[22452] in Kerberos

home help back first fref pref prev next nref lref last post

Kerberos lockout after X failed tgs/tgt attempts

daemon@ATHENA.MIT.EDU (Paul M Fleming)
Tue Sep 14 19:39:58 2004

Message-ID: <41460B55.BED58558@siumed.edu>
Date: Mon, 13 Sep 2004 16:04:21 -0500
From: Paul M Fleming <pfleming@siumed.edu>
MIME-Version: 1.0
To: kerberos@mit.edu
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Has anyone implemented Kerberos id lockouts after X invalid TGS/TGT
attempts? (obviously PREAUTH has to be enabled). I see reference on the
list to folks parsing the logs to do this function. I also found several
references to using the built-in untested MIT code to update the db on
fails. The MIT code has several issues that are making me lean toward
implementing some custom code to implement lockout after X fails and
auto unlock after some configurable time interval. I'm still not sure
how I'm going to handle the master/slave - distributed db issues 

Any comments or ideas would be welcome. I'm currently working on a
design for a lockout daemon unless I find a better solution. 

Thanks

Paul Fleming
SIU School of Medicine
Springfield IL
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post