Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

OS/2 must die!


devel / comp.protocols.kerberos / Re: Protocol benchmarking / auditing inquiry

SubjectAuthor
o Re: Protocol benchmarking / auditing inquiryKen Hornstein

1
Re: Protocol benchmarking / auditing inquiry

<mailman.22.1707948635.2322.kerberos@mit.edu>

  copy mid

https://www.rocksolidbbs.com/devel/article-flat.php?id=473&group=comp.protocols.kerberos#473

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: kenh@cmf.nrl.navy.mil (Ken Hornstein)
Newsgroups: comp.protocols.kerberos
Subject: Re: Protocol benchmarking / auditing inquiry
Date: Wed, 14 Feb 2024 17:10:24 -0500
Organization: TNet Consulting
Lines: 22
Message-ID: <mailman.22.1707948635.2322.kerberos@mit.edu>
References: <YT1PR01MB4187CA8C93DE6AC8560FB1BCFA4E2@YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM>
<YT1PR01MB418752C508C40187D7D88BC8FA4E2@YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM>
<ba168ba8-161d-47c1-82e2-edf4cba957c7@acm.org>
<YT1PR01MB418788B7045DF1E5B375143FFA4E2@YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM>
<202402142210.41EMAOpv030765@hedwig.cmf.nrl.navy.mil>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="13710"; mail-complaints-to="newsmaster@tnetconsulting.net"
To: "kerberos@mit.edu" <kerberos@mit.edu>
DKIM-Filter: OpenDKIM Filter v2.11.0 unknown-host (unknown-jobid)
Authentication-Results: mailman.mit.edu;
dkim=pass (1024-bit key, unprotected) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.a=rsa-sha256
header.s=selector2-mitprod-onmicrosoft-com header.b=QurZcDq4;
dkim=pass (2048-bit key,
unprotected) header.d=nrl.navy.mil header.i=@nrl.navy.mil header.a=rsa-sha256
header.s=s2.dkim header.b=DxJbADpl
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=dKyusF+K47QIslafQl1r5oRb3hrV9MAKkFjnFpHsEzL/TEEIDiRoCsItpTSb6CYKdF4+DXK/8wBRZhwPygCPWK4lCmAxdqUQG4Bs2LOgdpKXD7YCBYJhVsmjmnEKQ7zDhz1y53lrRAWKEFGkhvrpge9gAQgjpOA0aAZlvKgb4gWLSxYWf6zELdkl1tpRwshiWxFd2eE0Bdn+Uwfp4qsKGM8+KOirwCcgvwgOcfGE4gITvHuY/lEYrXxLexnGg3OKX5kmn9vR/d0JwnHu0bqHBcGHbxt5rXeGAlqCnjDZkz6muZmkUvpLavZEOjnIm0kAbNRkeHSVcu+RrMIfCWEr3w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=c2lAy1R2uqsQJ7PORrd/Zjq9+51TuMJGClFgLVio8cw=;
b=hIi4QpxFiJM4QkNJMohJC8/K1FRxsQhP5Q8kfYDdOlowZkL7rOgGCLryZdsMRduZFOa+0ZOVxkDyo0yVmrqIaFQBeICB7r7jMJjXc2z1fSQMfE8PlOPc+iHNA8/Wbz7wFDFCEboTwIlEQoSjyDsDWYLag2WK9cI9bZ9BouxleDdvUIjOGgjxXTXb0Oz+tAfbR8NLqjfBKhczhSkCnrJLm9OIguwEBHwkChfFRCzELJZqYnob3XhWSXgjIlK7uUm7gJaO+9JOW+KzWJ8JFbEYns1PhMR+sGi61HGutzsHJOLUggEFi1DvYDE0kRIe5nB/yoOQVB8g1xc9c9VG+GmW8A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
140.32.61.234) smtp.rcpttodomain=mit.edu smtp.mailfrom=cmf.nrl.navy.mil;
dmarc=pass (p=reject sp=reject pct=100) action=none
header.from=cmf.nrl.navy.mil; dkim=pass (signature was verified)
header.d=nrl.navy.mil; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=c2lAy1R2uqsQJ7PORrd/Zjq9+51TuMJGClFgLVio8cw=;
b=QurZcDq4PjQfxechf3n9i4tbTmfPe66t03WbFTrioJmS8gM34p8uf7d363X/DF94YCIP5x6pt5enQrPbgha/K7IGk0+81RgO+FtO3y7AMu9WOQCjc2fB+1kiqsZaT1BVqSyxPAs6x0QQGB/h7fTcXHkFwtH4p3ZCV3Ftc6nn8/0=
Authentication-Results: spf=pass (sender IP is 140.32.61.234)
smtp.mailfrom=cmf.nrl.navy.mil; dkim=pass (signature was verified)
header.d=nrl.navy.mil;dmarc=pass action=none header.from=cmf.nrl.navy.mil;
Received-SPF: Pass (protection.outlook.com: domain of cmf.nrl.navy.mil
designates 140.32.61.234 as permitted sender)
receiver=protection.outlook.com; client-ip=140.32.61.234; helo=mf.dren.mil;
pr=C
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nrl.navy.mil;
h=message-id : from :
to : subject : in-reply-to : references : mime-version : content-type :
date; s=s2.dkim; bh=c2lAy1R2uqsQJ7PORrd/Zjq9+51TuMJGClFgLVio8cw=;
b=DxJbADplGOOPxT8rMltBHZGYCpi6bMjLNhPOhr96aU/0Db7OfL889nLjzrARKzLUMfhg
QAmxT/n68//gHpWFzMFTu3i5Z95W2iQEtZcc6neG1sRKSRC6yPDdlMHTiPWR0Ne04HdB
VOwYb7DPFBiNo431tSx05tLK2ShbMwtWDDQEGtkD13Yl3MAHthITcPZFcWNLbshqMN0V
83/cxtgqeSnQT1FVcWAKHRu/Gou2D+7Wj1tsRZosQ52c90U35c1tmUZ5xLOyOdTr8XOO
