Kerberos referrals - PowerPoint PPT Presentation

About This Presentation
Title:

Kerberos referrals

Description:

Basic referral mechanism. Motivation. Client config changes are not scalable ... Referrals and canonicalization. Client name canonicalization issues ... – PowerPoint PPT presentation

Number of Views:54
Avg rating:3.0/5.0
Slides: 7
Provided by: jkjaga
Learn more at: https://www.ietf.org
Category:

less

Transcript and Presenter's Notes

Title: Kerberos referrals


1
Kerberos referrals
2
Schedule
  • Refresh draft and publish before interim meeting
  • Current date - December 20(tentative)

3
Basic referral mechanism
  • Motivation
  • Client config changes are not scalable
  • MS deployments are heavily cross realm oriented
  • Mechanism
  • KDC issues referrals
  • Client chases referrals

4
AS referrals
  • Client uses KRB-NT-ENTERPRISE in request
  • Client sets canonicalize
  • KDC returns
  • KRB-NT-PRINCIPAL if name found
  • KDC_ERR_WRONG_REALM if referral
  • KDC_ERR_C_PRINCIPAL_UNKNOWN

5
TGS referrals
  • Client sends TGS-REQ with canonicalize
  • KDC returns TGS-REP
  • with service ticket if service found
  • Cross realm TGT if the service in another realm

6
Issues
  • Referrals and canonicalization
  • Client name canonicalization issues
  • Possible issues with name based access control
  • Can only get canonicalization when authenticating
Write a Comment
User Comments (0)
About PowerShow.com