Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

Chemist who falls in acid will be tripping for weeks.


devel / comp.protocols.kerberos / Re: Looking for a "Kerberos Router"?

SubjectAuthor
o Re: Looking for a "Kerberos Router"?Yoann Gini

1
Re: Looking for a "Kerberos Router"?

<mailman.51.1710347544.2322.kerberos@mit.edu>

  copy mid

https://news.novabbs.org/devel/article-flat.php?id=1119&group=comp.protocols.kerberos#1119

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: yoann.gini@gmail.com (Yoann Gini)
Newsgroups: comp.protocols.kerberos
Subject: Re: Looking for a "Kerberos Router"?
Date: Wed, 13 Mar 2024 17:32:18 +0100
Organization: TNet Consulting
Lines: 20
Message-ID: <mailman.51.1710347544.2322.kerberos@mit.edu>
References: <CD4C5157-C1DF-4AAB-9DA1-F54FEF928266@gmail.com>
<202403131416.42DEGRub016309@hedwig.cmf.nrl.navy.mil>
<581276BD-9D29-4D8C-A23E-8613493E378B@gmail.com>
<202403131452.42DEqTwP016604@hedwig.cmf.nrl.navy.mil>
<4DF7F808-676D-4226-AE6F-034995094DAC@gmail.com>
<202403131507.42DF7PwP016768@hedwig.cmf.nrl.navy.mil>
<31CAD52C-40A9-4C1B-B411-4957DB414ED3@gmail.com>
<202403131621.42DGLZEE017497@hedwig.cmf.nrl.navy.mil>
<08C219DB-7B64-48FD-A500-3A043BDED825@gmail.com>
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.500.171.1.1\))
Content-Type: text/plain;
charset=utf-8
Content-Transfer-Encoding: quoted-printable
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="12960"; mail-complaints-to="newsmaster@tnetconsulting.net"
Cc: kerberos@mit.edu
To: Ken Hornstein <kenh@cmf.nrl.navy.mil>
DKIM-Filter: OpenDKIM Filter v2.11.0 unknown-host (unknown-jobid)
Authentication-Results: mailman.mit.edu;
dkim=pass (1024-bit key, unprotected) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.a=rsa-sha256
header.s=selector2-mitprod-onmicrosoft-com header.b=i6cAFMIE;
dkim=pass (2048-bit key,
unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256
header.s=20230601 header.b=OTVKdEs+
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=GVtm8ueDbOPUUr9vek0s+FhhsxSztHszuygJuarduITUpbW6PC4Ch4+uo6NO/UQCJbMsohcrcKc6vMXNIlpiDT93AXEzxHkToD2p5FT77k/+4ttWKcUDrteQ1zdOsnQLIDpQhIPvQvdBLOfALfmX0lGc5IxNl6zfADT7w5r+IIDKNFBYcPHTEbkub9k0KGBmuhfIb/ha9yVNuPGOVFdkAo8p0tZMF6hZILLXgHyzGpFHKA7JIKbPluP9ZAk5RBEvK83Iobs6K6BBee2hGGC5lcm0/uB35edcPTqPZoJ5wJmbBzJrRxMg0LMt6WMo6P5okyes9DT26xl+8HB+mhg5dg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=fobfXEF5DMSLVR+V3N17PVqeMjplQDESvZxy+XPPBsY=;
b=EpyrXTkhsGyzoc70rAL3rnDQzM0WwreQxLjaBlnFMJdZN/0YCTiuiIScy1+M3yquU+YyjcdMbXxCKWn1qrvB6tJAwDZr2c/SSqLO1BmdJiIcd3IxLXIxCFwfeK4BMnvUXS1BZyBtGr8yTvoKDYMmPNa55ou2EnzOpGx4XSStGm2OTJMzr0A1sro7nzyY3W7RiX5jTQfJ7+XoB16Vap4tGsI/6gXvAw2wXqpF4uYHcsgOtTf9euX+47M6BI3exqYwYB2HIqiJ0A8r+Q/KFqSglEJlReRUKxX6iWgRk8yWA0igXs/m67k9o0X3g9ViB/veZNQXAAVZf/NEd8hjOv66Yw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
209.85.221.52) smtp.rcpttodomain=mit.edu smtp.mailfrom=gmail.com; dmarc=pass
(p=none sp=quarantine pct=100) action=none header.from=gmail.com; dkim=pass
(signature was verified) header.d=gmail.com; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=fobfXEF5DMSLVR+V3N17PVqeMjplQDESvZxy+XPPBsY=;
b=i6cAFMIEEJyk3CECgZvNQy/QzAnc96J9g1RWPxGGXx8HaBI51RaX3IhB/elK/v6KGKc+DGmcEkJJ7mrz1z83cDmQJRHJHfd7jWb1JJtqBaNI7RcaB11ZvhyvHIpNRbqWtUS7VsujBLm77NIBmUmDgUDFH1ahSD7m+KdVcLAo/+A=
Authentication-Results: spf=pass (sender IP is 209.85.221.52)
smtp.mailfrom=gmail.com; dkim=pass (signature was verified)
header.d=gmail.com;dmarc=pass action=none header.from=gmail.com;
Received-SPF: Pass (protection.outlook.com: domain of gmail.com designates
209.85.221.52 as permitted sender) receiver=protection.outlook.com;
client-ip=209.85.221.52; helo=mail-wr1-f52.google.com; pr=C
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20230601; t=1710347540; x=1710952340; darn=mit.edu;
h=references:to:cc:in-reply-to:date:subject:mime-version:message-id
:from:from:to:cc:subject:date:message-id:reply-to;
bh=fobfXEF5DMSLVR+V3N17PVqeMjplQDESvZxy+XPPBsY=;
b=OTVKdEs+cxQgQZoxI6YOXqy75n/O+Eq9Ej7EKJfQYgQoXIB5V9HJo4k+JIqzTAlDpe
6fg1vy1R81zpYVKY7YsAkVQqA4bBid3D3SRgruf5vu96R2jBLuL31fVRuCFId6b7+X87
paiFU/gq/4+s0VMtTsdaKgslEk7isZCoi7/rTU35kd+Qb+gKrwIy5TOM967XKKC1pgBC
eGwKPYRYoNf1PwyzU10nyhZ4O1CjGi/iwTBUykeGI6WfFRtdLYbfgMHgol3NZzE5tT6Y
vWMdDrx3MdYVqclCAeItssXBbvqB3ZieH/+5hZGeTHhhzoWb9HGnUYwRtIQfQovyqINm
rbWg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1710347540; x=1710952340;
h=references:to:cc:in-reply-to:date:subject:mime-version:message-id
:from:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=fobfXEF5DMSLVR+V3N17PVqeMjplQDESvZxy+XPPBsY=;
b=KfevihJHf9JN70MX09bo3NTonclpD3Hwh1SAsNkGieu4OjNc2YM/teDKaR31CUGbdH
j7UO8FILy+6Nk4AuejGz7Ed/0n76s9tvRL7GaHJdy3P16WMazf4etXMicVEd9m/AvBRM
awkZvX/8SUXw+AhacHlksE8ibWiHnsAZXJxtVmiKcdLwzpxM+ibp69KnCJK/uXfXSgVg
CILTwqj0XLB7TPg+aSQ0m7HUO7fYu+1Y5sPest3dW+x386GEL5ZSCRixcmfTkS7tj5Hl
xTVnU2h3ZbpcNUfElZZrKC5j0347lsk/AR9OnbKRtCCPwi+EikapbaXjHW2LiUaRFqWf
niiw==
X-Gm-Message-State: AOJu0Yy6f0CONLMVaR/LwO6uC8PFJJqB79SbHPbz2CQ4/uU7JQlNCj4H
Y57MPQXy9u2smL5nn1ODKCyNdE8fLXe9bFVE2z2T2rv/e8SdRnVDCeyQ5/09cmA=
X-Google-Smtp-Source: AGHT+IEZmCsc7Op0m28x8IaxDzhe5eqPdRjK5VS9uNhOyqMeXkmqdmMr/ZxBzI4RigPl399hBYlZ9Q==
X-Received: by 2002:adf:e492:0:b0:33e:bfd2:24cc with SMTP id
i18-20020adfe492000000b0033ebfd224ccmr713334wrm.31.1710347539558;
Wed, 13 Mar 2024 09:32:19 -0700 (PDT)
In-Reply-To: <202403131621.42DGLZEE017497@hedwig.cmf.nrl.navy.mil>
X-Mailer: Apple Mail (2.3774.500.171.1.1)
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: BN3PEPF0000B371:EE_|PH7PR01MB8199:EE_
X-MS-Office365-Filtering-Correlation-Id: 0ab1f254-6777-4572-4555-08dc437b27e4
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: zTTm4bbTVDFrkowCYAH2XO1WPO1n761TjiI4Hp4TPBzUQW51oZ+gz6atiB2P0JcKTEBDRWyO+AFNAkT0Qzm8+pUe/qiKPNKnhFFUBu7RoJUUWSYTeHftuYu1atKUSmYvlmOIp59AL3HSVjtp44T+lmuf3EcyIIaX6oU8wo0L2eMy32moD2/92pp2MesOLVgzCWF8/R+34cMKMhgu+tUvfUaF4rg8kiKulB71wPUOBBZ5w/3Fxn+iYVDe1EZhA2fkGISI97q0Z/j2Ayv9gnWoGfVtqqDnAyOlfWxAQ4zpa4uhYRpNCFQKEvFGkjzm3yoeQn1muZ5XMqopJPoX27k2C4RvF/Ru1uOEcpIuvNEJ0TXDKFxPizQWFJM6hoE/g/s6JOv8bnzd180IkCsUQumt0KYlJO5TEmGW7RDGV+0oU4mzOm5iHhQ3lQAh1nVFeHcrsVs7icX1dtfdKGguisBskYQXgHJJhwj/Pd9xBnxe9RbfJq8ce6EbWe9LObxlam0e9FLNh3V7xzqpQp4MpyEPrBC/uuzA+4S/+z/k/Hc5JFlYkCJX7feYzg8ri1w8DGTuobz/q+ZsGcAsfc3xntCHG9K4lkq80zHRJk1El5e5F68wPK9wA9zq3OmchiXtp4h19VOUkXu8pdYDKYlyMVlPhcZ5gwgE+kVUWSJbKkVH7dVIvkETUB41MpQlL/wpEPSkeRxO0hXFnC5ZaWf0HmunJg==
X-Forefront-Antispam-Report: CIP:209.85.221.52; CTRY:; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:mail-wr1-f52.google.com; PTR:mail-wr1-f52.google.com;
CAT:NONE; SFS:(13230031)(61400799018)(376005); DIR:OUT; SFP:1102;
X-ExternalRecipientOutboundConnectors: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-OriginatorOrg: mitprod.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 13 Mar 2024 16:32:20.8921 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 0ab1f254-6777-4572-4555-08dc437b27e4
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF0000B371.namprd21.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH7PR01MB8199
X-Content-Filtered-By: Mailman/MimeDel 2.1.34
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <08C219DB-7B64-48FD-A500-3A043BDED825@gmail.com>
X-Mailman-Original-References: <CD4C5157-C1DF-4AAB-9DA1-F54FEF928266@gmail.com>
<202403131416.42DEGRub016309@hedwig.cmf.nrl.navy.mil>
<581276BD-9D29-4D8C-A23E-8613493E378B@gmail.com>
<202403131452.42DEqTwP016604@hedwig.cmf.nrl.navy.mil>
<4DF7F808-676D-4226-AE6F-034995094DAC@gmail.com>
<202403131507.42DF7PwP016768@hedwig.cmf.nrl.navy.mil>
<31CAD52C-40A9-4C1B-B411-4957DB414ED3@gmail.com>
<202403131621.42DGLZEE017497@hedwig.cmf.nrl.navy.mil>
 by: Yoann Gini - Wed, 13 Mar 2024 16:32 UTC

> Le 13 mars 2024 à 17:21, Ken Hornstein <kenh@cmf.nrl.navy.mil> a écrit :
>
> It does occur to me that maybe if you have different KDC hostnames but
> the same IP address you could use TLS SNI or hostname routing which
> you indicated you already use and maybe that would be simpler? That
> presumes the client implementations set the SNI field (I see that it
> does send a "Host" header, and it looks like MIT Kerberos does set the
> SNI hostname).

This is what I have in mind looking at the documentation of kkdcp (reading as exchanging here). Using SNI to select the KDC.

I will give it a try, it looks like the option I need here.

And yes, all of those complexities would have been avoided by network teams just supporting IPv6 and not blocking random ports for no reasons…

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor