[23372] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Java Pre-auth for Windows 2003 mixed case revival

daemon@ATHENA.MIT.EDU (Roland Dowdeswell)
Thu Feb 10 17:21:57 2005

To: "Douglas E. Engert" <deengert@anl.gov>
In-reply-to: Your message of "Thu, 10 Feb 2005 14:25:46 CST."
             <420BC34A.4020906@anl.gov> 
Date: Thu, 10 Feb 2005 15:40:07 -0500
From: Roland Dowdeswell <elric@imrryr.org>
Message-Id: <20050210204007.00AB73701F@arioch.imrryr.org>
cc: Mike Chapel <spielfriek@gmail.com>
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

On 1108067146 seconds since the Beginning of the UNIX epoch
"Douglas E. Engert" wrote:
>

>In the future as PKINIT and /or other pre-auths are implemented, you
>may have to send in the first request without any pre-auth just to find
>out what the KDC will accept so you might as well do it now too.

Even today, sending pre-auth without first talking to the KDC is
a bit of a security problem if the client is not properly configured.
E.g. if I send a DES PA_TIMESTAMP, Eve can easily crack my password
regardless of not having DES keys in the KDC.  Of course, a MITM
can easily convince me to send a DES PA_TIMESTAMP...

--
    Roland Dowdeswell                      http://www.Imrryr.ORG/~elric/
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post