ad-assurance - RE: [AD-Assurance] Protected Channels and the IAP
Subject: Meeting the InCommon Assurance profile criteria using Active Directory
List archive
- From: "Capehart,Jeffrey D" <>
- To: "" <>
- Subject: RE: [AD-Assurance] Protected Channels and the IAP
- Date: Wed, 15 May 2013 13:15:01 +0000
- Accept-language: en-US
- Authentication-results: sfpop-ironport01.merit.edu; dkim=neutral (message not signed) header.i=none
Although it seems like it should be straightforward to determine whether any particular type of communications is over a network or local to a particular system,
sometimes it is not obvious just from the name, or from what IT tells you. As an example, if you have three separate domain controllers, and they communicate amongst themselves with password changes, then that is over the network.
For Active Directory, they have to be on the network to do their job and they have to be accessible. But, if there is some communications channel where passwords are synchronized and that channel isn’t a protected channel, then that could be a problem. However,
encrypting the secret would be OK, right? Well, as long as the box that the secret is decrypted on is the same one doing the synch/update, then yes it would be local (i.e. not network). Otherwise, if the process/protocol just unwraps the encryption and then
RPC’s it or Kerberizes it out to the other domain controllers, then we’re back to needing secure communication and most likely a protected channel. Does anyone see any allowance for the communications to be on the internal network being different than those outside the internal network? How about communications
behind a switch with all components physically on the same circuit that do not go outside the room/building? Both still qualify as “network” communications. Draw your own insight from NIST’s Glossary of Key Information Security Terms (NIST IR 7298 Rev 1) http://csrc.nist.gov/publications/nistir/ir7298-rev1/nistir-7298-revision1.pdf
Jeff From: [mailto:]
On Behalf Of David Walker Everyone, 4.2.5.3 (S) (B) SECURE COMMUNICATION (part of 4.2.5 AUTHENTICATION PROCESS)
|
- [AD-Assurance] Protected Channels and the IAP, David Walker, 05/14/2013
- RE: [AD-Assurance] Protected Channels and the IAP, Capehart,Jeffrey D, 05/15/2013
- RE: [AD-Assurance] Protected Channels and the IAP, Ron Thielen, 05/15/2013
- RE: [AD-Assurance] Protected Channels and the IAP, Capehart,Jeffrey D, 05/15/2013
Archive powered by MHonArc 2.6.16.