[2286] in Kerberos
Question Re: Xterminals
daemon@ATHENA.MIT.EDU (Jim Hendrick)
Mon Oct 12 13:35:32 1992
Date: 10 Oct 92 14:23:12 GMT
From: hendrick@ctron.com (Jim Hendrick)
To: kerberos@shelby.Stanford.EDU
Hi,
I am looking for information on the security problems with
using Xterminals to access "realtively secure" machines. By this I
mean machines that act as access points to a database containing
critical resources. These access machines have been physically
"secured" in a minimal sense, locked cabinets, no terminals
considered secure in the /etc/ttytab file including the console. As
part of the duties of several administrators, they are required to log
into these "trusted" machines and occasionally su to root or other
more priviliged accounts. My question relates to the ability (or
inability) to safely use Xterminals to access these "trusted"
machines. Specifically, does anyone know of a way to secure the
transmissions from these Xterminals such that a network "snooper"
could not obtain the cleartext passwords as they fly by? I am moving
towards using Kerberos as the authentication service for these
machines so that one could (from a workstation running K.) use the
encrypted mode of transmission for sensitive login sessions and to
generally keep cleartext passwords off the wire but now I have been
asked to set up Xterminals for the administrative staff to use and
think that this might pose a problem. {whew, how's that for a sentence :-}
Please reply via email any questions, answers, comments or pointers to
further information sources. I will summarize if there appears to be
the desire.
Thanks!!
Jim
--
###########################################################################
### Jim Hendrick (hendrick@ctron.com) ### ###
### Cabletron Systems Inc. ### " My opinions, etc are ###
### P. O. Box 5005 ### exclusively the property ###
### Rochester, NH 03867-5005 ### of nobody in particular." ###
### (603) 332-9400 x1457 ### ###
### fax:(603)332-1019 ### ###
###########################################################################