[23327] in Kerberos

home help back first fref pref prev next nref lref last post

Lost Authenticator for an krb_ap_request

daemon@ATHENA.MIT.EDU (Ahluwalia, Ish)
Thu Feb 3 21:02:24 2005

content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Date: Thu, 3 Feb 2005 18:56:45 -0500
Message-ID: <A3863F3136CBC546A40A61BA9CBA9D930113D944@sonusmail03.sonusnet.com>
From: "Ahluwalia, Ish" <iahluwalia@sonusnet.com>
To: <kerberos@mit.edu>
Content-Transfer-Encoding: 8bit
Errors-To: kerberos-bounces@mit.edu

Hi All:

Does anyone one know that if for some reason Kerberos loses track of any authenticator presented with in the acceptable clock skew, then kerberos rejects all the requests untill the interval has passed?

The above question directly stems out of the Kerberos V5 requirement where Kerberos must remember any authenticators presented with the acceptable clock skew, so that replay attempt is guaranteed to fail.

Any information/thoughts will be highly appreciated?

Thanks.

Ish...

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post