Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

Entropy requires no maintenance. -- Markoff Chaney


devel / comp.protocols.kerberos / Re: Looking for a "Kerberos Router"?

SubjectAuthor
o Re: Looking for a "Kerberos Router"?Marco Rebhan

1
Re: Looking for a "Kerberos Router"?

<mailman.44.1710341106.2322.kerberos@mit.edu>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=496&group=comp.protocols.kerberos#496

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: me...@dblsaiko.net (Marco Rebhan)
Newsgroups: comp.protocols.kerberos
Subject: Re: Looking for a "Kerberos Router"?
Date: Wed, 13 Mar 2024 15:44:46 +0100
Organization: TNet Consulting
Lines: 9
Message-ID: <mailman.44.1710341106.2322.kerberos@mit.edu>
References: <CD4C5157-C1DF-4AAB-9DA1-F54FEF928266@gmail.com>
<F2C79001-B1E0-4D8F-91BC-FC8260003282@dblsaiko.net>
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.500.171.1.1\))
Content-Type: text/plain;
charset=utf-8
Content-Transfer-Encoding: 8bit
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="16139"; mail-complaints-to="newsmaster@tnetconsulting.net"
Cc: kerberos@mit.edu
To: Yoann Gini <yoann.gini@gmail.com>
DKIM-Filter: OpenDKIM Filter v2.11.0 unknown-host (unknown-jobid)
Authentication-Results: mailman.mit.edu;
dkim=pass (1024-bit key, unprotected) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.a=rsa-sha256
header.s=selector2-mitprod-onmicrosoft-com header.b=LQYGxQXQ;
dkim=pass header.d=dblsaiko.net header.i=@dblsaiko.net header.a=ed25519-sha256
header.s=ed25519 header.b=VJbVm6a7;
dkim=pass (2048-bit key,
unprotected) header.d=dblsaiko.net header.i=@dblsaiko.net header.a=rsa-sha256
header.s=rsa header.b=CweTSxq0
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=PKZ6Raq0V/CUrqruieIvqsoAJwkjMWc94EO7MHez7Hb9TfaOUzgoo5dwLph1xnrDuTrc/c7xblYs74/QLQsv/Nu3NVui6EeMgpW5mlcIiWgX+WLFG1EXDEdgo3sDQVsuwUdRl/TltJmLdUbfhw/10p3kWCaKlV/C/KxHOwCK61SEeGnOfVdGUfbCIURNiisJosUEYOijtYh+iQpbU9CU/e9oJ8QZmARe0j/rb6lSIJITZS8lvZnTNs835QPj/aLeBr7VfQdFjTCraSFNYqO/U7UAetuKH+OngSRdbwFQrh5Jh7+0/kMrl5OO3hBoTinksqewhEYYwK33Te0pLCVrRg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=K2ggsGcEZFkbJatpTHAOgaYnhXIfj7zD9H+zg6pLats=;
b=TtgQysk8DykGVBUdRBOMk6yjoM33FbD+haFLp5D9q9tUYFVDs91duVdoeK7sIdFZ4TrAIeuwRcAu/pcpro5xdZ0wcFY8/nQYmqux2gVbf+NvIBdoNuuuAfuykcOxaH1D2RLGcBnQ5Hn9yu76YAIXOCu+ekE1MJ+AbFIqoQTJ8ShAjPBM9eJeHbSPafww/HdSkzwsIeS8ITmNVf5xE31KwRhKH3PfUM5fVvLNJMDLbBsAy7R3d9EapsQ1ykP9w/gEWawBVK9x3pi/mTZKBZ/TMQi+SPdumzys4d/lpgftBRJwVT/gqF4avN1kGfsaW4Hb7O5G1ve5XKq6hd3Z7di0QQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
135.181.103.53) smtp.rcpttodomain=mit.edu smtp.mailfrom=dblsaiko.net;
dmarc=pass (p=reject sp=reject pct=100) action=none header.from=dblsaiko.net;
dkim=fail (signature syntax error) header.d=none; dkim=pass (signature was
verified) header.d=dblsaiko.net; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=K2ggsGcEZFkbJatpTHAOgaYnhXIfj7zD9H+zg6pLats=;
b=LQYGxQXQ2H8P4+1jKVbr4NgOc+UqNUNNAqWHNq0A4l1pQ+qI2GeXN768m46MKdKDfU2kv6KZJlLShQVSOi1sdzcPJK+QbDUfX2eCFVYS4fPzCIhb84giYG0fxmnoe9Sj2uhIv5/p21JqNQ2b2jbMQGXhKa5bRQ5RUGqOx+l3PwY=
Authentication-Results: spf=pass (sender IP is 135.181.103.53)
smtp.mailfrom=dblsaiko.net; dkim=pass (signature was verified)
header.d=dblsaiko.net;dmarc=pass action=none header.from=dblsaiko.net;
Received-SPF: Pass (protection.outlook.com: domain of dblsaiko.net designates
135.181.103.53 as permitted sender)
receiver=protection.outlook.com;
client-ip=135.181.103.53; helo=polaris.dblsaiko.net; pr=C
DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=dblsaiko.net;
s=ed25519; t=1710341096;
h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
to:to:cc:cc:mime-version:mime-version:content-type:content-type:
content-transfer-encoding:content-transfer-encoding:
in-reply-to:in-reply-to:references:references;
bh=K2ggsGcEZFkbJatpTHAOgaYnhXIfj7zD9H+zg6pLats=;
b=VJbVm6a7f5iqtlH7yYWYxvgK1I4qhu8DL22q0cP4SUKJNrW8UTf26dOYsGQzwTEo0vEE+X
z0XUHjLEx833E1CQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dblsaiko.net;
s=rsa; t=1710341096;
h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
to:to:cc:cc:mime-version:mime-version:content-type:content-type:
content-transfer-encoding:content-transfer-encoding:
in-reply-to:in-reply-to:references:references;
bh=K2ggsGcEZFkbJatpTHAOgaYnhXIfj7zD9H+zg6pLats=;
b=CweTSxq0mfhVe0myqiy+6eFLLH/eJN+hO4Kxz1S2Wr1bRSM+NwJ4DsSKOJdnWl6Z/r8EwN
vg2Dn40FLQhgI17XY3efHJlrIPkBcZR5mrPyHbOHh9P3mwp/OpQZ5qTAxQDVmNZq3gyQ3z
z7uAcYDz9rXslfDHd/+77p4zo/+9u0avhdUnZ7+QGX7MZRHW+YeKhYP7en8rjqGapckZ4W
Jx56R/5WovxhoxYUV0cMEvSF4yTB99dxK7svY2oPkkZ7LpyQ7l7h+aF4SsuAZv2IXGC3wm
3w/j/tz1Zr/VysvPLyYGNSzlf4gPmn0mPOVvGqWmfkPIhvuYmy2hCo4pTAE2OA==
In-Reply-To: <CD4C5157-C1DF-4AAB-9DA1-F54FEF928266@gmail.com>
X-Mailer: Apple Mail (2.3774.500.171.1.1)
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: SN1PEPF0002529E:EE_|MN0PR01MB7705:EE_
X-MS-Office365-Filtering-Correlation-Id: 07f7dd5e-09ae-408c-a4b1-08dc436c282b
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: KvDwLpbKxGf51aVmdfOkSpIb3aV2Ie7qh51FpizFPc7l2LftZ1BoQd2DPtbJZexhewVPTVbAZcVDAgmmu3rJuxr3dIInPqRnlyxbYIY+JzfvDLs5Q8rnnPyU9RDfrPFPEdGaywZl8ISlp7ZP9Cf6Y/shW9DBSctSYN2rJJ2qHJ6+vkF79e1Yhg6sRpx2q1rdC+rYVICajPWbtEY4LkZoIpsjPvHhfHGF1PTjBH7n+P38TUcREn9UJnoKO2ctyjEwu0WtIrdMYBoxTLiIyZV9I1VTq4FpJgLx1Z7R46kd5aKqfonrGYdh19zEHlBuRNrg4RC1PGNEOPFWc5dnjJtmfzC+Sij4TtEyGc5y/+D9c0/MiQS7651VxSTtf4P30qx+T5cX5yC1FMlMZa5J2FYhqsIlkwqlbHNfSTh6unnxZcO4U5Lz9dDPO9rMfpUqfEivb7eOQXsGs4M1br8jllRgncLt2OyiA1dHUFBlHAxUGbhnkVbr8y5YhT99qx8tAFcIcEhs1yPVGjNVTno6brtPZM5DxPSB4Y2vO0xAEf15qRD+URuV3ON5e8Rc9yMzlOB6NgHmHuPHSKSVo99+82zjBBzciKS7mT8+CJAlF38sVuDpwlmiGvP0nRRX6VI0PNnw6hNSgT3AqDEi1999tivfYzJXTA4Yoa3DVgPjXAIjEgpxdICMnU4mOUOGQUL3orKeT8min3XNbCY44Vt7uYvikbQexig6H1awZaqBSF4dVb2ErjdmU+pMvXtJVr0bRxzp
X-Forefront-Antispam-Report: CIP:135.181.103.53; CTRY:FI; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:polaris.dblsaiko.net; PTR:polaris.dblsaiko.net; CAT:NONE;
SFS:(13230031)(376005)(61400799018); DIR:OUT; SFP:1102;
X-ExternalRecipientOutboundConnectors: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-OriginatorOrg: mitprod.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 13 Mar 2024 14:44:58.5964 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 07f7dd5e-09ae-408c-a4b1-08dc436c282b
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: SN1PEPF0002529E.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN0PR01MB7705
X-MIME-Autoconverted: from quoted-printable to 8bit by mailman.mit.edu id
42DEj28O1411925
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <F2C79001-B1E0-4D8F-91BC-FC8260003282@dblsaiko.net>
X-Mailman-Original-References: <CD4C5157-C1DF-4AAB-9DA1-F54FEF928266@gmail.com>
 by: Marco Rebhan - Wed, 13 Mar 2024 14:44 UTC

> On 13. Mar 2024, at 12:48, Yoann Gini <yoann.gini@gmail.com> wrote:
>
> Which allow us to have end to end TLS communication between our customers and their tenant. Which is mandatory for our mTLS. But without consuming one public IP per tenant to keep cost under control.
>
> Here with Kerberos, I'm wondering how we can achieve something equivalent, using a shared IP for multiple Kerberos realms and having the incoming requests routed to the appropriate backend by some kind of inspection.

Set it up with a publicly routable IPv6 network, with one IP per tenant. You’re not going to run out of a /64 anytime soon, so the cost should stay constant.

-Marco

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor