[2340] in Kerberos
Local password validation (was: kerberizing xlock)
daemon@ATHENA.MIT.EDU (Barry Jaspan)
Thu Nov 5 11:16:01 1992
Date: Thu, 5 Nov 92 10:38:32 -0500
From: "Barry Jaspan" <bjaspan@Athena.MIT.EDU>
To: greg@duke.cs.unlv.edu
Cc: hendrick@neptune.ctron.com, kerberos@Athena.MIT.EDU
In-Reply-To: Greg Wohletz's message of Wed, 04 Nov 92 22:44:07 -0800 <9211050649.AA24026@Athena.MIT.EDU>
Date: Wed, 04 Nov 92 22:44:07 -0800
From: Greg Wohletz <greg@duke.cs.unlv.edu>
In our environment ... I'm not particularly
concerned if an imposter gains access to a workstation cpu since all
he would not actually be able to do anything useful (nfs, pop, etc.
all require kerberos authentication)
**PRECISELY**
We have now come full circle. Notice that the subject line in this
message contains "was: kerberizing xlock." This entire conversation
began because people were discussing using Kerberos for local password
authentication, when it was not designed for that purpose.
With public workstations (like those you described, and those at MIT's
Athena) the spoofability of public workstations is irrelevant.
However, when people start talking about using Kerberos for xlock, it
is clear that they *do* care about an imposter gaining access to a
workstation (particularly given that another user's credentials are
already available there). In that case, the spoofing issue becomes
highly relevant.
So now, I think, the point has been made and everyone understands the
issues better. That is, after all, part of the purpose of this
mailing list. :-)
Barry