Re: KDC model and atomicity

Nico Williams <[email protected]> Tue, 26 Jun 2012 10:32:20 -0500
Newsgroups gmane.ietf.krb-wg
Message-ID <CAK3OfOhF3j-iwwU-tSNEh_5mxRg6eZ_uuR=c_Bt23c+a2KSgTA@mail.gmail.com>
On Tue, Jun 26, 2012 at 9:51 AM, Greg Hudson <[email protected]> wrote:
> On 06/26/2012 06:57 AM, Sam Hartman wrote:
>> Mark 4.1.1.5 through 4.1.1.8 as OPTIONAL.
>
> I would rather remove them than have text which we expect most people to
> ignore.  But if there isn't consensus for that, I'm minimally okay with
> marking them as optional.

What text would get ignored?

>> * Add a note to 4.1.1.4 indicating that schemas MUST have a mechanism
>>   for re-enabling a principal that has been disabled through operational
>>   mechanisms such as account lock out.
>
> Do we need to be prescriptive about this here?  I don't understand this
> draft to be a general requirements document for an admin protocol.  If
> we still believe we want an unlock operation when we're writing a
> schema, we can put it in.
>
> At the moment I'm against this part.

This is a good point.  This document does not set out requirements for
an admin protocol.  Of course, it's possible to do quite a bit of
administration through just a schema (see, for example, Windows, and
also Heimdal's kadmin client, which can talk to AD via LDAP).  But
some operations are beyond the reach of a schema.  I'm willing to
consider principal unlock to be such an operation, but then I think
I'd really like to just remove all attributes related to failed
authentication attempts as those too imply more semantics than just
reading some data in a directory.

Nico
--
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg