[2591] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos 5 & login

daemon@ATHENA.MIT.EDU (Theodore Ts'o)
Wed Feb 24 21:36:48 1993

Date: Wed, 24 Feb 93 21:26:08 -0500
From: Theodore Ts'o <tytso@Athena.MIT.EDU>
To: ramus@nersc.gov
Cc: kerberos@Athena.MIT.EDU
In-Reply-To: Joe Ramus's message of Wed, 24 Feb 93 17:39:16 PST,

   Date: Wed, 24 Feb 93 17:39:16 PST
   From: ramus@nersc.gov (Joe Ramus)

   But on other platforms (such as SunOS), there is no "-f" option on
   the vendor supplied login.  In this case, Sandia chose to use 
   "login -r" after authentication is completed.  This method requires a 
   user to have a  .rhosts  file in the home directory and this opens up
   some new security risks.  There are some ways to disable the normal
   BSD rlogin mechanism which uses the .rhosts file.

This only opens up some security risks if you enable the non-Kerberized
rlogin/rsh/rcp daemons.  Of course, for backwards compatibility reasons,
you may not be able to disable them.

   For some platforms, I think MIT has a replacement for the vendor login
   that implements the -f option.   If so, what platforms does it run on?
   Are there any undesirable "side-effects" when using the non-vendor
   login?

The reason why we moved away from providing our own (BSD-derived) login
is that more and more vendors are putting in vendor-specific hacks; for
example, things like initializing fascist license managers, or "Secure
SunRPC".  You can probably find a login.c from the BSD Net-2
distribution, that will mostly work.  However, if your vendor has put
anything wierd and/or wonderful in their login, you may lose in
interesting ways.

						- Ted

home help back first fref pref prev next nref lref last post