Re: Miscellaneous CAMMAC issues

Simo Sorce <[email protected]>
Newsgroups gmane.ietf.krb-wg
Organization Red Hat, Inc.
Message-ID <[email protected]>
On Wed, 2012-02-15 at 17:15 -0500, Sam Hartman wrote:
> >>>>> "Simo" == Simo Sorce <[email protected]> writes:
> 
> 
>     Simo> The reason why I proposed to use the long term key is that I
>     Simo> want to be able to extract the CAMMAC and verify it
>     Simo> independently. A session key binds it to the ticket and that
>     Simo> would require to expose the session key if the internal
>     Simo> validation service is separate from the receiving service.
> 
> I want to strongly discourage extracting the CAMAC from the ticket.
> Authorization validation should take the ap-req AD restrictions and all
> AD into account.  This is particularly true in the GSS context where
> you're trying to construct a name with all the appropriate name
> attributes.

Can you explain why you want to discourage that ?

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York

_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.