[2190] in Kerberos
Re: Existing authentication mechanisms have a deficiency
daemon@ATHENA.MIT.EDU (Stephen C. Trier)
Mon Sep 14 15:29:40 1992
Date: 14 Sep 92 17:29:57 GMT
From: trier@slc6.ins.cwru.edu (Stephen C. Trier)
To: kerberos@shelby.Stanford.EDU
In article <9209091614.AA15084@ocfmail.ocf.llnl.gov> nessett@OCFMAIL.OCF.LLNL.GOV (Danny Nessett) writes:
>One could imagine a system configured so that all on-machine authentication
>requests contacted the appropriate server, say the Kerberos server or
>SPX LEAF server, rather than looking in /etc/passwd for the user's
>encrypted password. Actually, I think SUN already does something like this
>by looking in the NIS...
If one is willing to look beyond Unix, this is more or less what is being
done in the MS-DOS and Macintosh worlds when Kerberos is installed. In
those environments, there exist no local user access controls, nor is it
clear that any such controls would be effective.
Kerberos can be integrated into the network software on such machines,
moving, as you suggest, all authentication information to a centralized
server. (I should say this is still a theoretical idea here because we
haven't gotten our DOS Kerberos working yet.)
NIS and similar systems are inappropriate for this sort of environment,
which is, I think, why so many people are interested in any news about
Kerberos or SPX for MS-DOS, MacOS, and Windows.
>My suggestion about modifying su to contact the appropriate server to
>perform authentication was along these lines.
I was recently attempting to figure out whether there was any use for
ksu on MS-DOS. :-) I still haven't decided -- I need to figure out
exactly what ksu does with TGTs before I decide whether we should port
it.
--
"Beware of programmers who Stephen Trier
carry screwdrivers." Network Services Engineering, IRIS/INS/Telecom
Leonard Brandwein Case Western Reserve University
trier@ins.cwru.edu