Re: Add. comments on Kdc model, WAS[Re: I-D Action: draft-ietf-krb-wg-kdc-model-12.txt]
Sam Hartman <[email protected]> Mon, 04 Jun 2012 09:20:33 -0400
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
>>>>> "Simo" == Simo Sorce <[email protected]> writes: >> > However assuming that this scheme is really preferred, then I do >> > not understand how it can be implemented if 4.1.1.5 says that the >> > counter should not be reset. I think implementations need to reset >> > it when a successful authentication happens. I think that should be >> > explicitly said, rather than a blanket 'SHOULD NOT reset'. >> > >> >> This was discussed in the WG. I don't think we should go back on that >> decision wo clear consensus. Simo> Point is, I am trying to understand what that paragraph means. As is Simo> written I can't see how to implement something that works and respects Simo> the letter of the document, feel free to explain to me what I am reading Simo> wrong. I'd like to ask the WG whether we want to support lockouts depending on how many failed authentications there have been since last successful authentication. I cannot think of a way to implement that consistent with the current text. _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg