Difference between revisions of "Projects/Audit"
Line 21: | Line 21: | ||
;Audit module loaded/unloaded: Startup and shutdown of the audit system must be recorded by audit system; |
;Audit module loaded/unloaded: Startup and shutdown of the audit system must be recorded by audit system; |
||
; KDC started/stopped |
; KDC started/stopped |
||
− | :KDC startup - KDC clockskew, list of realms and ports, location and names of the plugins, the values of allow_weak_crypto, kdc_req_sumtype, default_ap_req_sumtype and default_safe_sumtype from configuration files; |
||
+ | :KDC start-up. Basic information: List of KDC realms and corresponding ports on which the Kerberos server should listen for UDP and TCP requests, allowable amount of clockskew in seconds, location and names of the plugins, indicator whether weak encryption types are allowed; |
||
:KDC stopped - no additional information; |
:KDC stopped - no additional information; |
||
;AS exchange: |
;AS exchange: |
||
− | :kdc time timestamp,client's and server's flags and unparsed names, port number, ticket start, end and renew until times and flags, requested enckey types and used session enckey type, pre-auth type requested and used, KDC status message; |
||
+ | :Basic information: client principal name; requested service name, remote port; selected keytype for the ticket session key; KDC status message; |
||
+ | On success: tgt_id; returned ticket start, end and renew until times and ticket flags; |
||
;TGS exchange: |
;TGS exchange: |
||
:TGS |
:TGS |
||
− | ::Successful or unsuccessful attempt - kdc time and authtime timestamps, unparsed client, server, 2nd client and s4u names, port number, client's enckey types and flags, used session enckey type, is referral, is constrained delegation, is protocol transition, was ticket renewed, KDC status message; |
||
+ | ::Basic information: tgt_id, client principal name; requested service name, remote port; authtime timestamp; selected keytype for the ticket session key; KDC status message; if the request is for referral ticket indicate to which server; |
||
+ | ::On success: returned ticket start, end and renew until times and ticket flags; if the request was to renew ticket – indicate that ticket was renewed; |
||
:Alternative TGS |
:Alternative TGS |
||
− | ::Successful or unsuccessful attempt - kdc time and authtime timestamps, unparsed client, server and alternate server, KDC status message; |
||
+ | ::Basic information: tgt_id, client principal name; requested service name; authtime timestamp; KDC status message; |
||
+ | ::On success: alternate TGT |
||
:Cross-realm TGS |
:Cross-realm TGS |
||
− | ::Successful or unsuccessful attempt - kdc time and authtime timestamps, unparsed client, server, cross-realm, KDC status message; |
||
+ | ::Basic information: tgt_id, client principal name; requested service name, remote port; authtime timestamp; KDC status message; |
||
+ | ::On success: cross-realm tgt |
||
:U2U TGS |
:U2U TGS |
||
::Successful attempt - kdc time and authtime timestamps, unparsed client, server and second client, KDC status message |
::Successful attempt - kdc time and authtime timestamps, unparsed client, server and second client, KDC status message |
||
+ | :S4U extensions |
||
+ | ::Basic information: tgt_id, client principal name; requested service name; authtime timestamp; s4u extention type; KDC status message; |
||
+ | ::On success: s4u client name |
||
;Session keys: |
;Session keys: |
||
− | : AS and TGS exchange session key generation; |
||
+ | : AS and TGS exchange: tgt_id, client principal name; requested service name, remote port; authtime timestamp; keytype list in request and selected keytype for the ticket session key; |
||
− | : AS and TGS exchange session key cleaning; |
+ | : AS and TGS exchange: tgt_id, session key cleaning; |
;Policy: Policies violation when processing requests - TBD; |
;Policy: Policies violation when processing requests - TBD; |
||
:AS request |
:AS request |
||
Line 45: | Line 52: | ||
== Design details == |
== Design details == |
||
− | === |
+ | === KDC facing API === |
− | |||
− | /* Audit plugin vtable */ |
||
− | typedef struct krb5_audit_vtable_st { |
||
− | /* Mandatory: name of module. */ |
||
− | char *name; |
||
− | kau_open_fn open; |
||
− | kau_close_fn close; |
||
− | kau_kdc_start_fn kdc_start; |
||
− | kau_kdc_stop_fn kdc_stop; |
||
− | kau_as_req_fn as_req; |
||
− | kau_tgs_fn tgs; |
||
− | kau_tgs_alt_fn tgs_alt; |
||
− | kau_tgs_u2u_fn tgs_u2u; |
||
− | kau_tgs_xrealm_fn tgs_xrealm; |
||
− | kau_sesskey_as_generated_fn sesskey_as_generated; |
||
− | kau_sesskey_as_cleared_fn sesskey_as_cleared; |
||
− | kau_sesskey_tgs_generated_fn sesskey_tgs_generated; |
||
− | kau_sesskey_tgs_cleared_fn sesskey_tgs_cleared; |
||
− | kau_policy_as_req_fn policy_as_req; |
||
− | kau_policy_tgs_req_fn policy_tgs_req; |
||
− | kau_policy_s4u2proxy_req_fn policy_s4u2proxy_req; |
||
− | } *krb5_audit_vtable; |
||
− | |||
− | typedef krb5_error_code |
||
− | (*kau_open_fn)(krb5_context context , kau_ctx *au_ctx); |
||
− | |||
− | typedef krb5_error_code |
||
− | (*kau_close_fn)(krb5_context context, kau_ctx au_ctx); |
||
− | |||
− | typedef krb5_error_code |
||
− | (*kau_kdc_start_fn)(krb5_context context, kau_ctx au_ctx, |
||
− | krb5_deltat clockskew, const char *realm_port, |
||
− | krb5_boolean allow_weak_crypto, |
||
− | const char *plugins, const char *plugin_dir, |
||
− | krb5_cksumtype kdc_req_sumtype, |
||
− | krb5_cksumtype default_ap_req_sumtype, |
||
− | krb5_cksumtype default_safe_sumtype, int status); |
||
− | |||
− | typedef krb5_error_code |
||
− | (*kau_kdc_stop_fn)(krb5_context context, kau_ctx au_ctx, krb5_error_code status); |
||
− | |||
− | typedef krb5_error_code |
||
− | (*kau_as_req_fn)(krb5_context context, kau_ctx au_ctx, |
||
− | krb5_timestamp kdc_time, const char *kdc_status, |
||
− | const char *cname, const char *sname, |
||
− | krb5_flags c_flags, krb5_flags s_flags, |
||
− | int req_patype, const int from_port, |
||
− | const char *ktypes krb5_enctype sesskey_etype, |
||
− | krb5_flags tkt_flags, |
||
− | krb5_deltat tkt_start_time, krb5_deltat tkt_end_time, krb5_deltat tkt_renew_till, |
||
− | const char *tkt_cname, const int tr_type, int rep_patype, int status); |
||
− | |||
− | typedef krb5_error_code |
||
− | (*kau_tgs_fn)(krb5_context context, kau_ctx au_ctx, |
||
− | krb5_timestamp kdc_time, krb5_timestamp authtime, const char *status_msg, |
||
− | const char *cname, const char *sname, |
||
− | const char *altcname, const char *s4u_name, |
||
− | krb5_flags c_flags, krb5_flags s_flags, |
||
− | const int from_port, |
||
− | const char * ktypes_buf, krb5_enctype session_key_etype, |
||
− | const int tkt_renewed, |
||
− | const int is_referral, const int is_constrained, |
||
− | const int is_transition, int status); |
||
− | |||
− | typedef krb5_error_code |
||
− | (*kau_tgs_alt_fn)(krb5_context context, kau_ctx au_ctx, |
||
− | krb5_timestamp kdc_time, krb5_timestamp authtime, const char *kdc_status, |
||
− | const char *cname, const char *sname, |
||
− | krb5_flags c_flags, krb5_flags s_flags, |
||
− | const int from_port, const char *altsrv, int status); |
||
− | |||
− | typedef krb5_error_code |
||
− | (*kau_tgs_u2u_fn)(krb5_context context, kau_ctx au_ctx, |
||
− | krb5_timestamp kdc_time, krb5_timestamp authtime, const char *kdc_status, |
||
− | const char *cname, const char *sname, |
||
− | krb5_flags c_flags, krb5_flags s_flags, |
||
− | const int from_port, const char *cl2, int status); |
||
− | |||
− | typedef krb5_error_code |
||
− | (*kau_tgs_xrealm_fn)(krb5_context context, kau_ctx au_ctx, |
||
− | krb5_timestamp kdc_time, krb5_timestamp authtime, const char *kdc_status, |
||
− | const char *cname, const char *sname, |
||
− | krb5_flags c_flags, krb5_flags s_flags, |
||
− | const int from_port, const char *xrealm, int status); |
||
− | |||
− | typedef krb5_error_code |
||
− | (*kau_sesskey_as_generated_fn)(krb5_context context, kau_ctx au_ctx, |
||
− | krb5_timestamp kdc_time, const char *kdc_status, |
||
− | const char *cname, const char *sname, |
||
− | const int from_port, const char * ktypes, |
||
− | krb5_enctype used_ktype, int status); |
||
− | |||
− | typedef krb5_error_code |
||
− | (*kau_sesskey_as_cleared_fn)(krb5_context context, kau_ctx au_ctx, |
||
− | krb5_timestamp kdc_time, const char *kdc_status, |
||
− | const char *cname, const char *sname, |
||
− | const int from_port, krb5_enctype used_ktype,int status); |
||
− | |||
− | typedef krb5_error_code |
||
− | (*kau_sesskey_tgs_generated_fn)(krb5_context context, kau_ctx au_ctx, |
||
− | krb5_timestamp kdc_time, const char *kdc_status, |
||
− | const char *cname, const char *sname, |
||
− | const int from_port, |
||
− | const char *ktypes, krb5_enctype used_ktype, int status); |
||
− | |||
− | typedef krb5_error_code |
||
− | (*kau_sesskey_tgs_cleared_fn)(krb5_context context, kau_ctx au_ctx, |
||
− | krb5_timestamp kdc_time, const char *kdc_status, |
||
− | const char *cname, const char *sname, |
||
− | const int from_port, krb5_enctype used_ktype, int status); |
||
− | |||
− | === API signatures === |
||
/* Audit plugin loaded/unloaded */ |
/* Audit plugin loaded/unloaded */ |
||
Line 73: | Line 80: | ||
kau_tgs_u2u(krb5_context context, struct tgs_req_audit_state *state, |
kau_tgs_u2u(krb5_context context, struct tgs_req_audit_state *state, |
||
krb5_principal cl2, int status); |
krb5_principal cl2, int status); |
||
+ | krb5_error_code |
||
+ | kau_tgs_s4u(krb5_context context, struct tgs_req_audit_state *state, |
||
+ | krb5_error_code status); |
||
krb5_error_code |
krb5_error_code |
||
kau_tgs_xrealm(krb5_context context, struct tgs_req_audit_state *state, |
kau_tgs_xrealm(krb5_context context, struct tgs_req_audit_state *state, |
||
Line 108: | Line 118: | ||
struct tgs_req_audit_state { |
struct tgs_req_audit_state { |
||
krb5_kdc_req *request; |
krb5_kdc_req *request; |
||
⚫ | |||
krb5_timestamp authtime; |
krb5_timestamp authtime; |
||
char *sname, *cname,*s4u_name, *u2ucname; |
char *sname, *cname,*s4u_name, *u2ucname; |
||
Line 114: | Line 123: | ||
char *xrealm; |
char *xrealm; |
||
const krb5_fulladdr *from; |
const krb5_fulladdr *from; |
||
− | unsigned int c_flags |
+ | unsigned int c_flags; |
const char *status; /* KDC status message */ |
const char *status; /* KDC status message */ |
||
krb5_enctype useenctype; |
krb5_enctype useenctype; |
||
Line 121: | Line 130: | ||
}; |
}; |
||
+ | === Pluggable interface === |
||
+ | |||
+ | /* Audit plugin vtable */ |
||
+ | typedef struct krb5_audit_vtable_st { |
||
+ | /* Mandatory: name of module. */ |
||
+ | char *name; |
||
+ | kau_open_fn open; |
||
+ | kau_close_fn close; |
||
+ | kau_kdc_start_fn kdc_start; |
||
+ | kau_kdc_stop_fn kdc_stop; |
||
+ | kau_as_req_fn as_req; |
||
+ | kau_tgs_fn tgs; |
||
+ | kau_tgs_alt_fn tgs_alt; |
||
+ | kau_tgs_u2u_fn tgs_u2u; |
||
+ | kau_tgs_s4u_fn tgs_s4u; |
||
+ | kau_tgs_xrealm_fn tgs_xrealm; |
||
+ | kau_sesskey_as_generated_fn sesskey_as_generated; |
||
+ | kau_sesskey_as_cleared_fn sesskey_as_cleared; |
||
+ | kau_sesskey_tgs_generated_fn sesskey_tgs_generated; |
||
+ | kau_sesskey_tgs_cleared_fn sesskey_tgs_cleared; |
||
+ | kau_policy_as_req_fn policy_as_req; |
||
+ | kau_policy_tgs_req_fn policy_tgs_req; |
||
+ | kau_policy_s4u2proxy_req_fn policy_s4u2proxy_req; |
||
+ | } *krb5_audit_vtable; |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_open_fn)(krb5_context context , kau_ctx *au_ctx); |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_close_fn)(krb5_context context, kau_ctx au_ctx); |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_kdc_start_fn)(krb5_context context, kau_ctx au_ctx, |
||
+ | krb5_deltat clockskew, const char *realm_port, |
||
+ | krb5_boolean allow_weak_crypto, |
||
+ | const char *plugins, const char *plugin_dir, int status); |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_kdc_stop_fn)(krb5_context context, kau_ctx au_ctx, krb5_error_code status); |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_as_req_fn)(krb5_context context, kau_ctx au_ctx, |
||
+ | const char *cname, const char *sname, |
||
+ | const int from_port, krb5_enctype sesskey_etype, |
||
+ | krb5_flags tkt_flags, const char *tkt_cname, |
||
+ | krb5_deltat tkt_start_time, krb5_deltat tkt_end_time, krb5_deltat tkt_renew_till, |
||
+ | const char *kdc_status, int status); |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_tgs_fn)(krb5_context context, kau_ctx au_ctx, |
||
⚫ | |||
+ | const char *cname, const char *sname, |
||
+ | const int from_port, krb5_enctype session_key_etype, |
||
+ | const int is_referral, const int tkt_renewed, |
||
+ | krb5_flags tkt_flags, krb5_deltat tkt_start_time, |
||
+ | krb5_deltat tkt_end_time, krb5_deltat tkt_renew_till, |
||
+ | const char *kdc_status, int status); |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_tgs_alt_fn)(krb5_context context, kau_ctx au_ctx, |
||
+ | krb5_timestamp authtime, |
||
+ | const char *cname, const char *sname, const char *altsrv, |
||
+ | const int from_port, const char *kdc_status, int status); |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_tgs_u2u_fn)(krb5_context context, kau_ctx au_ctx, |
||
+ | krb5_timestamp authtime, |
||
+ | const char *cname, const char *sname, const char *cl2, |
||
+ | const int from_port, const char *kdc_status, int status); |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_tgs_s4u_fn)(krb5_context context, kau_ctx au_ctx, |
||
+ | krb5_timestamp authtime, |
||
+ | const char *cname, const char *sname, |
||
+ | const char * s4u_type, const char * s4u_name, |
||
+ | const int from_port, |
||
+ | const char *kdc_status, int status); |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_tgs_xrealm_fn)(krb5_context context, kau_ctx au_ctx, |
||
+ | krb5_timestamp authtime, |
||
+ | const char *cname, const char *sname, const char *xrealm, |
||
+ | krb5_flags c_flags, krb5_flags s_flags, |
||
+ | const int from_port, const char *kdc_status, int status); |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_sesskey_as_generated_fn)(krb5_context context, kau_ctx au_ctx, |
||
+ | const char *cname, const char *sname, |
||
+ | const int from_port, |
||
+ | const char * ktypes, krb5_enctype used_ktype, |
||
+ | const char *kdc_status, int status); |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_sesskey_as_cleared_fn)(krb5_context context, kau_ctx au_ctx, |
||
+ | const char *cname, const char *sname, |
||
+ | const int from_port, krb5_enctype used_ktype, |
||
+ | const char *kdc_status, int status); |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_sesskey_tgs_generated_fn)(krb5_context context, kau_ctx au_ctx, |
||
+ | const char *cname, const char *sname, |
||
+ | const int from_port, |
||
+ | const char *ktypes, krb5_enctype used_ktype, |
||
+ | const char *kdc_status, int status); |
||
+ | |||
+ | typedef krb5_error_code |
||
+ | (*kau_sesskey_tgs_cleared_fn)(krb5_context context, kau_ctx au_ctx, |
||
+ | const char *cname, const char *sname, |
||
+ | const int from_port, krb5_enctype used_ktype, |
||
+ | const char *kdc_status, int status); |
||
+ | |||
=== Configuration === |
=== Configuration === |
||
− | The following ./configure |
+ | The following ./configure option to be added: |
− | ;--enable-audit[=yes/no]: Enable audit plugin. By default at build time audit is disabled. |
||
;--with-audit-plugin=simple: (For demo and testing purposes) Build the audit plugin "simple" and enable audit plugin. |
;--with-audit-plugin=simple: (For demo and testing purposes) Build the audit plugin "simple" and enable audit plugin. |
||
=== Ticket ID === |
=== Ticket ID === |
||
− | We need to introduce the concept of ticket ID (perhaps, session key hash) that would allow to |
+ | We need to introduce the concept of ticket ID (perhaps, session key hash) that would allow to link tickets with the initial TGT. |
TODO. |
TODO. |
||
Revision as of 14:30, 28 October 2012
Contents
Purpose
The focus of this project will be on creating an Audit infrastructure within MIT Kerberos to monitor security related events on the KDC. The initial set of the audible events will be identified.
Requirements
The new audit system should be:
- build-time enabled;
- run-time pluggable;
- simple, so it could be easily replaced with the OS specific implementations;
- if possible, prepare i18n- and l10n-ready log messages.
Events
This section details the categories of the auditable events and the associated information.
- Audit module loaded/unloaded
- Startup and shutdown of the audit system must be recorded by audit system;
- KDC started/stopped
- KDC start-up. Basic information: List of KDC realms and corresponding ports on which the Kerberos server should listen for UDP and TCP requests, allowable amount of clockskew in seconds, location and names of the plugins, indicator whether weak encryption types are allowed;
- KDC stopped - no additional information;
- AS exchange
- Basic information: client principal name; requested service name, remote port; selected keytype for the ticket session key; KDC status message;
On success: tgt_id; returned ticket start, end and renew until times and ticket flags;
- TGS exchange
- TGS
- Basic information: tgt_id, client principal name; requested service name, remote port; authtime timestamp; selected keytype for the ticket session key; KDC status message; if the request is for referral ticket indicate to which server;
- On success: returned ticket start, end and renew until times and ticket flags; if the request was to renew ticket – indicate that ticket was renewed;
- Alternative TGS
- Basic information: tgt_id, client principal name; requested service name; authtime timestamp; KDC status message;
- On success: alternate TGT
- Cross-realm TGS
- Basic information: tgt_id, client principal name; requested service name, remote port; authtime timestamp; KDC status message;
- On success: cross-realm tgt
- U2U TGS
- Successful attempt - kdc time and authtime timestamps, unparsed client, server and second client, KDC status message
- S4U extensions
- Basic information: tgt_id, client principal name; requested service name; authtime timestamp; s4u extention type; KDC status message;
- On success: s4u client name
- Session keys
- AS and TGS exchange: tgt_id, client principal name; requested service name, remote port; authtime timestamp; keytype list in request and selected keytype for the ticket session key;
- AS and TGS exchange: tgt_id, session key cleaning;
- Policy
- Policies violation when processing requests - TBD;
- AS request
- TGS request
- S4U2PROXY request
Design details
KDC facing API
/* Audit plugin loaded/unloaded */ krb5_error_code load_audit_plugin(krb5_context context); krb5_error_code unload_audit_plugin(krb5_context context);
/* KDC started /stopped */ krb5_error_code kau_kdc_start(krb5_context context, int status); krb5_error_code kau_kdc_stop(krb5_context context, krb5_error_code status);
/* AS exchange: Successful or unsuccessful attempt */ krb5_error_code kau_as_req(krb5_context context, struct as_req_state *state, int status);
/* TGS exchange: Successful or unsuccessful attempt; alternative, u2u and cross-realm TGS */ krb5_error_code kau_tgs(krb5_context context, struct tgs_req_audit_state *state, int status); krb5_error_code kau_tgs_alt(krb5_context context, struct tgs_req_audit_state *state, int status); krb5_error_code kau_tgs_u2u(krb5_context context, struct tgs_req_audit_state *state, krb5_principal cl2, int status); krb5_error_code kau_tgs_s4u(krb5_context context, struct tgs_req_audit_state *state, krb5_error_code status); krb5_error_code kau_tgs_xrealm(krb5_context context, struct tgs_req_audit_state *state, char* xrealm, int status);
/* Session key generation and cleaning them up */ krb5_error_code kau_sesskey_as_generated(krb5_context context, struct as_req_state *state, int status); krb5_error_code kau_sesskey_as_cleared(krb5_context context, struct as_req_state *state, int status); krb5_error_code kau_sesskey_tgs_generated(krb5_context context, struct tgs_req_audit_state *state,int status); krb5_error_code kau_sesskey_tgs_cleared(krb5_context context, struct tgs_req_audit_state *state, int status);
/* Policy driven events - TBD */ krb5_error_code kau_policy_as_req(krb5_context context, struct as_req_state *state, krb5_error_code status); krb5_error_code kau_policy_s4u2proxy_req(krb5_context context, struct tgs_req_audit_state *state, krb5_db_entry *st_client, krb5_error_code status); krb5_error_code kau_policy_tgs_req(krb5_context context, struct tgs_req_audit_state *state, krb5_ticket *header_ticket, krb5_error_code status);
/* Name of audit module */ krb5_error_code kau_plugin_name(krb5_context context, char **name);
struct tgs_req_audit_state { krb5_kdc_req *request; krb5_timestamp authtime; char *sname, *cname,*s4u_name, *u2ucname; krb5_principal altprinc; char *xrealm; const krb5_fulladdr *from; unsigned int c_flags; const char *status; /* KDC status message */ krb5_enctype useenctype; krb5_boolean tkt_renewed; krb5_boolean is_referral; };
Pluggable interface
/* Audit plugin vtable */ typedef struct krb5_audit_vtable_st { /* Mandatory: name of module. */ char *name; kau_open_fn open; kau_close_fn close; kau_kdc_start_fn kdc_start; kau_kdc_stop_fn kdc_stop; kau_as_req_fn as_req; kau_tgs_fn tgs; kau_tgs_alt_fn tgs_alt; kau_tgs_u2u_fn tgs_u2u; kau_tgs_s4u_fn tgs_s4u; kau_tgs_xrealm_fn tgs_xrealm; kau_sesskey_as_generated_fn sesskey_as_generated; kau_sesskey_as_cleared_fn sesskey_as_cleared; kau_sesskey_tgs_generated_fn sesskey_tgs_generated; kau_sesskey_tgs_cleared_fn sesskey_tgs_cleared; kau_policy_as_req_fn policy_as_req; kau_policy_tgs_req_fn policy_tgs_req; kau_policy_s4u2proxy_req_fn policy_s4u2proxy_req; } *krb5_audit_vtable; typedef krb5_error_code (*kau_open_fn)(krb5_context context , kau_ctx *au_ctx); typedef krb5_error_code (*kau_close_fn)(krb5_context context, kau_ctx au_ctx); typedef krb5_error_code (*kau_kdc_start_fn)(krb5_context context, kau_ctx au_ctx, krb5_deltat clockskew, const char *realm_port, krb5_boolean allow_weak_crypto, const char *plugins, const char *plugin_dir, int status); typedef krb5_error_code (*kau_kdc_stop_fn)(krb5_context context, kau_ctx au_ctx, krb5_error_code status); typedef krb5_error_code (*kau_as_req_fn)(krb5_context context, kau_ctx au_ctx, const char *cname, const char *sname, const int from_port, krb5_enctype sesskey_etype, krb5_flags tkt_flags, const char *tkt_cname, krb5_deltat tkt_start_time, krb5_deltat tkt_end_time, krb5_deltat tkt_renew_till, const char *kdc_status, int status); typedef krb5_error_code (*kau_tgs_fn)(krb5_context context, kau_ctx au_ctx, krb5_timestamp authtime, const char *cname, const char *sname, const int from_port, krb5_enctype session_key_etype, const int is_referral, const int tkt_renewed, krb5_flags tkt_flags, krb5_deltat tkt_start_time, krb5_deltat tkt_end_time, krb5_deltat tkt_renew_till, const char *kdc_status, int status); typedef krb5_error_code (*kau_tgs_alt_fn)(krb5_context context, kau_ctx au_ctx, krb5_timestamp authtime, const char *cname, const char *sname, const char *altsrv, const int from_port, const char *kdc_status, int status); typedef krb5_error_code (*kau_tgs_u2u_fn)(krb5_context context, kau_ctx au_ctx, krb5_timestamp authtime, const char *cname, const char *sname, const char *cl2, const int from_port, const char *kdc_status, int status);
typedef krb5_error_code (*kau_tgs_s4u_fn)(krb5_context context, kau_ctx au_ctx, krb5_timestamp authtime, const char *cname, const char *sname, const char * s4u_type, const char * s4u_name, const int from_port, const char *kdc_status, int status); typedef krb5_error_code (*kau_tgs_xrealm_fn)(krb5_context context, kau_ctx au_ctx, krb5_timestamp authtime, const char *cname, const char *sname, const char *xrealm, krb5_flags c_flags, krb5_flags s_flags, const int from_port, const char *kdc_status, int status); typedef krb5_error_code (*kau_sesskey_as_generated_fn)(krb5_context context, kau_ctx au_ctx, const char *cname, const char *sname, const int from_port, const char * ktypes, krb5_enctype used_ktype, const char *kdc_status, int status); typedef krb5_error_code (*kau_sesskey_as_cleared_fn)(krb5_context context, kau_ctx au_ctx, const char *cname, const char *sname, const int from_port, krb5_enctype used_ktype, const char *kdc_status, int status); typedef krb5_error_code (*kau_sesskey_tgs_generated_fn)(krb5_context context, kau_ctx au_ctx, const char *cname, const char *sname, const int from_port, const char *ktypes, krb5_enctype used_ktype, const char *kdc_status, int status); typedef krb5_error_code (*kau_sesskey_tgs_cleared_fn)(krb5_context context, kau_ctx au_ctx, const char *cname, const char *sname, const int from_port, krb5_enctype used_ktype, const char *kdc_status, int status);
Configuration
The following ./configure option to be added:
- --with-audit-plugin=simple
- (For demo and testing purposes) Build the audit plugin "simple" and enable audit plugin.
Ticket ID
We need to introduce the concept of ticket ID (perhaps, session key hash) that would allow to link tickets with the initial TGT. TODO.
Test implementation
We will use libaudit module available on Fedora, Debian, Suse for the first round.
Some "simple" audit plugin will be implemented and Python test system will become aware of its existence. New ./configure --with-audit-plugin option will be introduced to build "simple" audit plugin for testing purpose. If audit is enabled and audit plugin is available, "make check" will store audit messages into audit log file.
References
- Common Criteria for Information Technology Security Evaluation http://www.commoncriteriaportal.org/files/ccfiles/CCPART2V3.1R4.pdf
- Oracle Solaris Auditing http://docs.oracle.com/cd/E19963-01/html/821-1456/auditov-1.html
- Understanding Linux Audit http://doc.opensuse.org/products/draft/SLES/SLES-security_sd_draft/cha.audit.comp.html
- Advanced Security Audit Policy Settings http://technet.microsoft.com/en-us/library/dd772712(v=ws.10).aspx
- Events Classification in Log Audit http://airccse.org/journal/nsa/0410ijnsa5.pdf