[saag] Re: SKEX bof comment

"Salz, Rich" <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <MN2PR17MB39018F14C4BC9B171A140764CDDF2@MN2PR17MB3901.namprd17.prod.outlook.com>
I am saying #2. 

I am inclined to think that making public-key work better with Kerberos is harder to do and deploy than a brand new thing. 

On 3/17/25, 2:11 PM, "Michael Richardson" <[email protected]> wrote: 


Salz, Rich <[email protected] <mailto:[email protected]>> wrote: 

mcr> A problem with Kerberos is that the KDC knows all the keys! 



> It does not have to. Kerberos has the concept of cross-realm 

> authentication. 



I don't quite understand you. 



I think you are saying two things, which I didn't think are related. 



1. Are you saying that it is possible to use Kerberos in a way where the KDC 

doesn't (never!) knows what keys it is wrapping into the tickets? 

(Of course, it can forget them the moment they are wrapped up into 

tickets, sent to the two participants) 



2. yes, you can have cross-realm authentication, where two KDCs talk to each 

other. I know that they was more common in the past, but I'm not 

convinced that it's used that often. pk-init.. RFC4556 describes a way to 

initialize this using public keys... otherwise, I think one has to use 

sneakernet. I see SKEX as being that sneakernet. 





I have no idea how often cross-realm authenticaiton is actually set in these 

modern days of Kerberos is almost always Active Directory. I've configured 

KDCs myself in the very distant past, and used it as a "user" in the past decade. 



-- 

Michael Richardson <[email protected] <mailto:[email protected]>>, Sandelman Software Works 

-= IPv6 IoT consulting =- *I*LIKE*TRAINS*

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s (application/x-pkcs7-signature, 4.6 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.