Re: KDC model and atomicity

Greg Hudson <[email protected]> Sun, 10 Jun 2012 16:25:43 -0400
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
I agree that N-strikes lockout, implemented through counters in the KDB, 
is not the final word on how one should respond to a password-guessing 
attack, and we don't want to carve it in stone.

The simplest, and possibly best, thing to say about lockout in the 
information model is nothing.  Of course, that doesn't help us get to 
the point of interoperating on administrative operations related to 
lockout (policy-setting and administrative unlock)--but that can always 
be the subject of future revisions to the model (or schema, or admin 
protocol).

_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg