[22619] in Kerberos

home help back first fref pref prev next nref lref last post

kerberos blacklisting

daemon@ATHENA.MIT.EDU (Rich Frobose)
Tue Oct 5 19:17:21 2004

Message-Id: <5.0.2.1.2.20041005161007.00add280@mail-lc.llnl.gov>
Date: Tue, 05 Oct 2004 16:14:45 -0700
To: kerberos@mit.edu
From: Rich Frobose <frobose@llnl.gov>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
cc: frobose@llnl.gov
Errors-To: kerberos-bounces@mit.edu

I would like to know if the MIT KDC supports black listing (i.e. not issuing
tickets for a principal after a set number of password failures.)  If it does
not, has anyone implemented extensions to provide that feature?

I have a second question that relates to this issue but is not just confined
to black listing.

I realize that preauthentication must be enabled for the KDC to "know"
about a password/authentication failure.  I have done that.  I then used
kadmin to do "getprinc" so that I could see information about a given 
principal.  The reply
to "getpric <NAME>" included the following lines (for a principal
that is definitely using preauthentication):
   Last successful authentication: [never]
   Last failed authentication: [never]
   Failed password attempts: 0
This tells me that these fields are not being reported properly.  I had
previously authenticated as this principal and have had failures.

Question: Why are these fields not getting updated and reported properly?

Thanks for the help.
Richard Frobose

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post