SLIDE 1
Questioning Kerberos Assumptions
- Principal Names are not remapped in cross-realm
- The destination KDC is not involved in cross-realm
- Privacy of principal names
1
Questioning Kerberos Assumptions Sam Hartman IETF 63 Questioning - - PowerPoint PPT Presentation
Questioning Kerberos Assumptions Sam Hartman IETF 63 Questioning Kerberos Assumptions Principal Names are not remapped in cross-realm The destination KDC is not involved in cross-realm Privacy of principal names 1 Why Remap
1
2
3
vacy so that passive observers cannot know who is logging in.
.
4
5
6
tication as Microsoft PAC replaces the principal name
7
KDC.
8
9
account within an infrastructure.
cept.
10
11
12
added to TGTS.
13
14
15
16
17
is the core protocol impacted?
18