Skip to main content

7.1. Host Address Types

Overview

Host addresses in Kerberos tickets can restrict ticket usage to specific network locations. Various address types are defined to support different network protocols.

Defined Address Types

TypeValueDescription
IPv42Internet Protocol V4
Directional3Directional address
ChaosNet5ChaosNet address
XNS6Xerox Network Services
ISO7ISO protocols
DECNET Phase IV12DECnet Phase IV
AppleTalk DDP16AppleTalk DDP
NetBios20NetBios address
IPv624Internet Protocol V6

Usage

  • Address restrictions in tickets
  • Client address validation
  • Network location-based access control
  • Address-based ticket restrictions

Security Considerations

  • Addresses can be spoofed in some network environments
  • NAT and proxies complicate address-based restrictions
  • Modern deployments often use addressless tickets
  • Policy decisions should not solely rely on addresses

Reference

For complete list, refer to RFC 4120 Section 7.1.