[2158] in Kerberos

home help back first fref pref prev next nref lref last post

Re: New User Accounts

daemon@ATHENA.MIT.EDU (smb@ulysses.att.com)
Thu Sep 3 13:03:16 1992

From: smb@ulysses.att.com
To: socrates!socrates.bell-atl.com!ravi
Cc: kerberos@Athena.MIT.EDU
Date: Thu, 03 Sep 92 11:16:09 EDT

	 Dictionary attacks can eb stopped using the protocls developed
	 by li Gong et al, and by Bellovin & Merrit. Note that the
	 latter necessitates the use of public-key, and both have
	 (probably acceptable) an overhead.

Both protocols require public key cryptosystems.  One significant difference
is that the Lomas/Gong/Needham/Saltzer protocol requires a known public
key for the server, and the Bellovin/Merritt one does not.  Both require
high-quality random numbers.  Bellovin/Merritt imposes some possibly-tricky
constraints on what a public key can look like.


		--Steve Bellovin

home help back first fref pref prev next nref lref last post