Re: KDC model and atomicity

Jeffrey Hutzelman <[email protected]> Wed, 13 Jun 2012 19:41:40 -0400
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
On Wed, 2012-06-13 at 17:43 -0500, Nico Williams wrote:

> We do not need to manage the count of failed authentication attempts.
> That's an implementation detail.  We may need to observe it.
> 
> Given that I think it'd be good to leave this attribute in place but
> describe it as read-only.

Right.  However, note that the present attribute as described may not be
the one that a KDC can provide, depending on how its policy works.  I'd
suggest three attributes:

- failed auths since last successful auth
- failed auths since last key/pw change
- failed auths since "forever"

... where "forever" does not necessarily extend past deleting and
recreating the principal, or administratively resetting the counter, or
whatever.

All three attributes should be both read-only and optional, with the
expectation that most KDCs will implement at most one.

Same deal with timestamp of last successful/unsuccessful/attempt.



> We need to describe how to unlock a principal though.

Yup.  For this I'd suggest a boolean attribute indicating the principal
is locked out, which MAY be write-only, and in fact MAY support only
writing a value of "false".

-- Jeff

_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg