Re: Standard mechanisms to manage domain->realm mappings in multi-domain infrastructure



Newman, Edward (GTI) wrote:
What are the preferred mechanisms to manage DNS domain to Kerberos Realm
mappings in large implementations?

I want to avoid having to redistribute a krb5.conf to every client each
time this changes so was wondering how others have solved this problem.


How often do you think this changes and what is wrong with the SRV
records that Kerberos currently uses?

Need some solution that supports a combination of the following
platforms:

- Active Directory 2003
- MIT Libraries
- Sun Java JDK
- Quest Vintela
+ other proprietary implementations

Looking online suggests the following:

1) DNS TXT records

- DNS TXT records used to link a DNS domain to Realm via
_Kerberos.<Domain-name>
- Apparently vulnerable to MITM attacks (is this an issue in closed
environments?)

MITM attacks mostly happen that way.

- Appears to be support by MIT & Heimdal but not by Java JDK Kerberos
libraries or various commercial products
- Still an IETF draft (draft ietf cat krb dns locate 02 txt)

2) Kerberos Server referrals

- KDC returns referrals to client when request made to local environment
- supported by Windows AD 2003 & MIT (limited documentation on how
mappings managed for referral process)
- Still an IETF draft (draft ietf krb wg kerberos referrals 09 txt)

3) Standard krb5.conf/ini [domain_realm] mappings

- appears to be best supported by various products
- pain to deploy in large environments


Thoughts? Suggestions? Is this on the Kerberos-wg plan?
--------------------------------------------------------

This message w/attachments (message) may be privileged, confidential or
proprietary, and if you are not an intended recipient, please notify the
sender, do not use or share it and delete it. Unless specifically
indicated, this message is not an offer to sell or a solicitation of any
investment products or other financial product or service, an official
confirmation of any transaction, or an official statement of Merrill
Lynch. Subject to applicable law, Merrill Lynch may monitor, review and
retain e-communications (EC) traveling through its networks/systems. The
laws of the country of each sender/recipient may impact the handling of
EC, and EC may be archived, supervised and produced in countries other
than the country in which you are located. This message cannot be
guaranteed to be secure or error-free. This message is subject to terms
available at the following link:
http://www.ml.com/e-communications_terms/. By messaging with Merrill
Lynch you consent to the foregoing.
--------------------------------------------------------

No, I don't consent to any of this and by replying I don't automatically
give my consent, nor will I go and look at that URL. This is a public
mailing list so I can't even tell whether or not I'm even the intended
recipient. What I do with a message that you send me is my business and
you have no right to dictate what I do with it.

Danny
.



Relevant Pages

  • Standard mechanisms to manage domain->realm mappings in multi-domain infrastructure
    ... What are the preferred mechanisms to manage DNS domain to Kerberos Realm ... KDC returns referrals to client when request made to local environment ... Still an IETF draft ...
    (comp.protocols.kerberos)
  • Re: Kerberos Issue
    ... the Kerberos Key for the PDC System Account was ... Kerberos through the System Account, ... zones off Active Directory), DHCP (Unable to communicate with DNS), CertSrv ... > as preferred dns servers and make sure that there are no ISP dns servers in ...
    (microsoft.public.windows.server.security)
  • Re: Kerberos Issue
    ... the Kerberos Key for the PDC System Account was ... > Kerberos through the System Account, ... > zones off Active Directory), DHCP (Unable to communicate with DNS), ... >> as preferred dns servers and make sure that there are no ISP dns servers ...
    (microsoft.public.windows.server.security)
  • Re: KRB_AP_ERR_MODIFIED Error on Windows2003 Server
    ... DNS problems can cause this error as well. ... attempting to contact systema so the Kerberos Key Distribution Center ... encrypts the service ticket with systema's password but poor DNS causes the ... KRB_AP_ERR_MODIFIED Error on Windows2003 Server ...
    (microsoft.public.windows.server.general)
  • Re: Working out a OS X 10.4 Tiger ssh implementation issue, slow logins
    ... port of the OpenSSH release; it has code added to it. ... order to construct a ticket request for the SSH server, ... for the ticket request instead of going to the DNS. ... client will try to find the Kerberos context for the server via the DNS ...
    (comp.security.ssh)

Loading