iya-sts
    Preparing search index...

    Kerberos FAST (RFC 6113), OTP pre-authentication (RFC 6560) and authentication indicators (RFC 8129 over RFC 7751) for the KDC's AS and TGS exchanges.

    The way in for a person a password alone will not do for: the password as the OTP PIN and an authenticator app code, inside a tunnel armored by a host's TGT. Reached by the KDC through the key source; it registers nothing.

    Index
    • Builds the FAST handler over the given dependencies.

      Parameters

      • deps: Krb5FastDeps

        the modules it uses

      Returns export=

    CHALLENGE_SCOPE: "krb5.encrypted-challenge" = CHALLENGE_SCOPE

    The claim scope an encrypted challenge's ciphertext is spent under, for the replay check.

    COOKIE_LIFETIME_MS: number = COOKIE_LIFETIME_MS

    How long a PA-FX-COOKIE, and so an OTP challenge's nonce, may be answered, in milliseconds.

    OTP_INDICATOR: "otp" = OTP_INDICATOR

    The authentication indicator an OTP pre-authentication puts in a ticket, otp.

    • Checks an encrypted challenge, the password factor inside FAST, with its replay check, and builds the KDC's half.

      Parameters

      • client: any

        the client principal

      • etype: number

        the etype asked for

      • pa: any

        the PA-ENCRYPTED-CHALLENGE

      • fast: FastState

        the exchange's FAST state

      Returns Promise<any>

      a promise of { ok: true, kdcPadata, etype }, or a refusal

    • Checks an OTP request: the nonce, then the PIN (the person's password, by the Kerberos key it derives), then the authenticator app code, spent once as at the sign-in screen.

      Parameters

      • client: any

        the client principal

      • etype: number

        the etype asked for

      • pa: any

        the PA-OTP-REQUEST

      • fast: FastState

        the exchange's FAST state

      Returns Promise<any>

      a promise of { ok: true, replyKey, indicators }, or a refusal

    • Builds an armored AS reply: the padata in an encrypted KrbFastResponse, a KrbFastFinished over the ticket, and a strengthened reply key.

      Parameters

      • opts: any

        the exchange's fast state, the replyKey, and what the reply is built from

      Returns Promise<any>

      a promise of { padata, replyKey }: the outer AS-REP's padata and the key its enc-part is sealed under

    • Says whether the armored request set hide-client-names.

      Parameters

      • fast: FastState

        the exchange's FAST state, or null

      Returns boolean

      whether it did

    • Builds a ticket's authentication indicators: an AD-AUTHENTICATION-INDICATOR in an AD-CAMMAC in AD-IF-RELEVANT, with a kdc-verifier and a svc-verifier.

      Parameters

      • opts: any

        indicators, kdcKey, serviceKey, and encodeTicketPart(ad), which encodes the EncTicketPart with ad as its authorization data

      Returns Promise<any[]>

      a promise of the AD entries, or [] for no indicators

    • Returns what a KDC_ERR_PREAUTH_REQUIRED offers inside FAST: the OTP challenge where the KDC asks for it, the encrypted challenge, and a sealed cookie.

      Parameters

      • client: any

        the client principal

      • fast: FastState

        the exchange's FAST state

      • opts: any

        otp, whether to offer OTP pre-authentication

      Returns Promise<any[]>

      a promise of the PA-DATA

    • Opens an armored AS-REQ: the AP-REQ armor, the armor key, and the KrbFastReq whose req-body and padata replace the outer ones.

      A refusal here is sent unarmored.

      Parameters

      • request: any

        the decoded AS-REQ

      • pa: any

        its PA-FX-FAST

      Returns Promise<any>

      a promise of { ok: true, fast, padata, reqBody }, or a refusal { ok: false, code, errorCode, eText }

    • Opens an armored TGS-REQ once its PA-TGS-REQ has verified, with the implicit armor of the Authenticator's subkey, or an explicit armor opened as in an AS-REQ.

      Parameters

      • pa: any

        the PA-FX-FAST

      • ctx: any

        { apReqBytes, ticketKey, subkey, realm, client }

      Returns Promise<any>

      a promise of the inner request, or a refusal

    • Returns what the KDC advertises outside FAST in every KDC_ERR_PREAUTH_REQUIRED: PA-FX-FAST with an empty value.

      Returns any

      the PA-DATA

    • Returns the client names for an outer, cleartext message: the anonymous principal under hide-client-names, the real ones otherwise.

      Parameters

      • fast: FastState

        the exchange's FAST state, or null

      • crealm: string

        the client's realm

      • cname: any

        the client's principal name

      Returns any

      { crealm, cname }

    • Describes what the KDC does with FAST in the ambient realm, for the console and the management API.

      Returns any

      the description

    • Reads the indicators a ticket carries; only a CAMMAC whose svc-verifier verifies under the ticket's key counts.

      Parameters

      • authorizationData: any[]

        the ticket's authorization data

      • ticketKey: Key

        the key the ticket is sealed with

      Returns Promise<any>

      a promise of { indicators, problem }; problem names a CAMMAC that did not verify

    • Armors a KRB-ERROR the KDC built: the error goes inside a KrbFastResponse as PA-FX-ERROR, and the outer error carries only PA-FX-FAST.

      Parameters

      • errorBytes: Uint8Array

        the KRB-ERROR

      • fast: FastState

        the exchange's FAST state

      Returns Promise<Uint8Array<ArrayBufferLike>>

      a promise of the outer KRB-ERROR

    • Returns the dependencies the key source builds this with, from the real modules.

      Returns Krb5FastDeps

      the dependencies