[1182] in Kerberos

home help back first fref pref prev next nref lref last post

Questions about ksu

daemon@ATHENA.MIT.EDU (Oren L. Stern)
Sat Dec 15 13:27:56 1990

Date: 15 Dec 90 17:31:49 GMT
From: nero@eng.umd.edu (Oren L. Stern)
To: kerberos@shelby.Stanford.EDU

Someone please correct me on ksu...

If you rlogin to a machine and then ksu, you are typing the password in the
clear over the network.  I'm told that the way around this is to ksu and
then rlogin.  However, to do this, you need to set up your pty's as secure
in /etc/ttytab.  I'm also told that this isn't the most secure way to set
up your system.  Is there no alternative, or have I just got my system
misconfigured?

Also, a question about the design of ksu.  Is there any reason that it doesn't
fork off a process to do a kdestroy when you leave the shell like login.krb
does?  Everyone here is having the hardest time remembering to kdestroy...

--
Oren Stern (nero@eng.umd.edu)	| "A boy without mischief is like a bowling ball
UUCP:  uunet!eng.umd.edu!nero  	|  without a liquid center" -- Homer Simpson

home help back first fref pref prev next nref lref last post