[saag] Re: SKEX bof comment
"Salz, Rich" <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <MN2PR17MB39018F14C4BC9B171A140764CDDF2@MN2PR17MB3901.namprd17.prod.outlook.com> |
I am saying #2. I am inclined to think that making public-key work better with Kerberos is harder to do and deploy than a brand new thing. On 3/17/25, 2:11 PM, "Michael Richardson" <[email protected]> wrote: Salz, Rich <[email protected] <mailto:[email protected]>> wrote: mcr> A problem with Kerberos is that the KDC knows all the keys! > It does not have to. Kerberos has the concept of cross-realm > authentication. I don't quite understand you. I think you are saying two things, which I didn't think are related. 1. Are you saying that it is possible to use Kerberos in a way where the KDC doesn't (never!) knows what keys it is wrapping into the tickets? (Of course, it can forget them the moment they are wrapped up into tickets, sent to the two participants) 2. yes, you can have cross-realm authentication, where two KDCs talk to each other. I know that they was more common in the past, but I'm not convinced that it's used that often. pk-init.. RFC4556 describes a way to initialize this using public keys... otherwise, I think one has to use sneakernet. I see SKEX as being that sneakernet. I have no idea how often cross-realm authenticaiton is actually set in these modern days of Kerberos is almost always Active Directory. I've configured KDCs myself in the very distant past, and used it as a "user" in the past decade. -- Michael Richardson <[email protected] <mailto:[email protected]>>, Sandelman Software Works -= IPv6 IoT consulting =- *I*LIKE*TRAINS* _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]
smime.p7s
(application/x-pkcs7-signature, 4.6 KB) - not displayed