[4129] in Kerberos
Re: paper on Kerberos weaknesses
daemon@ATHENA.MIT.EDU (Donald T. Davis)
Wed Nov 2 15:32:52 1994
To: terry@venus.sunquest.com (Terry R. Friedrichsen)
Cc: don@cam.ov.com, kerberos@MIT.EDU
In-Reply-To: Your message of "02 Nov 1994 00:15:08 GMT."
<396lmc$2tf@odin.sunquest.com>
--------
From: terry@venus.sunquest.com (Terry R. Friedrichsen)
Date: Wed, 02 Nov 1994 15:12:13 -0500
From: "Donald T. Davis" <don@cam.ov.com>
A couple of years ago, while visiting one of the national labs, I saw
a paper on Kerberos while in someone's office.
If anybody out there can, from this admittedly scanty description,
identify this paper, I'd appreciate knowing whether it is publicly
available and, if so, from where it might be obtained.
it's "weaknesses of the kerberos system"
by steve bellovin & michael merritt,
acm computer communications review, late 1990.
this is more-or-less the correct citation; i'm sure of
the authors, journal, and year. be aware, though, that
the paper critiques krb v4 only; v5 redresses most of
their complaints.
-don davis