[1714] in Kerberos
Re: protocol question
daemon@ATHENA.MIT.EDU (marantz@cs.rutgers.edu)
Thu Jan 16 12:53:22 1992
Date: Thu, 16 Jan 92 12:22:20 EST
From: marantz@cs.rutgers.edu
To: tytso@Athena.MIT.EDU
Cc: kerberos@Athena.MIT.EDU
In-Reply-To: <9201161635.AA03240@tsx-11.MIT.EDU> (tytso@athena.mit.edu)
I thought (now I see that isn't default, I'd need to set
ENC-TKT-IN-SKEY) that I could get the reply (or at least a part of it)
encrypted in my key which a bogus TGS shouldn't know. [If it does
know my key then I'm lost anyway] I'd use the encrypted stuff to
verify the TGS to me and then be able to believe the ticket for the
user.
Roy