[2229] in Kerberos

home help back first fref pref prev next nref lref last post

Ticket Forwarding

daemon@ATHENA.MIT.EDU (Joe Ramus)
Wed Sep 30 00:26:40 1992

Date: Tue, 29 Sep 92 21:06:11 PDT
From: ramus@nersc.gov (Joe Ramus)
To: kerberos@Athena.MIT.EDU


This seems like an issue that would have been resolved already.
But I have not discovered the solution.  We are using Kerberos 4 and
we want to do "Authentication Forwarding".  I know that Kerberos 5 has
such a capability but we are not ready to use Kerberos 5.

Assume that Host A is my local workstation and I want to use Host B
because it has certain capabilities that I need for my task.  In order
to use the Host B capabilities that I want, I must login on Host B.
No problem.  I just authenticate on Host A and use the Kerberos version
of rlogin or telnet.

But now I do not have a ticket on Host B so if I want to use some
"Kerberized" service I have a dilemma.  I can authenticate on Host B
but that exposes my password over the net.  If available, I could use
a telnet that provides encrypted messages to login on Host B and get a
ticket.  Then I could either turn off the encryption mode (if possible)
or logout and come back with the regular clear text mode.

It seems like there is a "better" way and I would expect that some sites
have done this.  Suppose there is a special server on Host B and a client
on the original Host A.  Host A could send an encrypted message to Host B
with my password.  The server on B could then get a ticket for me and install
it in my private workspace.  Now I can use Host B in the usual way.

I would like to hear from anyone who has done this.
Or else, what is wrong with the idea.

  Joe Ramus  NERSC Livermore  (510) 423-8917   ramus@nersc.gov

home help back first fref pref prev next nref lref last post