Re: AD review of draft-ietf-krb-wg-kerberos-referrals-14

Nico Williams <[email protected]> Fri, 14 Sep 2012 13:48:20 -0500
Newsgroups gmane.ietf.krb-wg
Message-ID <CAK3OfOjzMxjLEH0dbtgPDudamM9hpDGV8hgEha=taMP1dQmi=w@mail.gmail.com>
On Fri, Sep 14, 2012 at 1:08 PM, Sam Hartman <[email protected]> wrote:
>     Nico> Actually, AD does support varying levels of trust within
>     Nico> forests.  An AD client could search the AD configuration
>     Nico> partition to decide whether some realm is trusted or not, but
>     Nico> this is hard work.
>
> Sorry, clients accept the referral if they can get their own host ticket
> and verify it.

Sure.  I think we both meant to say different things.  AD can
represent less than full trust between all realms in a forest, but
clients accept referrals to anywhere within the forest.  Clients check
nothing more than the referred-to realm being within the forest -- the
KDC could not have issued the ticket if the referred-to realm did not
trust the client's realm and that's that.  Yes?

>     >> The intent of that paragraph if is that if you're going outside
>     >> of an AD-style trust model you may need to prompt.
>
>     Nico> Then it seems like we need an RFC2119 SHOULD.
>
> We're debating whether the SHOULD can be implemented.
>
> As stated, you should check policy.  I personally think you eventually
> get to a point where you have to check by asking the user, but I
> certainly don't want to SHOULD that specific way of checking.  If you
> find something environment-specific that works better, that's great.

OK, I see.  Prompting is hard because of the interfaces involved...

Nico
--
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg