Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

Beam me up, Scotty, there's no intelligent life down here!


devel / comp.protocols.kerberos / Re: query about a possible "KRB5KEYLOGFILE" feature, to log session keys

SubjectAuthor
o Re: query about a possible "KRB5KEYLOGFILE" feature, to log session keysRichard E. Silverman

1
Re: query about a possible "KRB5KEYLOGFILE" feature, to log session keys

<mailman.66.1710733475.2322.kerberos@mit.edu>

  copy mid

https://www.rocksolidbbs.com/devel/article-flat.php?id=518&group=comp.protocols.kerberos#518

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: res@qoxp.net (Richard E. Silverman)
Newsgroups: comp.protocols.kerberos
Subject: Re: query about a possible "KRB5KEYLOGFILE" feature, to log session
keys
Date: Sun, 17 Mar 2024 23:44:28 -0400 (EDT)
Organization: TNet Consulting
Lines: 18
Message-ID: <mailman.66.1710733475.2322.kerberos@mit.edu>
References: <08dd4568-38a3-0137-35c7-4ea43647dad6@qoxp.net>
<076090ac-97d7-866d-fe6f-d13d156d892a@qoxp.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: quoted-printable
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="31622"; mail-complaints-to="newsmaster@tnetconsulting.net"
To: MIT Kerberos <kerberos@mit.edu>
DKIM-Filter: OpenDKIM Filter v2.11.0 unknown-host (unknown-jobid)
Authentication-Results: mailman.mit.edu;
dkim=pass (1024-bit key, unprotected) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.a=rsa-sha256
header.s=selector2-mitprod-onmicrosoft-com header.b=Xj/Ecypi;
dkim=pass (1024-bit key,
unprotected) header.d=pobox.com header.i=@pobox.com header.a=rsa-sha256
header.s=sasl header.b=XPXZPav/
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=Mc1rvzbmJv7QYD3mNygetnT6dxL9IkF+EA0EjEd69o+3CEtTF7Ze4dybNjqWkFNjWqQaMUa5Bx+9HmUe1AXuEmaEUSrA/LF/oXxA5kQQ0LLTwBlsBafrFNii+eqVQZk+X0FhvYQWx1oeXs1fErMIAi/zciJTfFt4GJpwg86dsr3Mgo5hpQQoXXKG+c9TXjeLz9mGvoQgzE8aDq5PQXVNEuRK4LYw7RAxFvN+FimcPorzeSaONskCzuQOMJ8Vy0xUE1xj2tnPbh9BMng2dbrOyJlkcStJX+RG+52MV4yuMvEil0IuAR8Vm3Y4EJuxQdnbCbH1rwr5jnvy5ZzOwKF9HQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=mKFPMn0Q5b28DxkEwmf37YRspeF+W5NOb1uBGqNGFuk=;
b=cCzzkzy9whBK91ae413VDXa2m+XqTgTWxp7SQzZrwf3JOYmvBgeKfVQhNtIYpqM1K8bGGNYfn5o2VS2emwILlBCF5V7x7oiamIBytvRmHddKnkEU7RMPxykzGI+ibgk9z/W3dUjSXbToVTYPCV1zGGaKwrZtlB8Ao4oKJ1k8inH0HLXRiGV6NcmQO+wMb4KsKWT/wTXtZklCmNtuI5Q0ESxlpIFwcRZu8OrgPXEyeGQPmS8vGfrf/7dFjqu7wclhBqqj949Ljqlq8m9fWM6SHNhQtDbYw6C2R5YNBa3U3OmjVg8YAWZVece28jCS9t7mpA93OlK7odQOEsfsQPgmmA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
64.147.108.70) smtp.rcpttodomain=mit.edu smtp.mailfrom=qoxp.net;
dmarc=bestguesspass action=none header.from=qoxp.net; dkim=pass (signature
was verified) header.d=pobox.com; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=mKFPMn0Q5b28DxkEwmf37YRspeF+W5NOb1uBGqNGFuk=;
b=Xj/EcypiQb2vRwtSmfPUx4oIKnWw0Myg2n171ZXgBlO9hfgcjIaTyuHpPvB9iH8N6s7ZgV5VcvaFHp2jn1rjP6k73ESxjcsbXyIekUerrYPrsa7jS1BmBiHs4ZlXSxEq3Cbh+ia+cB5rBdIINShBP03reUC/uqGNhj4O5pYhUHM=
Authentication-Results: spf=pass (sender IP is 64.147.108.70)
smtp.mailfrom=qoxp.net; dkim=pass (signature was verified)
header.d=pobox.com;dmarc=bestguesspass action=none header.from=qoxp.net;
Received-SPF: Pass (protection.outlook.com: domain of qoxp.net designates
64.147.108.70 as permitted sender) receiver=protection.outlook.com;
client-ip=64.147.108.70; helo=pb-smtp1.pobox.com; pr=C
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=pobox.com; h=date:from
:to:subject:in-reply-to:message-id:references:mime-version
:content-type; s=sasl; bh=fjfvpDEYXE1vXUIAeq4N8VykJJg7F7cT9ctz07
Ar7M4=; b=XPXZPav/Z2KpjuXFpVbE73nZvpdC55e0RLgrUkxwFBXc4TRc5alO3Z
FhS62VAkeMH3Z8yNmNkkg9Pbx/2BuPgqvfGI3ot4Ly+zh1O6Ia1c7ePm336O1zjR
t9QDv3mp9bcnGIJwTDSUKs6iyZCYcFGn4fFsOiNYpPnDQsAVx0M3A=
In-Reply-To: <08dd4568-38a3-0137-35c7-4ea43647dad6@qoxp.net>
X-Pobox-Relay-ID: D2CFD970-E4D9-11EE-80DB-78DCEB2EC81B-03079791!pb-smtp1.pobox.com
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: CH2PEPF00000149:EE_|DS7PR01MB7808:EE_
X-MS-Office365-Filtering-Correlation-Id: 2ca9ba42-f2fd-462e-730d-08dc46fdb7e2
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: SdvCUJ8ypAlBXwiCki2G/jtnH8ZRnB+6fgWyREDYiFk2zPWtsYHWXiraWT7eus5evBNW/8dPiATvSDPp5GhikhjSk+bfAIfJs0k1xjmI6YgdSiwzsQTaxQRjp91PEYb3EaNJskz5yZIq6ghubiODXXNf2rJR+GX5ioDRayMv+hxAalG9+FwS/cWalnqjB5Y0anP57W5oR7t1TJWF5xyDpAbYix5eAxKdrveKygpP1FQp+0d9iKBoDDj0StGxFyEyXBEMgEu6KsPpLIrYPIZeVyVGdVWzt2cYFu/+zp1fpTEiYyY5oNjfOPqowu7dyHpXyeucUEWyqtVH1RD80b7pvYg2InkDSoJPj1abHC4O6C4f091MEnV7VkkW3iJFGjtRUHxdGAjawmZLgcUCFtmYbU0vJ3pnj0pbUhArBlRyHKirub4hZ845mocdTlZIn3OTWqgmGRn35ayfAGMW53oSFKVEyoCiblvgg3FDi0xSMH6f+XmD+x2nM2OL9W+jcSccq/KJcn4Ti5z8mAu9K3CSShFGF7Stu4WaqVww0iiGKYTwE/2zqW2fhiZtV9SClrLRSBndbgr8BjsdMjM9n2lA9sIAzoX6oRtJTCmhYOTvkCKC8TWGQrjRbMeH4iQzjTxxvzSStnCQD5j5zu9LLFoEyWwJC9GhuSAlDoaIvV2IAScPGCJ+kh2bQevCLROjmuSZqP6aDi40hW+IuKgPPXo6REmgpgdN+XoPAhoyBqt59xX7oI4Mw+1FJXmxH5BZzFVe
X-Forefront-Antispam-Report: CIP:64.147.108.70; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:pb-smtp1.pobox.com; PTR:pb-smtp1.pobox.com; CAT:NONE;
SFS:(13230031)(376005)(61400799018)(48200799009); DIR:OUT; SFP:1102;
X-ExternalRecipientOutboundConnectors: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-OriginatorOrg: mitprod.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 18 Mar 2024 03:44:30.3946 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 2ca9ba42-f2fd-462e-730d-08dc46fdb7e2
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: CH2PEPF00000149.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DS7PR01MB7808
X-Content-Filtered-By: Mailman/MimeDel 2.1.34
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <076090ac-97d7-866d-fe6f-d13d156d892a@qoxp.net>
X-Mailman-Original-References: <08dd4568-38a3-0137-35c7-4ea43647dad6@qoxp.net>
 by: Richard E. Silverman - Mon, 18 Mar 2024 03:44 UTC

> 2. A client may not have access to the session keys in its ccache, e.g. if
> it’s using gssproxy.

Oops, sorry -- that’s a little off the mark. In that case of course session-key logging won’t help the client directly, since it doesn’t perform those operations or call libkrb5 itself at all; the gssproxy daemon does. In that case we’d apply KRB5KEYLOGFILE to the daemon. But there is a second reason nonetheless: it’s easier for debugging. A long-lived client process under observation could have its ccache flushed by ticket renewal or similar management, losing the needed session keys (and a mechanism like gssproxy could in fact have several ccaches it manages) -- whereas setting KRB5KEYLOGFILE would reliably capture them all without extra work.

--
Richard

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor