[19449] in Kerberos_V5_Development
Re: Securing the keytabs of host-based principals
daemon@ATHENA.MIT.EDU (John Devitofranceschi)
Fri Jul 8 07:48:48 2016
Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))
From: John Devitofranceschi <jdvf@optonline.net>
In-Reply-To: <2124558.NBCL94HfaQ@perfluence.mit.edu>
Date: Fri, 8 Jul 2016 07:48:31 -0400
Message-Id: <797C2AB1-C84F-49A9-9A0B-66B6BDC39B76@optonline.net>
To: Sarah Day <sarahday@mit.edu>
Cc: krbdev@mit.edu, Simo Sorce <simo@redhat.com>
Content-Type: multipart/mixed; boundary="===============4050307418912570945=="
Errors-To: krbdev-bounces@mit.edu
--===============4050307418912570945==
Content-Type: multipart/signed;
boundary="Apple-Mail=_425D0802-DBB8-44FA-9773-D240C51874D5";
protocol="application/pkcs7-signature"; micalg=sha1
--Apple-Mail=_425D0802-DBB8-44FA-9773-D240C51874D5
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
charset=utf-8
> On Jul 7, 2016, at 1:14 PM, Sarah Day <sarahday@mit.edu> wrote:
>=20
> On Wednesday, July 6, 2016 9:03:28 AM EDT Simo Sorce wrote:
>> On Wed, 2016-07-06 at 07:25 -0400, John Devitofranceschi wrote:
>>> ...
>>> Would it be possible/desirable/sensible to have a new attribute (or =
flag)
>>> that designates a principal to be a host-based principal that =
follows
>>> standard conventions? When the KDC sees a ticket request from a =
principal
>>> with this attribute, an additional check will verify that the source
>>> address of the request maps to the fqdn in the principal.
>>>=20
>>> Additionally a kdc.conf variable could be defined that controls the
>>> behavior of this check when it fails: warn (the default) or deny.
>>>=20
>>> This would allow operators to (at least) easily detect if any =
keytabs are
>>> being used on hosts for which they were not intended.
>> Unless you plan to keep a hard copy of Name-IP pairs on the KDC you
>> would need DNSSEC to make this check useful, otherwise DNS spoofing =
can
>> be easily used to fool the check.
>> Also adding a DNS request before returning an AS Response will =
increase
>> the latency increase the chance clients will re-send the request or =
move
>> to another KDC and discard the request. Many clients have an =
aggressive
>> retry strategy that waits only 1 second for the first reply and then
>> slowly backs down.
>>=20
>> Simo.
>=20
> I still see value in something like this being implemented. It's still =
another=20
> layer of security that would have to be bypassed by an attacker. A =
keytab=20
> could be accidently leaked in many ways, and a DNS spoof attack isn't =
always=20
> incredibly easy.
>=20
> Including a warning log message should be relatively simple, but I do =
see=20
> multiple issues presenting themselves if it should actually fail if =
the=20
> hostname doesn't resolve correctly. I can add taking a look at how it =
performs=20
> to my list if you would like.
>=20
> --=20
> Sarah Day
> Identity & Access Management
> MIT | IS&T | Platform & Systems Integration
>=20
That would be great. If you do get some results/patches I would be happy =
to check/try them out.
At the risk of having this spiral out of control beyond all reason, =
perhaps when operators set the =E2=80=98hostbased=E2=80=99 flag on a =
principal they have the option of also setting providing the ip =
address(es) of the host which can then be stored in the principal entry. =
This takes care of Simo=E2=80=99s concerns while at the same time being =
optional for installations where these concerns are not material.
jd
--Apple-Mail=_425D0802-DBB8-44FA-9773-D240C51874D5
