Re: AD review of draft-ietf-krb-wg-kerberos-referrals-14
Nico Williams <[email protected]> Fri, 14 Sep 2012 13:48:20 -0500
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <CAK3OfOjzMxjLEH0dbtgPDudamM9hpDGV8hgEha=taMP1dQmi=w@mail.gmail.com> |
On Fri, Sep 14, 2012 at 1:08 PM, Sam Hartman <[email protected]> wrote: > Nico> Actually, AD does support varying levels of trust within > Nico> forests. An AD client could search the AD configuration > Nico> partition to decide whether some realm is trusted or not, but > Nico> this is hard work. > > Sorry, clients accept the referral if they can get their own host ticket > and verify it. Sure. I think we both meant to say different things. AD can represent less than full trust between all realms in a forest, but clients accept referrals to anywhere within the forest. Clients check nothing more than the referred-to realm being within the forest -- the KDC could not have issued the ticket if the referred-to realm did not trust the client's realm and that's that. Yes? > >> The intent of that paragraph if is that if you're going outside > >> of an AD-style trust model you may need to prompt. > > Nico> Then it seems like we need an RFC2119 SHOULD. > > We're debating whether the SHOULD can be implemented. > > As stated, you should check policy. I personally think you eventually > get to a point where you have to check by asking the user, but I > certainly don't want to SHOULD that specific way of checking. If you > find something environment-specific that works better, that's great. OK, I see. Prompting is hard because of the interfaces involved... Nico -- _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg