[2316] in Kerberos

home help back first fref pref prev next nref lref last post

Re: kerberizing xlock

daemon@ATHENA.MIT.EDU (Jim Haynes)
Thu Oct 29 18:33:39 1992

From: haynes@cats.UCSC.EDU (Jim Haynes)
Date: Thu, 29 Oct 92 10:05:19 -0800
To: kerberos@Athena.MIT.EDU

Some versions of Kerberized login edit the user's encrypted password into
the /etc/passwd file.  In such cases the existing xlock will work because
there is a password to get from the local password file.  We have found
this feature of login to be undesirable on multi-user machines because
it exposes a number of encrypted passwords to guessing attacks.

home help back first fref pref prev next nref lref last post