[2340] in Kerberos

home help back first fref pref prev next nref lref last post

Local password validation (was: kerberizing xlock)

daemon@ATHENA.MIT.EDU (Barry Jaspan)
Thu Nov 5 11:16:01 1992

Date: Thu, 5 Nov 92 10:38:32 -0500
From: "Barry Jaspan" <bjaspan@Athena.MIT.EDU>
To: greg@duke.cs.unlv.edu
Cc: hendrick@neptune.ctron.com, kerberos@Athena.MIT.EDU
In-Reply-To: Greg Wohletz's message of Wed, 04 Nov 92 22:44:07 -0800 <9211050649.AA24026@Athena.MIT.EDU>


   Date: Wed, 04 Nov 92 22:44:07 -0800
   From: Greg Wohletz <greg@duke.cs.unlv.edu>

   In our environment ... I'm  not  particularly
   concerned  if  an imposter gains access to a workstation cpu since all
   he would not actually be able to  do anything useful (nfs, pop,  etc.
   all require kerberos authentication)

**PRECISELY**

We have now come full circle.  Notice that the subject line in this
message contains "was: kerberizing xlock."  This entire conversation
began because people were discussing using Kerberos for local password
authentication, when it was not designed for that purpose.  

With public workstations (like those you described, and those at MIT's
Athena) the spoofability of public workstations is irrelevant.
However, when people start talking about using Kerberos for xlock, it
is clear that they *do* care about an imposter gaining access to a
workstation (particularly given that another user's credentials are
already available there).  In that case, the spoofing issue becomes
highly relevant.

So now, I think, the point has been made and everyone understands the
issues better.  That is, after all, part of the purpose of this
mailing list. :-)

Barry

home help back first fref pref prev next nref lref last post