Hi Tim,
 
Thanks for the quick response, but concerning the sizes are we talking 500
bytes, 1k, 2k? Statically allocating 4k on an embedded system is a little
heavy so I'd like get a ballpark idea for the upper boudries on the reply
messages. 
 
What are the largest numbers you've seen?
 

Eric Naud

Software Development Engineer, Ottawa Design Center

Imedia Semiconductor

613.592.1052 x232

mailto:[EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]> 



 
----------------------------------------------------------------------------
-----


-----Original Message-----
From: Tim Alsop [mailto:[EMAIL PROTECTED]
Sent: July 21, 2003 11:27 AM
To: Naud, Eric; [EMAIL PROTECTED]
Subject: RE: Maximum AP and AS message sizes



Eric, 

You also need to consider : 

i) Whether IP addresses are stored in the tickets. In particular on a multi
homed system the number of addresses can be quite large.

ii) Whether the KDC is a Microsoft KDC because PAC data will be stored in
tickets. 

These, along with PKINIT requirements are the major contributors to large
tickets, and hence large request/response packets to/from the KDC.

Cheers, Tim. 

-----Original Message----- 
From: Naud, Eric [ mailto:[EMAIL PROTECTED]
<mailto:[EMAIL PROTECTED]> ] 
Sent: 21 July 2003 16:23 
To: [EMAIL PROTECTED] 
Subject: Maximum AP and AS message sizes 

Hi All, 

Can anyone tell me what the AP and AS message size maximums would be and
what factor are to be considered? 

I'm using PKINIT so I know my AS request will be rather large due to the
certificate. 

Thank! 

Eric Naud 
Software Development Engineer, Ottawa Design Center Imedia Semiconductor 
613.592.1052 x232 
mailto:[EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>  


________________________________________________ 
Kerberos mailing list           [EMAIL PROTECTED] 
https://mailman.mit.edu/mailman/listinfo/kerberos
<https://mailman.mit.edu/mailman/listinfo/kerberos>  

________________________________________________
Kerberos mailing list           [EMAIL PROTECTED]
https://mailman.mit.edu/mailman/listinfo/kerberos

Reply via email to