Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

Linux: The OS people choose without $200,000,000 of persuasion. -- Mike Coleman


devel / comp.protocols.kerberos / Re: heimdal http proxy

SubjectAuthor
o Re: heimdal http proxySimo Sorce

1
Re: heimdal http proxy

<mailman.1.1632946375.30761.kerberos@mit.edu>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=148&group=comp.protocols.kerberos#148

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!tncsrv06.tnetconsulting.net!.POSTED.pch.mit.edu!not-for-mail
From: sim...@redhat.com (Simo Sorce)
Newsgroups: comp.protocols.kerberos
Subject: Re: heimdal http proxy
Date: Wed, 29 Sep 2021 16:12:26 -0400
Organization: Red Hat
Lines: 35
Message-ID: <mailman.1.1632946375.30761.kerberos@mit.edu>
References: <87sfyq9qtg.fsf@hope.eyrie.org>
<58C9CD4B-C68A-4480-BFD8-29DC38D8C22A@cs.rutgers.edu>
<6589bffb-75be-62f3-5e3e-6c0b315dd865@secure-endpoints.com>
<78619294-b425-bf71-934b-78381efa8564@spamtrap.tnetconsulting.net>
<B2F885AD-DCA2-4D8D-A3D1-85084F4FB1BA@cs.rutgers.edu>
<b4f28e2f-40f6-6ab2-2caf-7b2d901b9ea8@spamtrap.tnetconsulting.net>
Mime-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="pch.mit.edu:18.7.21.50";
logging-data="607"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Evolution 3.40.4 (3.40.4-1.fc34)
To: Grant Taylor <gtaylor@tnetconsulting.net>, kerberos@mit.edu
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=L0gqVBzDW4vqPFXzxtNR6XwIjZoegwyMxj5Bn4Hsdj4cx+MTkGzxEhrBL+D1SJfHpDkrJq/NGd29DhJbGhIYzKk9302LXpu9Wj9cKeoLwMmwqPqwdTBJibuEOIHUoOUlKcRlNPx4f4zJ+kaTiI8ePTQqQMVFIZP8rFN4Bad3ULA2xdJ0UZa2zB7vZ5m34Y5mfJ8pDnaViGRiD2KM4C3kEkcMF4LCjPLLr0Amfe5zIeYG19PU55NiA4noHC1y4oQ5YxdC7HcUn3kbQzmwqrlcG57sGy4EYHDTtQyCmnmtjniiKJHSEGM09sJUj+g9hUBpsvXBvQeeW9bq/2+RMWoReA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version;
bh=RJZJFisBpKYmrusf4ceVxitnAuCxnVBk/5r0WnBx/D0=;
b=cN6Zgd41zbpbCaxBduL6HBV5QKz1n0DWwX422sk+1h/upkgJ3BXbhNF3l0bQT32c9dzOwKura+PcTDk7Mrta8oB/cBvDA9Ilw+zN6KpB/W85r6onHnb9bf+TihuBQdvfwhmiB+XbqqdlAlA3g8nia1pgPXmcsBDNhcwTvg7WHqg4UHepAj+zFuTyC5w6TPd10N7vfM92sDixHkDkKjmw7eoMBmk4kb/Lq0kqCHVTtIfG0XtoFcWLx4s3pd6wrAb/qjg5Wgmdh4UsSrHY+4XqqAC31yFKW/o+Ubnn7nQfmPup3iXC1hUgq8799HvHxLPduW6An+M1N/vXYUmtsc4UWg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none;
dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=RJZJFisBpKYmrusf4ceVxitnAuCxnVBk/5r0WnBx/D0=;
b=N9MCjd6K8i2cdoiAjLkgsuLrAzqjkRXjCscd7ziBstiyT2FgNIY/IVk8BIIL7m9tuSGOz+tIOHvwpQzWUuzpM2IGq9DuaJhiWzHYJXl5xqgBpJVglrr3EM5FnMQMxPXQ1RoXgixFyOLbhsEOEjC61lueTnSgnZMDFxZbRovbuco=
Authentication-Results: spf=pass (sender IP is 170.10.133.124)
smtp.mailfrom=redhat.com; mit.edu; dkim=pass (signature was verified)
header.d=redhat.com; mit.edu;
dmarc=pass action=none header.from=redhat.com;
Received-SPF: Pass (protection.outlook.com: domain of redhat.com designates
170.10.133.124 as permitted sender) receiver=protection.outlook.com;
client-ip=170.10.133.124; helo=us-smtp-delivery-124.mimecast.com;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com;
s=mimecast20190719; t=1632946350;
h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
to:to:cc:mime-version:mime-version:content-type:content-type:
content-transfer-encoding:content-transfer-encoding:
in-reply-to:in-reply-to:references:references;
bh=RJZJFisBpKYmrusf4ceVxitnAuCxnVBk/5r0WnBx/D0=;
b=fKARPPEuE1V0evDmObaOJ7nPKRzRvu3ha96LRlenJmGyvN39F2UMUU/gPMn+wAQcrJuW6R
hR2EJRhHbL70SFus6/Ag8JTNKQCCRJzMuGh3ZeE5pxTg9t3askVH2i6HJRT+nTvSOmXCk/
VpxTIsHdb3V/HLyS9biqshyv6dWPRj8=
X-MC-Unique: gu9wU7EuMP6xfjFCDR_Bew-1
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20210112;
h=x-gm-message-state:message-id:subject:from:to:date:in-reply-to
:references:organization:user-agent:mime-version
:content-transfer-encoding;
bh=RJZJFisBpKYmrusf4ceVxitnAuCxnVBk/5r0WnBx/D0=;
b=oBdAdAlUy+ACrkwwJTGYWRMXD8pKmr9OYH1A6CPBqcwR4I/g3etykRqa6VqdVL5w+J
4sc9tl/TiqDinWgBbiylOdZSWBCm945j0wxkCut7F8QCdZgMRVlJcy7nOlkK5aib+3GL
o7CssIkJ3VYkf3m/wCyxNHewjzqgl3hRSS3Sur4OxN7QVXFfPiagiBUkIHFz5kt081+m
0q6dGJ+tdhnVZkYKIdCiaDyXK8w6ANhxk3cTtVDtlQfQx3SY8bamkZ1HFMWXRx2f3V4E
lfq37DlvLhhPKo4EDsrEsTRZa97GBU3izKrJi0UuZj5Pkluz9FeBTExXDwbwcuVfACbx
8P9A==
X-Gm-Message-State: AOAM533W1EUy8mj9qH4k1AKRaYG7Qr/G+r+hL3JVmxJRPtHz7xvVeulL
UaFIqzaYvmBMnh6Oavskn6DqaPmWsGgVC/PIQfKyRWVopsbGpoZKq3opfQhVvOkZxm2U2rYSe8U
fVM258X9o
X-Received: by 2002:ac8:76d4:: with SMTP id q20mr2164349qtr.312.1632946348325;
Wed, 29 Sep 2021 13:12:28 -0700 (PDT)
X-Google-Smtp-Source: ABdhPJzR1tSgTTvmh62PU0Hn3rHH95bLc+L4GuZxyPpEl4uXUrHDsZ5SfBZ4Gsrm6xl1BsDQE2SPcg==
X-Received: by 2002:ac8:76d4:: with SMTP id q20mr2164325qtr.312.1632946348076;
Wed, 29 Sep 2021 13:12:28 -0700 (PDT)
In-Reply-To: <b4f28e2f-40f6-6ab2-2caf-7b2d901b9ea8@spamtrap.tnetconsulting.net>
Authentication-Results-Original: relay.mimecast.com; auth=pass
smtp.auth=CUSA124A263 smtp.mailfrom=simo@redhat.com
X-Mimecast-Spam-Score: 0
X-Mimecast-Originator: redhat.com
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: f18821ac-ae23-48fd-0a79-08d9838577fa
X-MS-TrafficTypeDiagnostic: MN2PR01MB5951:
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-Microsoft-Antispam-PRVS: <MN2PR01MB5951138DE7A0B5C36A05F6A8A3A99@MN2PR01MB5951.prod.exchangelabs.com>
X-MS-Oob-TLC-OOBClassifiers: OLM:9508;
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: hAklelvDNeRBnh3bFhQ+Z6mIcPP1JJIr96kH7KZQkn6dGMQ9Mzi0gNT4d/1dUXYdGttJfCLcxz+eqaENItk1KIKi8YUrITSh9vN9sO3vLexeY7GjMRoSXg8ed0gaka7uEcmgXefxOMzyT7nqrS6O0h+Lc19xIHEA2QX5Sn55a7V9muyDDoVeJzoeqMo/yjZfrgIzgrqDPHfG3TeW+K4TPCLIlYgR1xn1KP1nRMzfTiM/dey0WT+tNLsNYTT1+IPkgJRlldaA5bkZh4YKVOtpIRTKhYRHjL7lxxnQOMi2rdQH+GOVYh59o+SbFsaogZS3tWAezMWJXTILx7J80sSu/5ttQkhM9ogEWY6CftJoU9P7rPiwKGec7bSJ92HsqpYQx5sVJAuwM5I4ORI8JhIK9W6uGaXAz8WOctHk7v2ozlNipBntUW3A4WEST2VHJIlcCv0sUn7Vq3elsdFM64ZUQODrv/PogFWwmcv1psxfdkfmGs3tlvwwnOYc/zHm+SyLmnJwL6qYA0YTY5UepK76pUi3Ws4iRrpf7nLsmDWAp5F2qRyTqOC+ZBtQsHN8v9pBZtC7TbLU6TrWfngV4KOwsT1BbLIYQX2XoMgnRt8Y35Wj7Fu3glS9ubbLmxZ3bBbo
X-Forefront-Antispam-Report: CIP:170.10.133.124; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:us-smtp-delivery-124.mimecast.com;
PTR:us-smtp-delivery-124.mimecast.com; CAT:NONE;
SFS:(4636009)(5660300002)(2906002)(86362001)(336012)(8676002)(316002)(786003)(36906005)(66574015)(83380400001)(36916002)(7696005)(3480700007)(7636003)(70586007)(68406010)(508600001)(36756003)(356005)(53546011)(26005)(7596003)(7116003)(956004)(2616005);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-Transport-Forked: True
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 29 Sep 2021 20:12:31.4124 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: f18821ac-ae23-48fd-0a79-08d9838577fa
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: CO1NAM11FT013.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR01MB5951
X-OriginatorOrg: mitprod.onmicrosoft.com
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.6
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
 by: Simo Sorce - Wed, 29 Sep 2021 20:12 UTC

On Wed, 2021-09-29 at 13:41 -0600, Grant Taylor wrote:
> On 9/28/21 2:31 PM, Charles Hedrick wrote:
> > If all the proxy is doing is forwarding content, it might work. But
> > in that case it’s not obvious how much security we’re gaining
> > by the proxy. It may be that just enabling access directly to port
> > 88 would be as good. (I control the network, mostly.) Any sense how
> > risky it is to expose port 88 to the internet?
>
> I was assuming that the proxy would have it's own authentication
> requirements. Thus the proxy would act somewhat like a bouncer in front
> of the KDC.
>
> Somewhat like putting the KDC behind a VPN or SPI w/ port knocking. --
> Allow people that have some modicum of knowledge access to the KDC while
> preventing any Joe Random on the Internet from accessing the KDC.

In truth, most of the value for the proxy (MS-KKDCP style) is that it
uses a standard port open in most places, and wraps everything in TLS
so that most inspection from broken HTTP middleboxes is prevented).

There is the added TLS channel encryption that can prevent a lot of
MITM as well given the client SHOULD validate the certificate of the
proxy.

HTH,
Simo.

--
Simo Sorce
RHEL Crypto Team
Red Hat, Inc

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor