Builds the FAST handler over the given dependencies.
the modules it uses
Static ReadonlyCHALLENGE_The claim scope an encrypted challenge's ciphertext is spent under, for the replay check.
Static ReadonlyCOOKIE_How long a PA-FX-COOKIE, and so an OTP challenge's nonce, may be answered, in milliseconds.
Static ReadonlyOTP_The authentication indicator an OTP pre-authentication puts in a ticket,
otp.
Checks an encrypted challenge, the password factor inside FAST, with its replay check, and builds the KDC's half.
the client principal
the etype asked for
the PA-ENCRYPTED-CHALLENGE
the exchange's FAST state
a promise of { ok: true, kdcPadata, etype }, or a refusal
Checks an OTP request: the nonce, then the PIN (the person's password, by the Kerberos key it derives), then the authenticator app code, spent once as at the sign-in screen.
the client principal
the etype asked for
the PA-OTP-REQUEST
the exchange's FAST state
a promise of { ok: true, replyKey, indicators }, or a refusal
Builds an armored AS reply: the padata in an encrypted KrbFastResponse, a KrbFastFinished over the ticket, and a strengthened reply key.
the exchange's fast state, the replyKey, and what the
reply is built from
a promise of { padata, replyKey }: the outer AS-REP's padata and
the key its enc-part is sealed under
Says whether the armored request set hide-client-names.
the exchange's FAST state, or null
whether it did
Builds a ticket's authentication indicators: an AD-AUTHENTICATION-INDICATOR in an AD-CAMMAC in AD-IF-RELEVANT, with a kdc-verifier and a svc-verifier.
indicators, kdcKey, serviceKey, and
encodeTicketPart(ad), which encodes the EncTicketPart with ad as its
authorization data
a promise of the AD entries, or [] for no indicators
Returns what a KDC_ERR_PREAUTH_REQUIRED offers inside FAST: the OTP challenge where the KDC asks for it, the encrypted challenge, and a sealed cookie.
the client principal
the exchange's FAST state
otp, whether to offer OTP pre-authentication
a promise of the PA-DATA
Opens an armored AS-REQ: the AP-REQ armor, the armor key, and the KrbFastReq whose req-body and padata replace the outer ones.
A refusal here is sent unarmored.
the decoded AS-REQ
its PA-FX-FAST
a promise of { ok: true, fast, padata, reqBody }, or a refusal
{ ok: false, code, errorCode, eText }
Opens an armored TGS-REQ once its PA-TGS-REQ has verified, with the implicit armor of the Authenticator's subkey, or an explicit armor opened as in an AS-REQ.
the PA-FX-FAST
{ apReqBytes, ticketKey, subkey, realm, client }
a promise of the inner request, or a refusal
Returns what the KDC advertises outside FAST in every KDC_ERR_PREAUTH_REQUIRED: PA-FX-FAST with an empty value.
the PA-DATA
Returns the client names for an outer, cleartext message: the anonymous principal under hide-client-names, the real ones otherwise.
the exchange's FAST state, or null
the client's realm
the client's principal name
{ crealm, cname }
Describes what the KDC does with FAST in the ambient realm, for the console and the management API.
the description
Reads the indicators a ticket carries; only a CAMMAC whose svc-verifier verifies under the ticket's key counts.
the ticket's authorization data
the key the ticket is sealed with
a promise of { indicators, problem }; problem names a CAMMAC
that did not verify
Armors a KRB-ERROR the KDC built: the error goes inside a KrbFastResponse as PA-FX-ERROR, and the outer error carries only PA-FX-FAST.
the KRB-ERROR
the exchange's FAST state
a promise of the outer KRB-ERROR
StaticdefaultReturns the dependencies the key source builds this with, from the real modules.
the dependencies
Kerberos FAST (RFC 6113), OTP pre-authentication (RFC 6560) and authentication indicators (RFC 8129 over RFC 7751) for the KDC's AS and TGS exchanges.
The way in for a person a password alone will not do for: the password as the OTP PIN and an authenticator app code, inside a tunnel armored by a host's TGT. Reached by the KDC through the key source; it registers nothing.