Content-Disposition: attachment;
filename=smime.p7s
Content-Type: application/pkcs7-signature;
name=smime.p7s
Content-Transfer-Encoding: base64
MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIF6DCCBeQw
ggPMoAMCAQICAxBgkDANBgkqhkiG9w0BAQ0FADB5MRAwDgYDVQQKEwdSb290IENBMR4wHAYDVQQL
ExVodHRwOi8vd3d3LmNhY2VydC5vcmcxIjAgBgNVBAMTGUNBIENlcnQgU2lnbmluZyBBdXRob3Jp
dHkxITAfBgkqhkiG9w0BCQEWEnN1cHBvcnRAY2FjZXJ0Lm9yZzAeFw0xNTAzMTQxNDM4MzlaFw0x
NzAzMTMxNDM4MzlaMIGFMR4wHAYDVQQDExVKb2huIERldml0b2ZyYW5jZXNjaGkxITAfBgkqhkiG
9w0BCQEWEmpkdmZAb3B0b25saW5lLm5ldDEfMB0GCSqGSIb3DQEJARYQamR2ZkBob3RtYWlsLmNv
bTEfMB0GCSqGSIb3DQEJARYQZm9vbm9uQGdtYWlsLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBAK4hgmTqZnFEjGB/yk+/J5guSzz71ZVuemKLvEmRvDznUHJ/o8+NqgdWc87WILzB
8cCgfvjR8gtCe555md2xYof9NrNuFShKfTpP5mvG/ny4RYn1uq6FVgY5qBgz+4UDzE3W1ZniRIT6
EruOeawVpsl03AmaSbQNPXZTpxr6BiIfdnhEexuxXdJX9ytMM2yf20U/L/hmIuu+ML9bvXdsJNHn
iytTxDxB4v1BaplLKnQIvr8nvP8MuaOSUDP6SrAOkXgLFG0lqB6YLSW66aj1i1YHkQDK95iO+X0C
3l7iLJvCiVnG/PTFNdu2mZrJ0KzVzI0SJwvH4v0qSMcc8WaQ55cCAwEAAaOCAWYwggFiMAwGA1Ud
EwEB/wQCMAAwVgYJYIZIAYb4QgENBEkWR1RvIGdldCB5b3VyIG93biBjZXJ0aWZpY2F0ZSBmb3Ig
RlJFRSBoZWFkIG92ZXIgdG8gaHR0cDovL3d3dy5DQWNlcnQub3JnMA4GA1UdDwEB/wQEAwIDqDBA
BgNVHSUEOTA3BggrBgEFBQcDBAYIKwYBBQUHAwIGCisGAQQBgjcKAwQGCisGAQQBgjcKAwMGCWCG
SAGG+EIEATAyBggrBgEFBQcBAQQmMCQwIgYIKwYBBQUHMAGGFmh0dHA6Ly9vY3NwLmNhY2VydC5v
cmcwMQYDVR0fBCowKDAmoCSgIoYgaHR0cDovL2NybC5jYWNlcnQub3JnL3Jldm9rZS5jcmwwQQYD
VR0RBDowOIESamR2ZkBvcHRvbmxpbmUubmV0gRBqZHZmQGhvdG1haWwuY29tgRBmb29ub25AZ21h
aWwuY29tMA0GCSqGSIb3DQEBDQUAA4ICAQCqiwk6dIVSS4Q7t3vXmhNrORxhHD2R44a2h8wd43+P
x19y59yZe9Jio4N7gFTJ2QLrxE6hDbBlJBZ7EgVLfDVqBWVGt2nvERDrCtzPr/uze2KmPEA1Smpk
sLAuWp2gDUKflWNL2NLInGCsuqdYkfqxCB1Kc+ws6DhZtHt83SjktGodh66pBTRrpfDSUEsY/3VR
q+kgjjQyNIYWyi2rsJQ7gP/e8YfGJC43TYwpfpcRM/rKwanUVgSMVwhSow9cQ3m3HYGyHB3+7WcV
orsP9u1I57FXyIHMKWmjmLNizzhVY05pM2Cd/T/7PS3ZNig53kclY4hx/XwRPjY3aHahhZacNKh+
96ImmxgJljJfQkc9avy7zZnsAb4neUUiYOacS1y5wPhGzIYor5gy6nQYT2g/nE6bAsaljNJICHWD
TwUuQqYUq39eN5RUGSxUVPM+sQts/BEAFh2Autk/nM6HWsO/bqpdAJNtE4w8zUFB3Wo72DAauA08
ADIw5UOulnmEqb1p2HlOYy1WdGy5xnuoG6EpppRujEC/a6gWcRvdCj4zrRR+dc9I5sohl3zyikff
I583wuX04H4d81EcLgrJGzUjIvQVSpDCdqgUrG8yOqnWzekZwIWLFwsr17h5vRmE4bruvUsAD4iW
J+fn5bezyENj6haxbkVqhGA98EjWh+0ehjGCAzMwggMvAgEBMIGAMHkxEDAOBgNVBAoTB1Jvb3Qg
Q0ExHjAcBgNVBAsTFWh0dHA6Ly93d3cuY2FjZXJ0Lm9yZzEiMCAGA1UEAxMZQ0EgQ2VydCBTaWdu
aW5nIEF1dGhvcml0eTEhMB8GCSqGSIb3DQEJARYSc3VwcG9ydEBjYWNlcnQub3JnAgMQYJAwCQYF
Kw4DAhoFAKCCAYcwGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0BCQUxDxcNMTYw
NzA4MTE0ODMyWjAjBgkqhkiG9w0BCQQxFgQUu4TYETEP3CkZbPBH5CF3FuM78PgwgZEGCSsGAQQB
gjcQBDGBgzCBgDB5MRAwDgYDVQQKEwdSb290IENBMR4wHAYDVQQLExVodHRwOi8vd3d3LmNhY2Vy
dC5vcmcxIjAgBgNVBAMTGUNBIENlcnQgU2lnbmluZyBBdXRob3JpdHkxITAfBgkqhkiG9w0BCQEW
EnN1cHBvcnRAY2FjZXJ0Lm9yZwIDEGCQMIGTBgsqhkiG9w0BCRACCzGBg6CBgDB5MRAwDgYDVQQK
EwdSb290IENBMR4wHAYDVQQLExVodHRwOi8vd3d3LmNhY2VydC5vcmcxIjAgBgNVBAMTGUNBIENl
cnQgU2lnbmluZyBBdXRob3JpdHkxITAfBgkqhkiG9w0BCQEWEnN1cHBvcnRAY2FjZXJ0Lm9yZwID
EGCQMA0GCSqGSIb3DQEBAQUABIIBAI7lKLfRZcXecvY4gN7PXx2dVuU370diAr0WiG366O5c+n+s
XqgupaarzZXbxoyVyg8iCj8DuGnaMGzPi9ZeG1k+eh5IzK67dewTYkVXwmorlpwXNE7Id4tLRgEv
fLKXv8wMmvRyNF2bafkufhsTaS6JVI3HoGyCLzNkNPf/As4Nl6t5hdcQwxhkpS+M30Y5exu1Xum4
Zt0CMiDlEWf91iqw6ENGbhshCOjryeHrXYz2aDjkewf/jBJgXiUxiV6WSi2FXqo9tL66ElnQX+B1
SdeWTPWaJCgLzYaSnM55zyeTMNUjcDFBJvxP032BUXVP1vxu9ovFqBCDdxMpYYQ/usgAAAAAAAA=
--Apple-Mail=_425D0802-DBB8-44FA-9773-D240C51874D5--
--===============4050307418912570945==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev
--===============4050307418912570945==--