40 likes | 197 Views
One-Time Password Specifications (OTPS): Kerberos. Gareth Richards, RSA Security OTPS Workshop, February 2006. Overview. Proposal is to define extensions to Kerberos V5 (rfc4120) to support authentication using OTP. Possibly based on expired I-D draft-ietf-cat-kerberos-passwords-04
E N D
One-Time Password Specifications (OTPS): Kerberos Gareth Richards, RSA Security OTPS Workshop, February 2006
Overview • Proposal is to define extensions to Kerberos V5 (rfc4120) to support authentication using OTP. • Possibly based on expired I-D draft-ietf-cat-kerberos-passwords-04 • Proposed method: • Use OTP instead of password in pre-authentication data of AS-REQ. • OTP is validated by KDC by validating pre-auth data. • Possibly support PIN change using password change extensions (rfc3244)
KRB_AS_REQ KRB_ERROR with key identifier, challenge etc KRB_AS_REQ with OTP KRB_AS_REP Principle of Operation KDC Client
Next Steps • Is this idea worth pursuing?