FW: AUTH48 [SG]: RFC 6560 <draft-ietf-krb-wg-otp-preauth-21.txt> NOW AVAILABLE
<[email protected]> Mon, 12 Mar 2012 09:10:28 -0400
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
The following issue was raised during the RFC editor review of draft-ietf-krb-wg-otp-preauth
> 12) Appendix B.3: We are having trouble parsing the following
> sentence. Please review and let us know how/if it may be updated.
>
> 7. The client uses the ticket requests a ticket for a PIN change
> service and changes the user's PIN.
>
>
Originally, the KDC response was going to contain a ticket to the PIN change service rather than the requested TGT but this was changed to be modeled on the system used for password change with KDC_ERR_PIN_EXPIRED being returned instead of KDC_ERR_KEY_EXPIRED. However, it looks as if the text in Appendix B.3 was not updated correctly. The current step 3 should have been removed and step 7 was only partially updated.
I therefore proposed that the steps in B.3 be updated as follows:
1. The client constructs and sends a PA-OTP-REQUEST to the KDC as
described in the previous examples.
2. The KDC validates the pre-authentication data and authenticates
the user as in the previous examples but determines that the
user's PIN has expired.
3. The KDC constructs a PA-OTP-PIN-CHANGE as follows:
flags
0
minLength
4
maxLength
8
4. The KDC encrypts the PA-OTP-PIN-CHANGE within the enc-fast-rep of a
PA-FX-FAST-REPLY.
5. The KDC returns a KRB-ERROR to the client of type KDC_ERR_PIN_EXPIRED
with padata containing the PA-FX-FAST-REPLY.
6. The client authenticates to the PIN change
service and changes the user's PIN.
7. The client sends a second AS-REQ to the KDC containing a PA-OTP-
REQUEST constructed using the new PIN.
8. The KDC responds with an AS-REP containing a TGT.
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg