[22619] in Kerberos
kerberos blacklisting
daemon@ATHENA.MIT.EDU (Rich Frobose)
Tue Oct 5 19:17:21 2004
Message-Id: <5.0.2.1.2.20041005161007.00add280@mail-lc.llnl.gov>
Date: Tue, 05 Oct 2004 16:14:45 -0700
To: kerberos@mit.edu
From: Rich Frobose <frobose@llnl.gov>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
cc: frobose@llnl.gov
Errors-To: kerberos-bounces@mit.edu
I would like to know if the MIT KDC supports black listing (i.e. not issuing
tickets for a principal after a set number of password failures.) If it does
not, has anyone implemented extensions to provide that feature?
I have a second question that relates to this issue but is not just confined
to black listing.
I realize that preauthentication must be enabled for the KDC to "know"
about a password/authentication failure. I have done that. I then used
kadmin to do "getprinc" so that I could see information about a given
principal. The reply
to "getpric <NAME>" included the following lines (for a principal
that is definitely using preauthentication):
Last successful authentication: [never]
Last failed authentication: [never]
Failed password attempts: 0
This tells me that these fields are not being reported properly. I had
previously authenticated as this principal and have had failures.
Question: Why are these fields not getting updated and reported properly?
Thanks for the help.
Richard Frobose
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos