[6688] in Kerberos
Re: Kerberos Weakness (COAST Findings)
daemon@ATHENA.MIT.EDU (Paul Danckaert)
Sun Feb 18 10:20:12 1996
To: kerberos@MIT.EDU
Date: 18 Feb 1996 10:02:21 -0500
From: pauld@umbc.edu (Paul Danckaert)
In article <4g5k5e$21c@narnia.cs.purdue.edu>,
Steve Lodin <swlodin@cs.purdue.edu> wrote:
>
>In article <4g5jdd$iv4@umbc7.umbc.edu>, pauld@umbc.edu (Paul Danckaert) writes:
>> I am somewhat concerned about this.. does anybody have any more information
>> on the extent of the problems here, or the status on any bug-fixes?
>
>Contact your Kerberos vendor or MIT for fixes. Further details will be
>released later.
One thing I am curious about are distributions like eBones, which don't really
have a vendor. I guess it will get fixed at some point..
>My first suggestion is don't use any kerberos based on MIT Kerberos
>Version 4 for military-grade security requirements.
Damn.. time to move those launch codes to a different machine. :)
thanks for the info,
paul
--