Re: AD review of draft-ietf-krb-wg-kerberos-referrals-14

Sam Hartman <[email protected]> Fri, 14 Sep 2012 15:18:39 -0400
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
>>>>> "Nico" == Nico Williams <[email protected]> writes:

    Nico> On Fri, Sep 14, 2012 at 1:08 PM, Sam Hartman <[email protected]> wrote:
    Nico> Actually, AD does support varying levels of trust within
    Nico> forests.  An AD client could search the AD configuration
    Nico> partition to decide whether some realm is trusted or not, but
    Nico> this is hard work.
    >> 
    >> Sorry, clients accept the referral if they can get their own host
    >> ticket and verify it.

    Nico> Sure.  I think we both meant to say different things.  AD can
    Nico> represent less than full trust between all realms in a forest,
    Nico> but clients accept referrals to anywhere within the forest.
    Nico> Clients check nothing more than the referred-to realm being
    Nico> within the forest -- the KDC could not have issued the ticket
    Nico> if the referred-to realm did not trust the client's realm and
    Nico> that's that.  Yes?

Since a forest can have one-way trusts I think it means more than within
forest.
But I think we're well beyond what's needed for this discussion.
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg