Re: KDC model and atomicity
Jeffrey Hutzelman <[email protected]> Wed, 13 Jun 2012 19:41:40 -0400
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 2012-06-13 at 17:43 -0500, Nico Williams wrote: > We do not need to manage the count of failed authentication attempts. > That's an implementation detail. We may need to observe it. > > Given that I think it'd be good to leave this attribute in place but > describe it as read-only. Right. However, note that the present attribute as described may not be the one that a KDC can provide, depending on how its policy works. I'd suggest three attributes: - failed auths since last successful auth - failed auths since last key/pw change - failed auths since "forever" ... where "forever" does not necessarily extend past deleting and recreating the principal, or administratively resetting the counter, or whatever. All three attributes should be both read-only and optional, with the expectation that most KDCs will implement at most one. Same deal with timestamp of last successful/unsuccessful/attempt. > We need to describe how to unlock a principal though. Yup. For this I'd suggest a boolean attribute indicating the principal is locked out, which MAY be write-only, and in fact MAY support only writing a value of "false". -- Jeff _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg