Re: AD review of draft-ietf-krb-wg-kerberos-referrals-14
Sam Hartman <[email protected]> Fri, 14 Sep 2012 12:15:57 -0400
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
>>>>> "Stephen" == Stephen Farrell <[email protected]> writes: Stephen> Hi all, Stephen> - p10, last para, maybe s/should/ought/ if you don't want Stephen> that as a 2119 should? Even without that being a SHOULD, it Stephen> seems odd to recommend that the client know about realms, Stephen> to the extent that it can differentiate between them, in a Stephen> spec whose purpose is to get rid of per-realm configuration Stephen> from clients. Is there in fact a missing 2119-level SHOULD Stephen> here that also says how to do this with no client config? Stephen> Or, are you really assuming that clients won't make any Stephen> checks, in which case wouldn't it be better to confess the Stephen> truth? What a lot of clients end up doing is confirming that the referred-to realm is in something like an AD forest. It would be valuable to mention that as an option for the local policy. It's actually not a bad choice in a lot of environments, although obviously if the trust within a forest varies widely (something that Kerberos supports but AD doesn't support as much) then you might need to be more clever. The intent of that paragraph if is that if you're going outside of an AD-style trust model you may need to prompt. Stephen> - If a KDC receives an AS-REQ with no PA-REQ-ENC-PA-REP or Stephen> canonicalize KDC option then I assume that KDC MUST behave Stephen> according to 4120. Is that stated explicitly somewhere? Stephen> Does there need to be any similar statement about TGS-REQs Stephen> or TGTs (since the new padata type is a MAY for TGS-REQs)? I don't think this is explicitly stated. It's true for AS and TGS. Will state in the post-lc update. IN practice the point is kind of moot since every implementation that seems to be in wide use implements canonicalize. This spec took a while in the standardization process:-) Stephen> nits: Will deal during post-lc update. _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg