[2190] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Existing authentication mechanisms have a deficiency

daemon@ATHENA.MIT.EDU (Stephen C. Trier)
Mon Sep 14 15:29:40 1992

Date: 14 Sep 92 17:29:57 GMT
From: trier@slc6.ins.cwru.edu (Stephen C. Trier)
To: kerberos@shelby.Stanford.EDU

In article <9209091614.AA15084@ocfmail.ocf.llnl.gov> nessett@OCFMAIL.OCF.LLNL.GOV (Danny Nessett) writes:
>One could imagine a system configured so that all on-machine authentication
>requests contacted the appropriate server, say the Kerberos server or
>SPX LEAF server, rather than looking in /etc/passwd for the user's
>encrypted password. Actually, I think SUN already does something like this
>by looking in the NIS...

If one is willing to look beyond Unix, this is more or less what is being
done in the MS-DOS and Macintosh worlds when Kerberos is installed.  In
those environments, there exist no local user access controls, nor is it
clear that any such controls would be effective.

Kerberos can be integrated into the network software on such machines,
moving, as you suggest, all authentication information to a centralized
server.  (I should say this is still a theoretical idea here because we
haven't gotten our DOS Kerberos working yet.)

NIS and similar systems are inappropriate for this sort of environment,
which is, I think, why so many people are interested in any news about
Kerberos or SPX for MS-DOS, MacOS, and Windows.

>My suggestion about modifying su to contact the appropriate server to
>perform authentication was along these lines.

I was recently attempting to figure out whether there was any use for
ksu on MS-DOS.  :-)  I still haven't decided -- I need to figure out
exactly what ksu does with TGTs before I decide whether we should port
it.

-- 
"Beware of programmers who     Stephen Trier
 carry screwdrivers."          Network Services Engineering, IRIS/INS/Telecom
       Leonard Brandwein       Case Western Reserve University
                               trier@ins.cwru.edu

home help back first fref pref prev next nref lref last post