Re: KDC model and atomicity
Leif Johansson <[email protected]> Mon, 11 Jun 2012 00:08:36 +0200
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 06/10/2012 10:25 PM, Greg Hudson wrote: > I agree that N-strikes lockout, implemented through counters in the > KDB, is not the final word on how one should respond to a > password-guessing attack, and we don't want to carve it in stone. > > The simplest, and possibly best, thing to say about lockout in the > information model is nothing. Of course, that doesn't help us get > to the point of interoperating on administrative operations related > to lockout (policy-setting and administrative unlock)--but that can > always be the subject of future revisions to the model (or schema, > or admin protocol). Well I think Nicos point was that you can't even implement the attribute in question wo transactions across all KDCs in a realm. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAk/VGt8ACgkQ8Jx8FtbMZndLUwCgsYchfcTCGqByuC1PNcQusqqv uLwAmQH8Mija+L9vCLVSuFkcMFcPYveK =iCSC -----END PGP SIGNATURE----- _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg