Re: Miscellaneous CAMMAC issues
Nico Williams <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <CAK3OfOg0U--0+4vBjiFQQ2kHqs+u3EF4=+vTeoOtH_5GAVAhPw@mail.gmail.com> |
On Wed, Feb 15, 2012 at 4:15 PM, Sam Hartman <[email protected]> wrote: >>>>>> "Simo" == Simo Sorce <[email protected]> writes: > Simo> The reason why I proposed to use the long term key is that I > Simo> want to be able to extract the CAMMAC and verify it > Simo> independently. A session key binds it to the ticket and that > Simo> would require to expose the session key if the internal > Simo> validation service is separate from the receiving service. > > I want to strongly discourage extracting the CAMAC from the ticket. > Authorization validation should take the ap-req AD restrictions and all > AD into account. This is particularly true in the GSS context where > you're trying to construct a name with all the appropriate name > attributes. I agree. The PAD will likely be the dominant item in terms of data size, so if size is the issue, then I don't see the issue. The other possible issue (that I can think of) driving Simo to pass around a PAD sans Ticket would be mechanism-independence. If this is the case then what I recommend is that Simo use GSS exported composite name tokens to pass around the PAD. This makes it possible to use the PAD without being too bound to Kerberos. Or if that is not feasible for whatever reason then I recommend that Simo pass around {PAD, <mechanism-specific validation data>}, where the latter item is the remainder of the Ticket in the Kerberos case. Nico -- _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg