[23435] in Kerberos

home help back first fref pref prev next nref lref last post

Re: afs to k5 conversion keytypes

daemon@ATHENA.MIT.EDU (Sam Hartman)
Tue Feb 22 15:34:32 2005

To: Ken Hornstein <kenh@cmf.nrl.navy.mil>
From: Sam Hartman <hartmans@mit.edu>
Date: Tue, 22 Feb 2005 15:33:51 -0500
In-Reply-To: <200502222027.j1MKR6CY001283@ginger.cmf.nrl.navy.mil> (Ken
 Hornstein's message of "Tue, 22 Feb 2005 15:27:06 -0500")
Message-ID: <tslr7j8xrkg.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

>>>>> "Ken" == Ken Hornstein <kenh@cmf.nrl.navy.mil> writes:

    Ken> Thewre is one way ... but it requires you to have your
    Ken> Kerberos Shit Together.

    Ken> Write a custom login program that once you login correctly
    Ken> using an AFS salted key, generates a V5 salted key from that
    Ken> plaintext password and stores it somewhere.  "Somewhere"
    Ken> could be in a V5 database (e.g., you can simply force a
    Ken> password change).  This means not only would you have to know
    Ken> how to program the poorly-documented Kerberos API, but you
    Ken> would have to figure out how to program the
    Ken> even-more-poorly-documented kadm5 API.
krb5_change_password is not any worse to use than the init_creds API.
You can avoid the kadm5 API.

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post