Re: The usability of service ticket lifetimes

"Henry B. Hotz" <[email protected]> Tue, 21 Aug 2012 20:10:26 -0700
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
On Aug 21, 2012, at 6:35 PM, Jeffrey Hutzelman wrote:

> On Tue, 2012-08-21 at 15:22 -0700, Henry B. Hotz wrote:
>> On Aug 21, 2012, at 3:09 PM, Nico Williams wrote:
>> 
>>> On Tue, Aug 21, 2012 at 12:21 PM, Jeffrey Altman
>>> <[email protected]> wrote:
>>>> As part of any revision to RFC 4120, I would like to see this section
>>>> modified.
>>> 
>>> Note that some client libraries check that the KDC does not exceed the
>>> limits you quoted.  That means that relaxing them will require a KDC
>>> options flag in the request...  And it should only be used in KDC-REQs
>>> where the body of the request is protected (e.g., TGS-REQs and AS-REQs
>>> in a FAST tunnel).
>>> 
>>> Nico
>> 
>> IMO it's inappropriate (as in: a *bug*) for a client to unconditionally
>> enforce limits which are the KDCs responsibility to enforce.  If
>> nothing else, it makes it hard to support edge cases which may violate
>> some letters of the limits, but not the intent or the policy.  (I
>> suppose I'm a bit twitchy due to a PKINIT issue I ran into recently.)
> 
> Actually, no.  The protocol contains fields to allow a client to place
> limits on the lifetime and renew lifetime of tickets it requests, and
> the spec requires the KDC to obey those limits.  As a check that these
> fields have not been modified in transit, it is reasonable for a client
> to verify that the requested limits have not been exceeded.

Oh, yeah. . .  I remember a bug in that check.  Not really what I was talking about though.

Or, actually, it is.  In both cases the client was erroneously failing because it was not leaving checks/modifications to the discretion of the KDC when it should have.

> There is a mechanism for a client to indicate the KDC should use the
> maximum lifetime permitted by policy; when this is used, clients should
> not expect any particular values back.
> 
> -- Jeff
> 

------------------------------------------------------
The opinions expressed in this message are mine,
not those of Caltech, JPL, NASA, or the US Government.
[email protected], or [email protected]

_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg