Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

#define SIGILL 6 /* blech */ -- Larry Wall in perl.c from the perl source code


devel / comp.protocols.kerberos / Re: Looking for a "Kerberos Router"?

SubjectAuthor
o Re: Looking for a "Kerberos Router"?Yoann Gini

1
Re: Looking for a "Kerberos Router"?

<mailman.43.1710339697.2322.kerberos@mit.edu>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=495&group=comp.protocols.kerberos#495

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: yoann.g...@gmail.com (Yoann Gini)
Newsgroups: comp.protocols.kerberos
Subject: Re: Looking for a "Kerberos Router"?
Date: Wed, 13 Mar 2024 15:21:20 +0100
Organization: TNet Consulting
Lines: 33
Message-ID: <mailman.43.1710339697.2322.kerberos@mit.edu>
References: <CD4C5157-C1DF-4AAB-9DA1-F54FEF928266@gmail.com>
<202403131416.42DEGRub016309@hedwig.cmf.nrl.navy.mil>
<581276BD-9D29-4D8C-A23E-8613493E378B@gmail.com>
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.500.171.1.1\))
Content-Type: text/plain;
charset=utf-8
Content-Transfer-Encoding: quoted-printable
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="12189"; mail-complaints-to="newsmaster@tnetconsulting.net"
Cc: kerberos@mit.edu
To: Ken Hornstein <kenh@cmf.nrl.navy.mil>
DKIM-Filter: OpenDKIM Filter v2.11.0 unknown-host (unknown-jobid)
Authentication-Results: mailman.mit.edu;
dkim=pass (1024-bit key, unprotected) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.a=rsa-sha256
header.s=selector2-mitprod-onmicrosoft-com header.b=pJMqlTTv;
dkim=pass (2048-bit key,
unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256
header.s=20230601 header.b=lTiXI/CC
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=mPhun9aoVAUWaBs4slgPNYIyTT4PJ5KPbNd743AJQrFDIHBmqiwu4bqO7VEWfe2UMwAwp31gZcGV07uCOAvWZW0GKXPTyHhA0Rl29j2B7sUkAHrqU1arR6epa3CLammwZLwm8BmCNfi3G2XR/RqT7hKBM7gBEHPXQmlBSjEva0/hyGkrS9IVys3y6Cj9YLVdAC37sgVHUPxG/ipRb5/YhOC2yefnccFmM1yqVyOTWFKwrELDnKdL/yUE/co3/c7WRmiGHTDqBDrIdwDfuDpZFXn+pt/4lpd6/DeLGfNNCDN6CY0XUXi/PHDQ5wtqfwtvWj9neuRYbX4ar+BmnOYgDw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=tCJTF8ZQUD/zTjKoeKPrF58qEydcb0tSY5IsZ2xANgA=;
b=JdMVb586z/WyY49Wx3pZzVZT0cpki+aP3K/cY43FMTFdKxUowV2QnssGzaPHaNNqsQPlIi+HerzLTufA/qclr4PQmS8OZ2a/TzEfN2sFSkQX2RA+C9wg0Akp9udw3ckl6bwd2fCITDsgUcIyzt6aAxfnr2u8NgKfOxf+lwiOpXEAGGnRFzAiBXG2Dh1fWInufF9FYgooRdQv4AbB7YM6n+dRM+ffwvw4gEku0g6oBRseziMRcNPLEWkr90jtPBtU7x9Z2AvYGlkc4WbcqCxh5Vi8sYygQ7yTY+33AiDPJugOJt0N9TEFT57Q+Fi8wEyU53ZbPIAOEp7E/GMbrxNc0A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
209.85.128.54) smtp.rcpttodomain=mit.edu smtp.mailfrom=gmail.com; dmarc=pass
(p=none sp=quarantine pct=100) action=none header.from=gmail.com; dkim=pass
(signature was verified) header.d=gmail.com; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=tCJTF8ZQUD/zTjKoeKPrF58qEydcb0tSY5IsZ2xANgA=;
b=pJMqlTTv3Q9aIhXoqtXa7E+pKeS0e4IZcuFDXWXxGyD7qawA3CTrLlz+BuU7oa4fSVnHF5T1UhB05hkR0Oi9zKndQMu25dpI6Ii9QVad4qqYuBDsYZOYGpYvC590s+fERNIsKq8BMEPC5Id5ui7Fw6OkEIINxsqhRTgWMEBx+KA=
Authentication-Results: spf=pass (sender IP is 209.85.128.54)
smtp.mailfrom=gmail.com; dkim=pass (signature was verified)
header.d=gmail.com;dmarc=pass action=none header.from=gmail.com;
Received-SPF: Pass (protection.outlook.com: domain of gmail.com designates
209.85.128.54 as permitted sender) receiver=protection.outlook.com;
client-ip=209.85.128.54; helo=mail-wm1-f54.google.com; pr=C
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20230601; t=1710339692; x=1710944492; darn=mit.edu;
h=references:to:cc:in-reply-to:date:subject:mime-version:message-id
:from:from:to:cc:subject:date:message-id:reply-to;
bh=tCJTF8ZQUD/zTjKoeKPrF58qEydcb0tSY5IsZ2xANgA=;
b=lTiXI/CCJxzgEOCjMX/8oEn4x6wa471ef2LVyjyAjdH3n+1pQlTOt5S9KrFBolRf2w
yCccZ1dmAHd5JLPxeezjyq6yeWiX17wcpfFbDeqXd5frHfZTsvFMiMQEqSErQEWvKO7F
SH7AyQCC5W/M8HH+6Jar6tCDCuxSx0CH5Ox4zxplEYHiX4whdHoWjuVQIQ2E3wTok4EI
kw44yuGWtOsxQlOv0dmyFd3xxgu0wEsjeAm2qA8MY7AY6U4yLbfcq6q//lqEjVHRgy0q
W+eFLs18ymJsqU+ZI7L1+Bt2iy+rw/4am3icppHCFxynYPd4NjVnbQ9y17A/kFqSZpHa
pH0g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1710339692; x=1710944492;
h=references:to:cc:in-reply-to:date:subject:mime-version:message-id
:from:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=tCJTF8ZQUD/zTjKoeKPrF58qEydcb0tSY5IsZ2xANgA=;
b=F3Qjjzud40nApcNT0LKGsw5LrUgmxC087l6oYbXcyStkYYtk/Mzm0GWD18XA4HuHN8
+qoXhMOwdAmtGqHo5TZ6LyI7j01XM2u/wcOhvrRBn4PtGkmFb7rbCjWF2XxtmKiFJQpM
04uZ2UtsRfXPltOmWqCa3eYQkc94dACZbEvl9cvQBMVrVqDOOzQ9jQTn3b8cRRk12QPY
OoSMEBqZKNTI8/O150tVeq6zzsxE0tdamoQzJZOIo5jiULBQXqni4t5aIwOLvV37NEOS
xF2dqM3f85/ZfiMz2Ezc6mnl35UofESI2ygCjWUN+W4469jRrApj/NWzasiWUOq/QocO
ReKA==
X-Gm-Message-State: AOJu0Yzz876xciNnD3cuBbaPg7lKLv0MleAabil8sgqAygHvSB+G/sq8
KRSieXDq2puRcKHVM8kdHeltEpsWLdaJZA2KsaGDgp/G2dk23+sY8dr+THAY/qI=
X-Google-Smtp-Source: AGHT+IGdieqFeS0zv7q6CqkGC1Zms9T0nG+eAU6WQevObP4Ws+yOnIgRz8nutzWh1hYuS75B7ySlDQ==
X-Received: by 2002:a05:600c:35c6:b0:412:9b49:11f with SMTP id
r6-20020a05600c35c600b004129b49011fmr92575wmq.2.1710339691854;
Wed, 13 Mar 2024 07:21:31 -0700 (PDT)
In-Reply-To: <202403131416.42DEGRub016309@hedwig.cmf.nrl.navy.mil>
X-Mailer: Apple Mail (2.3774.500.171.1.1)
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: BN2PEPF000044A8:EE_|SA0PR01MB6457:EE_
X-MS-Office365-Filtering-Correlation-Id: 4ca35adb-3bcb-4b99-4817-08dc4368e24b
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: YFlQvsLdHZLoacTNBMKP7h0/ufnb44hFHuI0tNA8kjZfkIRkQzB3MZXumc3mj4DbtkKcrVLZ81DbCfrf2n+RKMpJ2SZSBtJgttAFyjhQfOQa/fthb12H+5tQW2wwgCYOOmEY9yjxWrlGtsIIH6b7ZnCzcu2fj1A5lOaHKUiU6CEReWcw6iuRCzx78RPZ3JFAMsLvJFi8ZTLYd07IQTMnlbk7qmSez7jIM9SGccV2zcZaWIYxBVQCaG0QWv73VI8WQ2uQQfJbHE+wuQlpBezGBwP6qoa+ta49ZFDRrXCBMg3eLeIyThQWqfUP4tYe8bUCxgWCmXvb7N9Qpc3reRvhYuuU+ywRb6rjwWmpv+pcIE0afGiuMnXzErgxTRR5hlx4Cy+Ih9Gm6znS+KzeJDz9aghfqF5lU0imm56pGBCPYq3Rl01JCQixIrb6ELZxjcTpyg7iziR8lKZxVGGDX0Vff46pIdoropcWZV4qUqOi/3nVg1zwnMx0EpqqtcxaEFpHrejZJ5lGwweEM8hQeRSCwu2r6DQVnW8Bxbp6ZCWR/Zfb6DJrWb5YES6DG1TScafWrhEmLYYqZRZLr1HewtO8qH/VotZ3rHNlJ0VeCCldFx8r/yyTz1kISrl1TL6xe+Q4KFVupXkhPGH9ajy+ODQmBci6FfIfm9Ppj12EVTnqP8KoirC3qabsYnKLyzrMSwE34cUNtr+iJ88Yl70eO+DpFsV7053VRhFXGQiCnFQjAm2p8JAqsrCerDg9kf9HfS/D
X-Forefront-Antispam-Report: CIP:209.85.128.54; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:mail-wm1-f54.google.com; PTR:mail-wm1-f54.google.com;
CAT:NONE; SFS:(13230031)(61400799018)(376005); DIR:OUT; SFP:1102;
X-ExternalRecipientOutboundConnectors: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-OriginatorOrg: mitprod.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 13 Mar 2024 14:21:33.1543 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 4ca35adb-3bcb-4b99-4817-08dc4368e24b
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: BN2PEPF000044A8.namprd04.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA0PR01MB6457
X-Content-Filtered-By: Mailman/MimeDel 2.1.34
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <581276BD-9D29-4D8C-A23E-8613493E378B@gmail.com>
X-Mailman-Original-References: <CD4C5157-C1DF-4AAB-9DA1-F54FEF928266@gmail.com>
<202403131416.42DEGRub016309@hedwig.cmf.nrl.navy.mil>
 by: Yoann Gini - Wed, 13 Mar 2024 14:21 UTC

Hello,

> Le 13 mars 2024 à 15:16, Ken Hornstein <kenh@cmf.nrl.navy.mil> a écrit :
>
>> Here with Kerberos, I'm wondering how we can achieve something
>> equivalent, using a shared IP for multiple Kerberos realms and having
>> the incoming requests routed to the appropriate backend by some kind of
>> inspection.
>
> I think that is certainly _possible_, but I don't believe there is
> anything that does that today. You'd have to parse the Kerberos message
> (which is ASN.1 and there are plenty of things that can handle that)
> and extract out the realm of the server principal and route the message
> appropriately.

Yes, that's the main option we see so far, but before jumping on the "let write our own proxy" solution I wanted to be sure that we don't miss something like proxy feature in an Kerberos implementation or some kind of cascading scenario.

> One thing that leaps out at me is that by default a lot
> of Kerberos messages default to UDP transport so that might be a bit
> trickier to proxy them (but not impossible).

Yes, that's another aspect of the issue, our expectations so far are on support for TCP only clients. Since it's for mobile users that we are looking to have this support, it shouldn't be an issue.

Thanks.

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor