[2377] in Kerberos
Re: NTP mailing list?
daemon@ATHENA.MIT.EDU (Ganesan)
Thu Nov 12 18:28:10 1992
From: bf4grjc@socrates.MIT.EDU (Ganesan)
To: louie@ni.umd.edu (Louis A. Mamakos)
Date: Thu, 12 Nov 92 10:56:59 EST
Cc: bbh7rqj@socrates.wash.bell-atl.com (chris davies), kerberos@Athena.MIT.EDU
In-Reply-To: <9211110234.AA02587@sayshell.umd.edu>; from "Louis A. Mamakos" at Nov 10, 92 9:34 pm
Reply-To: bf4grjc@socrates.bell-atl.com
>
> I can add you to the mailing list.
Thanks, Could you add bbh7rqj@socrates.bell-atl.com to the list? This is
not me, but a colleague (Chris Davies), who is monitoring NTp more closely.
>
> There is no FAQ that I know of, though you may want to grab the file
> /pub/ntp/clock.txt from LOUIE.UDEL.EDU.
>
Will do.
> I don't know what you mean about an NTP that works with Kerberos. NTP
> uses its own authentication mechanism. Using Kerberos is not really
> appropriate for a number of reasons, the most troublesome of which is
> that kerberos relies on loosely synchronized clocks, which is what NTP
> is trying to do.
>
We use the current authentication scheme available with NTP, and realize
that the notion of the security of the time service relying on the
security of the security service which relies on the security of the
time service is troubling! However, in the absence of any name/time/security
services designed together in a secure fashion, we feel it is probably
easier (administratively speaking) to have a single security mechanism (in
this case Kerberos).
Thanks,
Ravi
--
*******************************************************************************
Ravi Ganesan e-mail: ravi@socrates.bell-atl.com
IS SAS Corporate Network Planning v-mail: (301) 595-8439
Bell Atlantic Fax: (301) 595-1341
Note: If your e-mail reply to me bounces, try sending it explicitly to
ravi@socrates.bell-atl.com instead of using the 'reply' feature.
******************************************************************************