Re: Add. comments on Kdc model, WAS[Re: I-D Action: draft-ietf-krb-wg-kdc-model-12.txt]

Sam Hartman <[email protected]> Mon, 04 Jun 2012 09:20:33 -0400
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
>>>>> "Simo" == Simo Sorce <[email protected]> writes:


    >> > However assuming that this scheme is really preferred, then I do
    >> > not understand how it can be implemented if 4.1.1.5 says that the
    >> > counter should not be reset. I think implementations need to reset
    >> > it when a successful authentication happens. I think that should be
    >> > explicitly said, rather than a blanket 'SHOULD NOT reset'.
    >> > 
    >> 
    >> This was discussed in the WG. I don't think we should go back on that
    >> decision wo clear consensus.

    Simo> Point is, I am trying to understand what that paragraph means. As is
    Simo> written I can't see how to implement something that works and respects
    Simo> the letter of the document, feel free to explain to me what I am reading
    Simo> wrong.

I'd like to ask the WG whether we want to support lockouts depending on
how many failed authentications there have been since last successful
authentication.

I cannot think of a way to implement that consistent with the current
text.
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg