[2510] in Kerberos
Re: KDC/Kadmin IP Addr Question
daemon@ATHENA.MIT.EDU (Steve Lunt)
Wed Jan 13 13:56:04 1993
Date: Wed, 13 Jan 93 13:25:35 EST
From: Steve Lunt <lunt@ctt.bellcore.com>
To: kerberos@Athena.MIT.EDU
Cc: mamros@athena.lkg.dec.com
Although there is little risk in getting
realm-to-Kerberos-server and realm-to-Master-Kerberos-server mappings
over the net, there is a big risk in getting the local realm name
over the net, and there is a subtle risk in getting hostname-to-realm
mappings over the net. If you don't *securely* know the Kerberos
name of the party with which you wish to authenticate, then some
imposter, albeit a legitimate Kerberos principal, will instead be
authenticated to and communicated with, thus compromising that
application transaction.
-- Steve
Steven J. Lunt lunt@bellcore.com
Information Technology Security RRC 1L-213
Bellcore 444 Hoes Lane
(908) 699-4244 Piscataway, NJ 08854