Re: The usability of service ticket lifetimes

Jeffrey Hutzelman <[email protected]> Tue, 21 Aug 2012 21:35:32 -0400
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
On Tue, 2012-08-21 at 15:22 -0700, Henry B. Hotz wrote:
> On Aug 21, 2012, at 3:09 PM, Nico Williams wrote:
> 
> > On Tue, Aug 21, 2012 at 12:21 PM, Jeffrey Altman
> > <[email protected]> wrote:
> >> As part of any revision to RFC 4120, I would like to see this section
> >> modified.
> > 
> > Note that some client libraries check that the KDC does not exceed the
> > limits you quoted.  That means that relaxing them will require a KDC
> > options flag in the request...  And it should only be used in KDC-REQs
> > where the body of the request is protected (e.g., TGS-REQs and AS-REQs
> > in a FAST tunnel).
> > 
> > Nico
> 
> IMO it's inappropriate (as in: a *bug*) for a client to unconditionally
>  enforce limits which are the KDCs responsibility to enforce.  If
>  nothing else, it makes it hard to support edge cases which may violate
>  some letters of the limits, but not the intent or the policy.  (I
>  suppose I'm a bit twitchy due to a PKINIT issue I ran into recently.)

Actually, no.  The protocol contains fields to allow a client to place
limits on the lifetime and renew lifetime of tickets it requests, and
the spec requires the KDC to obey those limits.  As a check that these
fields have not been modified in transit, it is reasonable for a client
to verify that the requested limits have not been exceeded.

There is a mechanism for a client to indicate the KDC should use the
maximum lifetime permitted by policy; when this is used, clients should
not expect any particular values back.

-- Jeff

_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg