Re: KDC model and atomicity

Leif Johansson <[email protected]> Mon, 11 Jun 2012 00:08:36 +0200
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 06/10/2012 10:25 PM, Greg Hudson wrote:
> I agree that N-strikes lockout, implemented through counters in the
> KDB, is not the final word on how one should respond to a
> password-guessing attack, and we don't want to carve it in stone.
> 
> The simplest, and possibly best, thing to say about lockout in the 
> information model is nothing.  Of course, that doesn't help us get
> to the point of interoperating on administrative operations related
> to lockout (policy-setting and administrative unlock)--but that can
> always be the subject of future revisions to the model (or schema,
> or admin protocol).

Well I think Nicos point was that you can't even implement the attribute
in question wo transactions across all KDCs in a realm.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk/VGt8ACgkQ8Jx8FtbMZndLUwCgsYchfcTCGqByuC1PNcQusqqv
uLwAmQH8Mija+L9vCLVSuFkcMFcPYveK
=iCSC
-----END PGP SIGNATURE-----
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg