Usability of Renewable Tickets
Jeffrey Altman <[email protected]> Tue, 21 Aug 2012 13:32:57 -0400
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Organization | Secure Endpoints Inc. |
| Message-ID | <[email protected]> |
In recent days it has come to my attention that various client libraries and KDCs imposes a variety of constraints on the use of renewable tickets which restrict their usability. Especially in cross-vendor deployments. Heimdal 1.5.x and earlier clients for example cannot request a renewable service ticket. Only initial TGTs can be renewable. Windows Server 2003 will issue renewable and forwardable TGTs and service tickets but will not renew anything other than an initial TGT. MIT's client libraries only permit renewals of TGTs. Attempts to renew service tickets result in a mismatched server name and ticket being sent to the KDC. It would be useful as guidance to implementers for this working group to come to a consensus on: * which ticket types should be renewable * which ticket types should be renewed by the KDC * the interactions of the renewable flag and other ticket flags * the use of RENEWABLE_OK by clients It is my hope that such guidance when implemented (and preferably backported by vendors) could quickly raise the level of interoperability and the usability of renewable Kerberos credentials. Jeffrey Altman _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
signature.asc
(application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (MingW32) iQEcBAEBAgAGBQJQM8ZLAAoJENxm1CNJffh4Z0kIAKRKVMUMytER8BBAQGm9WH5G xl0sfJXoW0ZYQxsz+cFKQfOuNGvD3wNuhsOfWhwITsAuKiYgKYfCn52eQtJV3ef8 Vt6HPJ5eAXiGf6I5MRiHwhHB32qN7HG+ald9SbBD+REt2Drgy+n2Jy2hCOKxHZ69 y/S2ZTo5/4k8FcXc3v36tW265xmrDynOyA8a806TjVa6Va7qAsYBYoEzK3GUY0uF pEZ6ReWZFwYNRbwIqIH31aRKjcD5igfdYnXCliJbgoL+QzazvUwLT2HfKuWO+U0S 3KpNn4qjSGLqAutdBhnFkljr6XY+foB9ozteWd9UjJer+RE3hwWX2WKkhc+bxfg= =BLld -----END PGP SIGNATURE-----