[2229] in Kerberos
Ticket Forwarding
daemon@ATHENA.MIT.EDU (Joe Ramus)
Wed Sep 30 00:26:40 1992
Date: Tue, 29 Sep 92 21:06:11 PDT
From: ramus@nersc.gov (Joe Ramus)
To: kerberos@Athena.MIT.EDU
This seems like an issue that would have been resolved already.
But I have not discovered the solution. We are using Kerberos 4 and
we want to do "Authentication Forwarding". I know that Kerberos 5 has
such a capability but we are not ready to use Kerberos 5.
Assume that Host A is my local workstation and I want to use Host B
because it has certain capabilities that I need for my task. In order
to use the Host B capabilities that I want, I must login on Host B.
No problem. I just authenticate on Host A and use the Kerberos version
of rlogin or telnet.
But now I do not have a ticket on Host B so if I want to use some
"Kerberized" service I have a dilemma. I can authenticate on Host B
but that exposes my password over the net. If available, I could use
a telnet that provides encrypted messages to login on Host B and get a
ticket. Then I could either turn off the encryption mode (if possible)
or logout and come back with the regular clear text mode.
It seems like there is a "better" way and I would expect that some sites
have done this. Suppose there is a special server on Host B and a client
on the original Host A. Host A could send an encrypted message to Host B
with my password. The server on B could then get a ticket for me and install
it in my private workspace. Now I can use Host B in the usual way.
I would like to hear from anyone who has done this.
Or else, what is wrong with the idea.
Joe Ramus NERSC Livermore (510) 423-8917 ramus@nersc.gov