[19485] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Authentication strength and ticket policy

daemon@ATHENA.MIT.EDU (Matt Rogers)
Tue Sep 13 15:57:17 2016

Message-ID: <1473796620.24191.35.camel@redhat.com>
From: Matt Rogers <mrogers@redhat.com>
To: krbdev@mit.edu
Date: Tue, 13 Sep 2016 15:57:00 -0400
Mime-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Errors-To: krbdev-bounces@mit.edu
Content-Transfer-Encoding: 8bit

On the call we briefly discussed the request to be able to influence
the ticket lifetime based on the preauth method used (ie. shorter
lifetimes for 2FA tickets).  It would be good to continue the
discussion here. 

To summarize, my understanding is that there is not a good way to do
this with auth indicators and the current AS/TGS policy code. The
authentication level may be desireable for influencing not just ticket
lifetime but other bits of policy, like the session key type, so we
would need a type of KDC policy interface (KDB?) in order to be
sufficiently generic. Then at that point plugins can be written to
support these kinds of policy decisions.

Regards,
Matt
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev


home help back first fref pref prev next nref lref last post