Re: AD review of draft-ietf-krb-wg-kerberos-referrals-14
Sam Hartman <[email protected]> Fri, 14 Sep 2012 15:18:39 -0400
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
>>>>> "Nico" == Nico Williams <[email protected]> writes: Nico> On Fri, Sep 14, 2012 at 1:08 PM, Sam Hartman <[email protected]> wrote: Nico> Actually, AD does support varying levels of trust within Nico> forests. An AD client could search the AD configuration Nico> partition to decide whether some realm is trusted or not, but Nico> this is hard work. >> >> Sorry, clients accept the referral if they can get their own host >> ticket and verify it. Nico> Sure. I think we both meant to say different things. AD can Nico> represent less than full trust between all realms in a forest, Nico> but clients accept referrals to anywhere within the forest. Nico> Clients check nothing more than the referred-to realm being Nico> within the forest -- the KDC could not have issued the ticket Nico> if the referred-to realm did not trust the client's realm and Nico> that's that. Yes? Since a forest can have one-way trusts I think it means more than within forest. But I think we're well beyond what's needed for this discussion. _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg