[2236] in Kerberos
Re: Ticket Forwarding
daemon@ATHENA.MIT.EDU (Derek Atkins)
Wed Sep 30 17:27:48 1992
To: dean@ksr.com
Cc: kerberos@Athena.MIT.EDU, ramus@nersc.gov (Joe Ramus)
In-Reply-To: [2235] in Kerberos
Date: Wed, 30 Sep 92 16:55:42 EDT
From: Derek Atkins <warlord@MIT.EDU>
There is a program called 'rkinit' which one can use to create an
initial ticket on a remote machine. This requires you to have a
secure local connection, but you are already making that assumption.
You run rkinit and tell it the remote machine-name, a file-name,
principal, etc, and then it will connect to a special server (rkinitd,
which is run out of inetd) and will locally ask for your password, and
then it will encrypt the initial ticket (not your password) in the
session key and send it over. Actually, there are TWO (2) initial
ticket requests: one from the client (rkint) and one from the server
(rkinitd).
The sources are publically available (although they are not with the
kerberos source tree as ftp-able from athena-dist). I could put them
up for ftp if there is a need for it.
In other words, there is no need to re-invent the wheel? Why go out
and re-code what has already been implemented....
-derek
Derek Atkins -- MIT '93 -- Electrical Engineering
--warlord@MIT.EDU | ..!mit-eddie!mit-athena!warlord | s20069@mitvma.bitnet
Chairman, MIT Student Information Processing Board (SIPB)
MIT Media Laboratory, Speech Research Group