[2277] in Kerberos
Question on Kerberos & X-terminals
daemon@ATHENA.MIT.EDU (Jim Hendrick)
Sat Oct 10 23:25:15 1992
Date: Sat, 10 Oct 92 23:02:34 EDT
From: Jim Hendrick <hendrick@neptune.ctron.com>
To: kerberos@Athena.MIT.EDU
Hi,
I am looking for information on the security problems with
using Xterminals to access "realtively secure" machines. By this I
mean machines that act as access points to a database containing
critical resources. These access machines have been physically
"secured" in a minimal sense, locked cabinets, no terminals
considered secure in the /etc/ttytab file including the console. As
part of the duties of several administrators, they are required to log
into these "trusted" machines and occasionally su to root or other
more priviliged accounts. My question relates to the ability (or
inability) to safely use Xterminals to access these "trusted"
machines. Specifically, does anyone know of a way to secure the
transmissions from these Xterminals such that a network "snooper"
could not obtain the cleartext passwords as they fly by? I am moving
towards using Kerberos as the authentication service for these
machines so that one could (from a workstation running K.) use the
encrypted mode of transmission for sensitive login sessions and to
generally keep cleartext passwords off the wire but now I have been
asked to set up Xterminals for the administrative staff to use and
think that this might pose a problem. {whew, how's that for a sentence :-}
I hope this is an appropriate forum for such a question (being new to
this mailing list).
Thanks
Jim