[2510] in Kerberos

home help back first fref pref prev next nref lref last post

Re: KDC/Kadmin IP Addr Question

daemon@ATHENA.MIT.EDU (Steve Lunt)
Wed Jan 13 13:56:04 1993

Date: Wed, 13 Jan 93 13:25:35 EST
From: Steve Lunt <lunt@ctt.bellcore.com>
To: kerberos@Athena.MIT.EDU
Cc: mamros@athena.lkg.dec.com

	Although there is little risk in getting
realm-to-Kerberos-server and realm-to-Master-Kerberos-server mappings
over the net, there is a big risk in getting the local realm name
over the net, and there is a subtle risk in getting hostname-to-realm
mappings over the net.  If you don't *securely* know the Kerberos
name of the party with which you wish to authenticate, then some
imposter, albeit a legitimate Kerberos principal, will instead be
authenticated to and communicated with, thus compromising that
application transaction.

-- Steve

Steven J. Lunt                     lunt@bellcore.com
Information Technology Security    RRC 1L-213
Bellcore                           444 Hoes Lane
(908) 699-4244                     Piscataway, NJ 08854


home help back first fref pref prev next nref lref last post