Re: Miscellaneous CAMMAC issues
Simo Sorce <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Organization | Red Hat, Inc. |
| Message-ID | <[email protected]> |
On Wed, 2012-02-15 at 17:15 -0500, Sam Hartman wrote: > >>>>> "Simo" == Simo Sorce <[email protected]> writes: > > > Simo> The reason why I proposed to use the long term key is that I > Simo> want to be able to extract the CAMMAC and verify it > Simo> independently. A session key binds it to the ticket and that > Simo> would require to expose the session key if the internal > Simo> validation service is separate from the receiving service. > > I want to strongly discourage extracting the CAMAC from the ticket. > Authorization validation should take the ap-req AD restrictions and all > AD into account. This is particularly true in the GSS context where > you're trying to construct a name with all the appropriate name > attributes. Can you explain why you want to discourage that ? Simo. -- Simo Sorce * Red Hat, Inc * New York _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg