Re: Add. comments on Kdc model, WAS[Re: I-D Action: draft-ietf-krb-wg-kdc-model-12.txt]

Sam Hartman <[email protected]> Tue, 05 Jun 2012 10:32:14 -0400
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
>>>>> "Nico" == Nico Williams <[email protected]> writes:

    Nico> On Mon, Jun 4, 2012 at 2:20 PM, Greg Hudson <[email protected]> wrote:
    >> On 06/04/2012 09:20 AM, Sam Hartman wrote:
    >>> I'd like to ask the WG whether we want to support lockouts depending on
    >>> how many failed authentications there have been since last successful
    >>> authentication.
    >> 
    >> MIT krb5 does this and Active Directory does this (I believe), so yes, I
    >> think it's important to support that if we're going to be talking about
    >> lockout counters in the information model.

    Nico> But it's not exact.  At least not for AD and not for MIT with a db2 backend.

Nico, I'm confused because I'd like to interpret your message in the
context of whether the information model should support lockouts based
on number of successful authentications, but I cannot understand how to
do so. You may be saying that it's OK because the current model supports
an in-exact form of this.
I don't think it does though.
I think  that the current model doesn't support this in any form.

Alternatively you may be saying that since the feature is in-exact in
existing implementations we should not support it.

Would you be willing to clarify what you are proposing with regard to
whether the information model needs to support this form of lockout?
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg