Skip to Content.
Sympa Menu

per-entity - Re: [Per-Entity] deploying TLS on the MDQ server

Subject: Per-Entity Metadata Working Group

List archive

Re: [Per-Entity] deploying TLS on the MDQ server


Chronological Thread 
  • From: Tom Scavo <>
  • To: "Cantor, Scott" <>
  • Cc: Tom Scavo <>, Per-Entity Metadata Working Group <>
  • Subject: Re: [Per-Entity] deploying TLS on the MDQ server
  • Date: Fri, 9 Sep 2016 09:53:21 -0400
  • Ironport-phdr: 9a23:VfiKmhZeWoCqo36NBijdg3r/LSx+4OfEezUN459isYplN5qZpsW8bnLW6fgltlLVR4KTs6sC0LWG9f27EjVdqb+681k8M7V0HycfjssXmwFySOWkMmbcaMDQUiohAc5ZX0Vk9XzoeWJcGcL5ekGA6ibqtW1aMlzFOAF0PuX4HJLJx4Tyjrjqus6bXwIdzhG0Z691NlH+lg7WqtVcyd9pI6AtzQGP+FNPYPkQyG91cwG9hRH5s/u3+dZY+C1OvLp169RbWqzkeIw5S6BVFjIrLzpz6cH240qQBTCT72cRBz1F2iFDBBLIuVSjBs/8

On Fri, Sep 9, 2016 at 9:40 AM, Cantor, Scott
<>
wrote:
> On 9/9/16, 9:31 AM,
> "
> on behalf of Tom Scavo"
> <
> on behalf of
> >
> wrote:
>
>> Can you be more specific about what you think is "tight enough?"
>
> I haven't thought about it, but in giving a little bit of consideration to
> it, I don't know if there is anything realistic that would help given the
> sort of attack I'm thinking of. Certainly hours at most, but really the
> attack just requires that the window between "it changed" and "it gets
> requested" is wider than real time. So I suppose I think TLS is basically a
> requirement in the end.
>
>> I'm not following you. On the production side, aggregates and entities
>> are identical since they emanate from the same infrastructure. On the
>> client side, request patterns are different, I realize that, but I
>> don't see how that influences validUntil. I think I'm missing something.
>
> The difference is in the knowledge the attacker has of when the request for
> the metadata might be made. Because it's an active attack, knowing when the
> request will be made is pretty significant in pulling something off that
> requires actively intercepting and changing/substituting a result.

Okay, putting both of those together, I conclude we need TLS on the
MDQ server to address your concern (and it has nothing to do with
validUntil). But what about the other scenario? What can/should we
provide to AD FS (which currently has no security options whatsoever)?

Tom



Archive powered by MHonArc 2.6.19.

Top of Page