[2581] in Kerberos

home help back first fref pref prev next nref lref last post

MIT Kerberos V5

daemon@ATHENA.MIT.EDU (Joe Ramus)
Thu Feb 18 22:50:11 1993

Date: Thu, 18 Feb 93 19:29:03 PST
From: ramus@nersc.gov (Joe Ramus)
To: kerberos@Athena.MIT.EDU


I am forwarding this message because I think it is of general interest.
This message was sent in response to a query regarding MIT Kerberos V5.
  Joe Ramus  NERSC Livermore  (510) 423-8917   ramus@nersc.gov

----- Begin Included Message -----

Date: Thu, 18 Feb 93 22:09:57 -0500
From: Theodore Ts'o <tytso@Athena.MIT.EDU>

Address: 1 Amherst St., Cambridge, MA 02139
Phone: (617) 253-8091

   Date: Thu, 18 Feb 93 10:47:18 PST
   From: ramus@nersc.gov (Joe Ramus)

   Jerry Johnson (PNL) recently posted a message that included a response from
   Jeff Schiller (MIT) regarding the status of Kerberos V5.  Part of that
   message is included below.  I am still not sure about the MIT position
   on Kerberos V5.

   1) Is MIT really committed to support of V5?

Yes, MIT is committed to supporting V5.  In addition to our continuing
work towards improving Kerberos V5 and getting it ready for production
use in our own environment, we are also working with the X Consortium to
add Kerberos V5 user-to-user authentication to X11R6.

   2) Is MIT using Kerberos V5 with the changes from Sandia?

Sandia National Labs has fed their changes back to us; we are currently
in the process of integrating them into our sources.  This integration
is something which we do slowly and carefully, since we want to be
certain that no security holes were inadvertently added to the sources
as a result of the changes.  We've had at least one case where someone
has submitted patches which fixed the immediate problem they were
worried about, but which potentially openned up a hole in the security
of the system.

We expect the next release of Kerberos V5 to have all of the bug fixed
and many of the enhancemented submitted by Sandia incorporated into it.
The next release will also see version of rlogin/rsh/rcp which are
backwards compatible with Kerberos V4 as well as working with Kerberos
V5.

I hope this answers your questions; if you have any other questions,
please feel free to ask me, and I will do my best to address them.

					- Ted

----- End Included Message -----

home help back first fref pref prev next nref lref last post