FAST is a pre-authentication framework for Kerberos. It includes a mechanism for tunneling pre-authentication exchanges using armoured KDC messages. FAST provides increased resistance to passive passive password guessing attacks.
- Implement FAST and the appropriate timestamp mechanism that is standardardized by the working group.
- Provide a plugin interface so that third parties can write FAST factors.
- Implement Anonymous Pkinit
The plugin interface needs to be suitable to be a public API.
This design would need to cover the following elements:
How are host tickets obtained? Do we just use anonymous pkinit all the time or do we cache host tickets to use? If so, how is privilege separation handled?
API for plugin interface
The FAST proposal has not yet been approved by the IETF.