[19403] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Implementing a KDB plugin

daemon@ATHENA.MIT.EDU (Rick van Rein)
Fri May 6 04:34:52 2016

Message-ID: <572C5716.9060307@openfortress.nl>
Date: Fri, 06 May 2016 10:34:30 +0200
From: Rick van Rein <rick@openfortress.nl>
MIME-Version: 1.0
To: harsh savla <harsh.savla@gmail.com>
In-Reply-To: <CACbP_Kb0qdbxUcD4BF0braRUqEbMaU7-kaAUYApgsQE539YuEw@mail.gmail.com>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

Hello Harsh,

> I have a use case where I need to authenticate Kerberos principals against
> a RESTful Cloud service. This service can talk to an Active Directory(AD)
> which maintains the users passwords. On the client side we have a Linux
> based VM which runs the MIT Kerberos server. It has also Samba running.
>
Please note that I am drafting an integration method for Kerberos +
Diffie-Hellman
into TLS, known als TLS-KDH.  I think most questionable parts are gone
nowadays,
and we are implementing this for a client and server side.  This work is
scheduled
for delivery on July 1st.

http://tls-kdh.arpa2.net
https://tools.ietf.org/html/draft-vanrein-tls-kdh

What you seem to want (KRB --> REST --> KRB if I understand correctly) would
easily run into timeouts of Kerberos clients which may be as low as 1 second
and are not generally user-tunable.  I bet you said HTTP and meant HTTPS,
which would aggravate the chances of a timeout.

-Rick
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post