Re: The usability of service ticket lifetimes

Jeffrey Altman <[email protected]> Tue, 21 Aug 2012 16:33:23 -0400
Newsgroups gmane.ietf.krb-wg
Organization Secure Endpoints Inc.
Message-ID <[email protected]>
On 8/21/2012 2:49 PM, Jeffrey Hutzelman wrote:
> On Tue, 2012-08-21 at 13:21 -0400, Jeffrey Altman wrote:
> 
>> The purpose of the endtime being shorter than the renew_till time is to
>> force the client to contact the Ticket Granting Service within the
>> required "lifetime" to permit the TGS to block continued use of the
>> tickets in case one of the principals has been deactivated.
> 
> No, that's not the only purpose.  It also gives operational control
> over the maximum time before a policy change has fully gone into
> effect.  Such policies may affect the issuing and/or renewing of both
> TGTs and service tickets, and may not be as simple as a particular
> client principal being enabled or not.  For example, I may need an
> upper bound on when an enctype policy change has become fully
> effective, or a policy change relating to authorization data included
> in issued tickets.
> 
> As an operator, I'd be nervous about replacing a relatively simple,
> easily-understood rule (a policy change is in effect by the time any
> TGT issued prior to it has expired) with one involving complex
> interactions between all of the services a user might have used.

The rule would become

  A policy is in effect by the time any ticket issued prior to it
  has expired.

Your rule assumes that policy changes are enforced upon TGT renewals and
my rule assumes that policy changes are enforced upon all ticket
renewals.  I hope that policy changes are enforced during the issuance
of all tickets and not just TGTs.

_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
signature.asc (application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)

iQEcBAEBAgAGBQJQM/CWAAoJENxm1CNJffh4tOAIAJAHrkNIlGExFDalMNpAOBJK
Jd8eaHz3ha/+Lu+nLol/Sy+5q9t/jYqkWw/ORvOgPfdfSPr35hg3hgpLl5/RALpP
BYc4tjyYfRfmujvH9J2w+9jMCcS8D2MrR2DHBKTLfyVDsMueGgPd7dNPrhLCSpXK
GWwKyby+YW/f48NLUSrss3ZYMGAWmUVVM+nAVN8XG3ixU62KvpeVdkhmMSn5IDKH
WRcD00J2PJvFNqP3oOxqzKDL9tnqCDkei/W8wQAnnCEzX9nUz58phfqs8lLLfiUc
IW7n8ppCp5TwdE/Nq1uNNcimMjMl0JkWziR0zeggQzSc3LJ1A0S+w729lAs+XuE=
=L9ez
-----END PGP SIGNATURE-----