dyqRganTm77vFYKgTuxzelxDCdX6h/qx6V1pW8V0KIopS0mWWc9qeXwPG+tuzNGf7Ph6 bQ==
In-Reply-To: <YT1PR01MB418788B7045DF1E5B375143FFA4E2@YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM>
X-Face: "Evs"_GpJ]],xS)b$T2#V&{KfP_i2`TlPrY$Iv9+TQ!6+`~+l)#7I)0xr1>4hfd{#0B4
WIn3jU;bql;{2Uq%zw5bF4?%F&&j8@KaT?#vBGk}u07<+6/`.F-3_GA@6Bq5gN9\+s;_d
gD\SW #]iN_U0 KUmOR.P<|um5yP<ea#^"SJK;C*}fMI;Mv(aiO2z~9n.w?@\>kEpSD@*e`
X-NRLCMF-Spam-Score: () hits=0 User Authenticated
X-NRLCMF-Virus-Scanned:
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: DS1PEPF0001709D:EE_|DM4PR01MB7569:EE_
X-MS-Office365-Filtering-Correlation-Id: 267abf28-b6a4-4845-1b38-08dc2da9c087
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: Nqge00DoTru5emJcw8XmBxrxcyh9a7k6amXd1CpRuVZ7Z+Bvtmd44Hdc0TWxvBKxAy5TAki+YsorNEfYiUh1R5GOiPbM24wY6UqRMxmW54K5CTzlTmxo3+AAciSGTd3nLMBXysoWnj9RMlJwA89wF9AuBNFojANCIVZJYTg2127NGTWx4PwvAaDX2GxTHkWz9X6rOliY9q0dnZ0G7S7eVg3eb3v0Ac1KKfmTFsHDpO2oXb3vGvKPCERHAXoRB11DzjcuHhIseS9rYkQxFBN72AHWSAI8pOned0mEt36/e7ERN7a7O3dnDXHT8GmFOI7U28b/vMT6XRCACBv7TRtG7NkC8XfE06PObLfsTCNzBkvIZEAmHMbMQ2b4L//b3Iv23tEowZG5LZfypT7xSsRWwYuLf9ITSJ1wyDpAq+Z5zYDPESY15GYADEib9vKBsfJRuyQIwu4aBY79Qug6VTgvekYtMmK7vnWQpLVhYJWF1HK6hAx0bmHPMNnaEPptoNZwa7S4SM9oK0/MqFXESomadrcnaZzZXWQlSaQZWIPIYctKak5q9L287qSRkM6Nba7QhoEE8vMZ5Q4DLJ6C+bwd7/abV7hoFiBR8E/4KFgIsHDduH8OMCQNsIarvmn/5tXWuEtqw1kAzSbI24YAcJXGO/V+N+ZDIiYfjRbUCxyrAr682NDZwgpVkteObYPC8+fI
X-Forefront-Antispam-Report: CIP:140.32.61.234; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:mf.dren.mil; PTR:mfw.dren.mil; CAT:NONE;
SFS:(13230031)(4636009)(39860400002)(346002)(136003)(396003)(376002)(451199024)(48200799006)(64100799003)(61400799015)(3613699003)(2906002)(86362001)(7636003)(956004)(356005)(6862004)(316002)(498600001)(26005)(336012)(786003)(426003)(1076003)(83380400001)(8676002)(5660300002)(68406010)(70586007);
DIR:OUT; SFP:1102;
X-ExternalRecipientOutboundConnectors: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-OriginatorOrg: mitprod.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 14 Feb 2024 22:10:28.0226 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 267abf28-b6a4-4845-1b38-08dc2da9c087
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: DS1PEPF0001709D.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM4PR01MB7569
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <202402142210.41EMAOpv030765@hedwig.cmf.nrl.navy.mil>
X-Mailman-Original-References: <YT1PR01MB4187CA8C93DE6AC8560FB1BCFA4E2@YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM>
<YT1PR01MB418752C508C40187D7D88BC8FA4E2@YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM>
<ba168ba8-161d-47c1-82e2-edf4cba957c7@acm.org>
<YT1PR01MB418788B7045DF1E5B375143FFA4E2@YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM>
 by: Ken Hornstein - Wed, 14 Feb 2024 22:10 UTC

>Minor comment the CIS Benchmark appears to have been written from the
>system administrator's frame of reference - not the network frame of
>reference (FoR). Typically, each frame of reference (FoR) needs to be
>audited. Hence the need for automation.

I can only say this:

- I've been doing Kerberos for a few decades (but I'm certainly not the
person with the most Kerberos experience on this list).
- I've done a ton of security accreditation work at my $DAYJOB, which
also involves Kerberos. As part of the accrediation work we (and
others) do automated scanning that includes the Kerberos servers
and this seems to satisfy the powers that be. Some of the scanning
seems to detect Kerberos but I am unclear how much it actually checks
for other than "Kerberos is found".
- I've used the aforementioned CIS Benchmark.
- I really have no clue what you mean by "frame of reference" in this
context, and this corresponds to no security accreditation or auditing
requirements I have ever encountered so I cannot provide any
suggestions; I'm really unclear what you are asking for.

--Ken

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor