Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

If God is perfect, why did He create discontinuous functions?


devel / comp.protocols.kerberos / Re: Looking for a "Kerberos Router"?

SubjectAuthor
o Re: Looking for a "Kerberos Router"?Ken Hornstein

1
Re: Looking for a "Kerberos Router"?

<mailman.42.1710339397.2322.kerberos@mit.edu>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=494&group=comp.protocols.kerberos#494

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!news.quux.org!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: ken...@cmf.nrl.navy.mil (Ken Hornstein)
Newsgroups: comp.protocols.kerberos
Subject: Re: Looking for a "Kerberos Router"?
Date: Wed, 13 Mar 2024 10:16:27 -0400
Organization: TNet Consulting
Lines: 14
Message-ID: <mailman.42.1710339397.2322.kerberos@mit.edu>
References: <CD4C5157-C1DF-4AAB-9DA1-F54FEF928266@gmail.com>
<202403131416.42DEGRub016309@hedwig.cmf.nrl.navy.mil>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="11394"; mail-complaints-to="newsmaster@tnetconsulting.net"
Cc: kerberos@mit.edu
To: Yoann Gini <yoann.gini@gmail.com>
DKIM-Filter: OpenDKIM Filter v2.11.0 unknown-host (unknown-jobid)
Authentication-Results: mailman.mit.edu;
dkim=pass (1024-bit key, unprotected) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.a=rsa-sha256
header.s=selector2-mitprod-onmicrosoft-com header.b=uwPo+oXd;
dkim=pass (2048-bit key,
unprotected) header.d=nrl.navy.mil header.i=@nrl.navy.mil header.a=rsa-sha256
header.s=s2.dkim header.b=ZNXkbn0E
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=mjO/gndrS4S6pgMd7aLC8O6nSdGObr+vDOHi1UvL3uUzBlCHXwHpNUKE+DuhAd+arrFv+PXmwK2/yOYQKB1ZsoV/gr6WBHMDrlnO91pvRzIPalVyl4RPDQtB0OI51P4MJxn2SIXmYwKlvHZjUzigAQf5JIT2mmUgzwxv/k53A2eHRDgsm6iv0QP0LBQkJgupma3Wy5SEbwMO324nRZRA0QcvHx2cadsbrYMaWqcxBpSjAQcZgwfQmGpid4UuPpXZHPHhVccTT0yPi8/SgyD0LUpYcNuDQ2wR4WHKjTmx1HsWYS+M9ut9bzuW4so5aeXIdtbcubsycXVTaG0IT4BjsQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=9/KFfzePpHeaeCUkIuAbW4P5/gCqsMuhtl+iZYMNUR4=;
b=OTHoj3owdEeIv8tYMJqto8zP/0TXIZ9HU+wfrhenp6ULndLBo29ttwm/joniNR2WeISLX1/P7qt7hoBrftwN8n5uf1VgGpoy9Jhjkl2g0DADD2Gm8RL+O3zRE2vctnmAxa+I9SlN4eRF+M7qtUFxPfoixx5fiI0//jRcFbNbyvwUaRGmoIHRrPtqB7Bmt8keEZZSiIgREDJMV9ZtOm49/zcKRFu3UKlTPThpNIifT/mxRyRVcvqnf/GkM1XbKL+yMPoeG/eMgUrF6oK4EjJpNd9FXbaF6ni6h+p6BUQHfFekQgFUINkz3nACmiWVzld/Aa5T82n12j4WciufqIT8PA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=temperror (sender ip
is 140.32.59.234) smtp.rcpttodomain=mit.edu
smtp.mailfrom=cmf.nrl.navy.mil;
dmarc=pass (p=reject sp=reject pct=100) action=none
header.from=cmf.nrl.navy.mil; dkim=pass (signature was verified)
header.d=nrl.navy.mil; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=9/KFfzePpHeaeCUkIuAbW4P5/gCqsMuhtl+iZYMNUR4=;
b=uwPo+oXdXuYfugIBJUd//AENkBfBrSKb7O6PvXTJoMBh5LOe05VnR8lNxO3mA1Nkd2cn/oUNUtZHRcdqU0Ztt/Db0Sq+z3eTf5rXa3+AfkW2N0dFkSZcc6vi3BR97k4YaUOIVWDombuCE02cYA+iHsR/Co+xIXQQuBxzhmJQINs=
Authentication-Results: spf=temperror (sender IP is 140.32.59.234)
smtp.mailfrom=cmf.nrl.navy.mil; dkim=pass (signature was verified)
header.d=nrl.navy.mil;dmarc=pass action=none header.from=cmf.nrl.navy.mil;
Received-SPF: TempError (protection.outlook.com: error in processing during
lookup of cmf.nrl.navy.mil: DNS Timeout)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nrl.navy.mil;
h=message-id : from :
to : cc : subject : in-reply-to : references : mime-version : content-type
: date; s=s2.dkim; bh=9/KFfzePpHeaeCUkIuAbW4P5/gCqsMuhtl+iZYMNUR4=;
b=ZNXkbn0E4qQUX+dD2z6U0oRGTOwHSy27AxlWgWShLOT2VZ64QXXyY6Y3kTfIyHe7rguK
7HEDtIsZ/wE/b+ocESxTpe57U31vVbrHgIsnpqhjzGuHdf2tVoLBMPXBvnvsYLbGwCmc
5itUp4249l0TPP0VApUIayfiwwOO4P/XptXNgrprZ/KpZd4SyGcotNmfDd9gVxbJYtIb
v3S+/mqKqjrJ+aOIXw1Jy816yVaEmp50hlqD/K+ngE/XgDd90+unQaGD7O9SP8oWw3nT
0u5gyHXdr5zz+xdQO+yZNTgPHHwClO3EHJVYQaTkaY5UhT+UWXxPXAqHRjaT3p26a4oc 0g==
In-Reply-To: <CD4C5157-C1DF-4AAB-9DA1-F54FEF928266@gmail.com>
X-Face: "Evs"_GpJ]],xS)b$T2#V&{KfP_i2`TlPrY$Iv9+TQ!6+`~+l)#7I)0xr1>4hfd{#0B4
WIn3jU;bql;{2Uq%zw5bF4?%F&&j8@KaT?#vBGk}u07<+6/`.F-3_GA@6Bq5gN9\+s;_d
gD\SW #]iN_U0 KUmOR.P<|um5yP<ea#^"SJK;C*}fMI;Mv(aiO2z~9n.w?@\>kEpSD@*e`
X-NRLCMF-Spam-Score: () hits=0 User Authenticated
X-NRLCMF-Virus-Scanned:
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: CH3PEPF00000017:EE_|SA0PR01MB6428:EE_
X-MS-Office365-Filtering-Correlation-Id: 9bc41316-840e-4256-9fce-08dc43682dcf
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: W8CNXDr7NQ+5Bv7FpqPkmsnKJFjXAEGTatFqgotnGAdKJsBaGxlVafhDusRYSOcT0LVmbYb7rvF3Hb2CfrpgPgB00juzc9AisLFHDNrFKcSo5tKmPEijXm+I06mhS+apv0yvWVGwnDIE6FR6Hi/apkQxC124q3ReHSn8ZiEEK/nuuefo8pAZbKLvcERhIeWMwSrb6RprMQ6FOitaxFyiKd7c0lmkqGNLXCS/QbN8JwAXycxtGKux6wUPzni4OySVQN1b+lStT5W6DyB15Zm5cQETnURjrw7MHJ2n6CUxffVnrv/WN0+b3GvdDqSd591yRmzGlwV+2KqIWcyo0xa++2Oz5oR+fDbbTdeMxNetzt2fkkBPp8xwf1y2nd4Mn2rkgEZM/YkfU70Eypdb4/Lmfi2PwCEayAg06A49U4KljoxYQwV/BsGseWUgE1y1f8mr4/n2EsY28YookrrOac0UJ3p9xRSYPbRtB0VOiVaOF6uyr9411DJvB+ebP0ivHUNvRyJP7sTNU4cmUxCkUI8AzwiFnJOjuo6UXi1iVwUPd6lvpnWGyhHEIavCk0npW4T9ahpNYLZI61ivbRjjyLve6wCEVB9aFoTnOjamGGh1KiO01WkCyUszf1XI3OvNuPISQLTL1i6RxlJGU4cYAk1ryV1lP34ffNLZs6ZME5h2HCoQ0r9kbvbOHyn8+kwPw79cAYE8MpSVlMIm9wzo6wXjiTv1xy6ld994Gjd4MlbcuYqrIjf3T/81tRMLPpF7kUe6
X-Forefront-Antispam-Report: CIP:140.32.59.234; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:mf.dren.mil; PTR:mfe.dren.mil; CAT:NONE;
SFS:(13230031)(376005)(61400799018); DIR:OUT; SFP:1102;
X-ExternalRecipientOutboundConnectors: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-OriginatorOrg: mitprod.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 13 Mar 2024 14:16:30.2915 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 9bc41316-840e-4256-9fce-08dc43682dcf
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: CH3PEPF00000017.namprd21.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA0PR01MB6428
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <202403131416.42DEGRub016309@hedwig.cmf.nrl.navy.mil>
X-Mailman-Original-References: <CD4C5157-C1DF-4AAB-9DA1-F54FEF928266@gmail.com>
 by: Ken Hornstein - Wed, 13 Mar 2024 14:16 UTC

>Here with Kerberos, I'm wondering how we can achieve something
>equivalent, using a shared IP for multiple Kerberos realms and having
>the incoming requests routed to the appropriate backend by some kind of
>inspection.

I think that is certainly _possible_, but I don't believe there is
anything that does that today. You'd have to parse the Kerberos message
(which is ASN.1 and there are plenty of things that can handle that)
and extract out the realm of the server principal and route the message
appropriately. One thing that leaps out at me is that by default a lot
of Kerberos messages default to UDP transport so that might be a bit
trickier to proxy them (but not impossible).

--Ken

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor