[22676] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Using ssh-keys for kerberos authentication

daemon@ATHENA.MIT.EDU (Michael Tautschnig)
Thu Oct 14 02:42:52 2004

Date: Thu, 14 Oct 2004 08:35:31 +0200 (CEST)
From: Michael Tautschnig <michael.tautschnig@zt-consulting.com>
To: Sam Hartman <hartmans@mit.edu>
In-Reply-To: <tslfz4iz4f7.fsf@cz.mit.edu>
Message-ID: <Pine.LNX.4.61.0410140824430.21414@l01.thnet>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

>
>    Michael> Hi!  I'm wondering wether it is (at least theoretically)
>    Michael> feasible to use a ssh-key to get kerberos tokens!? This
>    Michael> is fairly important to me, since filesystems such as
>    Michael> coda, afs of nfsv4 depend on kerberos-authentication to
>    Michael> access the filespace.
>
> It is theoretically possible.  You would need to modify the Kerberos
> KDC to support this.
Is there anyone out there planning to do this? If not, could someone give 
me some hints where to start?


>
> Why not just use Kerberos authentication at the ssh layer though.
People like ssh-keys and they are considered rather secure, passwords are 
not (they are more vulnerable to brute-force-attacks).

Thanks in advance,
Michael
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post