Re: KDC model and atomicity
Greg Hudson <[email protected]> Sun, 10 Jun 2012 16:25:43 -0400
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
I agree that N-strikes lockout, implemented through counters in the KDB, is not the final word on how one should respond to a password-guessing attack, and we don't want to carve it in stone. The simplest, and possibly best, thing to say about lockout in the information model is nothing. Of course, that doesn't help us get to the point of interoperating on administrative operations related to lockout (policy-setting and administrative unlock)--but that can always be the subject of future revisions to the model (or schema, or admin protocol). _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg