Re: KDC model and atomicity

Greg Hudson <[email protected]> Tue, 26 Jun 2012 12:12:55 -0400
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
On 06/26/2012 11:32 AM, Nico Williams wrote:
> On Tue, Jun 26, 2012 at 9:51 AM, Greg Hudson <[email protected]> wrote:
>> On 06/26/2012 06:57 AM, Sam Hartman wrote:
>>> Mark 4.1.1.5 through 4.1.1.8 as OPTIONAL.
>>
>> I would rather remove them than have text which we expect most people to
>> ignore.  But if there isn't consensus for that, I'm minimally okay with
>> marking them as optional.
> 
> What text would get ignored?

I expect 4.1.1.5 in its current form wouldn't be interesting to any
schema or KDC implementations.  I expect 4.1.1.6 and 4.1.1.7 to be
ignored by any schema or implementation not trying to do AD-style
n-strikes lockout.

(I'm not sure why Sam included 4.1.1.8 in his proposal.  Last key change
time seems unrelated to lockout.)

If we think a schema document is likely to include attributes designed
to allow n-strikes lockout, then we should modify 4.1.1.5 (perhaps just
removing the last sentence) and leave in 4.1.1.6 and 4.1.1.7.  But the
recent conversation suggests that we are not especially likely to do
that, in which case the text of 4.1.1.5-7 serves no purpose.
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg