Re: AD review of draft-ietf-krb-wg-kerberos-referrals-14

Sam Hartman <[email protected]> Fri, 14 Sep 2012 14:08:03 -0400
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
>>>>> "Nico" == Nico Williams <[email protected]> writes:

    Nico> On Fri, Sep 14, 2012 at 11:15 AM, Sam Hartman <[email protected]> wrote:
    Stephen> - p10, last para, maybe s/should/ought/ if you don't want
    Stephen> that as a 2119 should? Even without that being a SHOULD, it
    Stephen> seems odd to recommend that the client know about realms,
    Stephen> to the extent that it can differentiate between them, in a
    Stephen> spec whose purpose is to get rid of per-realm configuration
    Stephen> from clients. Is there in fact a missing 2119-level SHOULD
    Stephen> here that also says how to do this with no client config?
    Stephen> Or, are you really assuming that clients won't make any
    Stephen> checks, in which case wouldn't it be better to confess the
    Stephen> truth?
    >> 
    >> What a lot of clients end up doing is confirming that the
    >> referred-to realm is in something like an AD forest.  It would be
    >> valuable to mention that as an option for the local policy.  It's
    >> actually not a bad choice in a lot of environments, although
    >> obviously if the trust within a forest varies widely (something
    >> that Kerberos supports but AD doesn't support as much) then you
    >> might need to be more clever.

    Nico> Actually, AD does support varying levels of trust within
    Nico> forests.  An AD client could search the AD configuration
    Nico> partition to decide whether some realm is trusted or not, but
    Nico> this is hard work.

Sorry, clients accept the referral if they can get their own host ticket
and verify it.
That's easy for a client to do and approximates what I said above
assuming their exists a trust from the user's realm to the host's realm.

My comment about AD not having as flexible a trust model as everything
supported by Kerberos involves more comments about GCs etc than that AD
doesn't do a good job for real-world situations of supporting multiple
trust levels.
    >> The intent of that paragraph if is that if you're going outside
    >> of an AD-style trust model you may need to prompt.

    Nico> Then it seems like we need an RFC2119 SHOULD.

We're debating whether the SHOULD can be implemented.

As stated, you should check policy.  I personally think you eventually
get to a point where you have to check by asking the user, but I
certainly don't want to SHOULD that specific way of checking.  If you
find something environment-specific that works better, that's great.
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg