home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.protocols.kerberos
- Path: sparky!uunet!math.fu-berlin.de!uniol!Christian.Kuehnke
- From: Christian.Kuehnke@arbi.informatik.uni-oldenburg.de (Christian Kuehnke)
- Subject: V5: Inter-Realm-Authentication
- Organization: University of Oldenburg, Germany
- Date: Fri, 1 Jan 1993 23:20:22 GMT
- Message-ID: <1993Jan1.232124.28836@arbi.Informatik.Uni-Oldenburg.DE>
- Sender: news@arbi.Informatik.Uni-Oldenburg.DE
- Lines: 52
-
- Hi!
-
- I've got a question regarding inter-realm authentication in
- Kerberos V5. I think the "Internet-Draft" leaves some gaps open in
- this field.
-
- Situation: Client c in Realm rc wants to communicate with
- Server s in Realm rs.
-
- Now, I see two possibilities:
-
- a) c requests from his TGS a TGT for Realm rs
- b) c requests from his TGS a Ticket for (s,rs)
-
- Which one is the proper procedure? Assume that no interaction with
- intermediate Realms is necessary. In both of these cases, the
- response would be the same: A TGT for Realm rs, with which the
- client could request a Ticket for s from the remote TGS. Right?
-
- Of course, in case b) the client would have to recognize, that the
- obtained Ticket isn't for s. On the other hand, in a) the client
- has to see that it simply cannot obtain the Ticket for s directly.
-
- I am still more confused by page 24, section 5.3.1 of the Internet-
- Draft (01/09/92), where in the explanation of the "realm" field in
- the Ticket, it says:
-
- "This field specifies the realm that issued a ticket. It also
- serves to identify the realm part of the servers's principal
- identifier. Since a Kerberos server can only issue tickets for
- servers within its realm, the two will always be identical."
-
- But what does a TGT for a "remote" Realm then look like? Of course,
- the statement holds for Tickets for application servers. But for
- the example given above, shouldn't be realm=rs, sname=s?
- Especially, because in the pseudocode for KRB_TGS_REP generation
- (A.6), the realm of the resulting ticket always is set to the realm
- the TGT is for.
-
- And the pseudocode for KRB_TGS_REQ generation (A.5) doesn't set
- req.realm at all...
-
- Any enlightening is very much appreciated :-)
-
- Happy new year,
- Christian
-
- --
- - Snail : Christian Kuehnke/Hartenscher Damm 65/2900 Oldenburg/BRD -
- - Internet: Christian.Kuehnke@arbi.Informatik.Uni-Oldenburg.DE -
- - Bitnet : 249923@DOLUNI1 -
- <* For CIA grep: bomb, spy, attack, socialism, panama, cuba, grenada *>
-