Usability of Renewable Tickets

Jeffrey Altman <[email protected]> Tue, 21 Aug 2012 13:32:57 -0400
Newsgroups gmane.ietf.krb-wg
Organization Secure Endpoints Inc.
Message-ID <[email protected]>
In recent days it has come to my attention that various client libraries
and KDCs imposes a variety of constraints on the use of renewable
tickets which restrict their usability.  Especially in cross-vendor
deployments.

Heimdal 1.5.x and earlier clients for example cannot request a renewable
service ticket.  Only initial TGTs can be renewable.

Windows Server 2003 will issue renewable and forwardable TGTs and
service tickets but will not renew anything other than an initial TGT.

MIT's client libraries only permit renewals of TGTs.  Attempts to renew
service tickets result in a mismatched server name and ticket being sent
to the KDC.

It would be useful as guidance to implementers for this working group to
come to a consensus on:

 * which ticket types should be renewable

 * which ticket types should be renewed by the KDC

 * the interactions of the renewable flag and other ticket flags

 * the use of RENEWABLE_OK by clients

It is my hope that such guidance when implemented (and preferably
backported by vendors) could quickly raise the level of interoperability
and the usability of renewable Kerberos credentials.

Jeffrey Altman

_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
signature.asc (application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)

iQEcBAEBAgAGBQJQM8ZLAAoJENxm1CNJffh4Z0kIAKRKVMUMytER8BBAQGm9WH5G
xl0sfJXoW0ZYQxsz+cFKQfOuNGvD3wNuhsOfWhwITsAuKiYgKYfCn52eQtJV3ef8
Vt6HPJ5eAXiGf6I5MRiHwhHB32qN7HG+ald9SbBD+REt2Drgy+n2Jy2hCOKxHZ69
y/S2ZTo5/4k8FcXc3v36tW265xmrDynOyA8a806TjVa6Va7qAsYBYoEzK3GUY0uF
pEZ6ReWZFwYNRbwIqIH31aRKjcD5igfdYnXCliJbgoL+QzazvUwLT2HfKuWO+U0S
3KpNn4qjSGLqAutdBhnFkljr6XY+foB9ozteWd9UjJer+RE3hwWX2WKkhc+bxfg=
=BLld
-----END PGP SIGNATURE-----