> want to be able to extract the CAMMAC and verify it
    Simo> independently. A session key binds it to the ticket and that
    Simo> would require to expose the session key if the internal
    Simo> validation service is separate from the receiving service.

I want to strongly discourage extracting the CAMAC from the ticket.
Authorization validation should take the ap-req AD restrictions and all
AD into account.  This is particularly true in the GSS context where
you're trying to construct a name with all the appropriate name
attributes.
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.