[saag] Re: [skex] SKEX bof comment
Daniel Shiu <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <LO0P265MB3065A356EE0B3975615F11BA97DE2@LO0P265MB3065.GBRP265.PROD.OUTLOOK.COM> |
Hi Rich, Thanks for the interest. If I were to SKEX-ify Kerberos, there would be a number of things that I'd like to do. I don't think of any of these as die-in-a-ditch, but improvements that I'd like to introduce if possible. * Merge the functions of Authentication Server and Ticket Granting Server rather than have each user enrol with two services. This would also reduce round trips. * Get better authentication properties for the "Receiver" (Service Server in Kerberos speak). Things that are higher up Lowe's hierarchy. * Combination of key transportation and distribution so that parties are contriubting to the agreed key and have personal assurance of injectivity * Key integrity * Perhaps some level of forward security from credential ratcheting * Perhaps more explicit methods for splitting trust I reserve the right to think of additional desiderata. Best regards, Daniel ________________________________ From: Salz, Rich <[email protected]> Sent: Monday, March 17, 2025 03:16 To: Daniel Shiu <[email protected]>; Stephen Farrell <[email protected]>; [email protected] <[email protected]>; [email protected] <[email protected]> Subject: Re: [skex] SKEX bof comment Overall, I'd like to see something that could be more naturally fit to peer-to-peer, is more efficient, and has improved security properties. This is not to mention the separate question of the best way to do unmediated key refreshment. None of this is meant to detract from Kerberos. It would be very helpful if you could explain what is missing from Kerberos. For example, do you want to make sure that you get the same key for A/B communication no matter who asks first? CAUTION: External Sender. This email originated from outside of Arqit. Do not click links or open attachments unless you recognize the sender and know the content is safe. CONFIDENTIALITY NOTICE: This e-mail message and any attachments are only for the use of the intended recipient and may contain information that is privileged, confidential or exempt from disclosure under applicable law. If you are not the intended recipient, any disclosure, distribution or other use of this e-mail message or attachments is prohibited. If you have received this e-mail message in error, please delete and notify the sender immediately. Thank you. _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]