Re: AD review of draft-ietf-krb-wg-kerberos-referrals-14
Nico Williams <[email protected]> Fri, 14 Sep 2012 11:43:58 -0500
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <CAK3OfOjJu0_nMN3tqXY_V34daC3iPraW_5oR9bkV5=fB_AN4xg@mail.gmail.com> |
On Fri, Sep 14, 2012 at 11:15 AM, Sam Hartman <[email protected]> wrote: > Stephen> - p10, last para, maybe s/should/ought/ if you don't want > Stephen> that as a 2119 should? Even without that being a SHOULD, it > Stephen> seems odd to recommend that the client know about realms, > Stephen> to the extent that it can differentiate between them, in a > Stephen> spec whose purpose is to get rid of per-realm configuration > Stephen> from clients. Is there in fact a missing 2119-level SHOULD > Stephen> here that also says how to do this with no client config? > Stephen> Or, are you really assuming that clients won't make any > Stephen> checks, in which case wouldn't it be better to confess the > Stephen> truth? > > What a lot of clients end up doing is confirming that the referred-to > realm is in something like an AD forest. > It would be valuable to mention that as an option for the local policy. > It's actually not a bad choice in a lot of environments, although > obviously if the trust within a forest varies widely (something that > Kerberos supports but AD doesn't support as much) > then you might need to be more clever. Actually, AD does support varying levels of trust within forests. An AD client could search the AD configuration partition to decide whether some realm is trusted or not, but this is hard work. Also, a forest is not / need not be strictly hierarchical, so it can be really hard for a client to make this check. > The intent of that paragraph if is that if you're going outside of an > AD-style trust model you may need to prompt. Then it seems like we need an RFC2119 SHOULD. Nico -- _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg