[2595] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos 5 & login

daemon@ATHENA.MIT.EDU (Derek Atkins)
Thu Feb 25 12:32:16 1993

To: bf4grjc@bell-atl.com
Cc: kerberos@Athena.MIT.EDU, tytso@Athena.MIT.EDU (Theodore Ts'o)
In-Reply-To: [2593] in Kerberos
Date: Thu, 25 Feb 93 12:02:40 EST
From: Derek Atkins <warlord@Athena.MIT.EDU>

> Given above, why cannot there be an OPTION ADDED (not change) to the protocol
> such that the initial TGT is sent to the login/xdm programs "additionaly" 
> encrypted with a service key known only to the KDC and the login/program.

Becuse I can go through the sources, or the binary, and find that key.

Actually, what you suggest is already done.  It *should* attempt to
get an rcmd service ticket for the machine, and the machine should try
to verify it.  However this requires the login program be run as root,
in order to read the srvtab file.

Basically, you can do this without any changes to the kerberos
protocol.  I just want to ask why you wanted to encrypt the TGT in the
rcmd ticket.  What kind of attack are you protecting against?  It's
still just as spoofable as just looking for a user TGT w/o checking
for the rcmd....

Anyways, just thought I'd point this out.. Look at the archives for
a more detailed discussion.

-derek

PGP 2 key available upon request, on the key-server:
	pgp-public-keys@toxicwaste.mit.edu
--
  Derek Atkins, MIT '93, Electrical Engineering and Computer Science
      Chairman, MIT Student Information Processing Board (SIPB)
           MIT Media Laboratory, Speech Research Group
           warlord@MIT.EDU       PP-ASEL        N1NWH

home help back first fref pref prev next nref lref last post