[6688] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos Weakness (COAST Findings)

daemon@ATHENA.MIT.EDU (Paul Danckaert)
Sun Feb 18 10:20:12 1996

To: kerberos@MIT.EDU
Date: 18 Feb 1996 10:02:21 -0500
From: pauld@umbc.edu (Paul Danckaert)

In article <4g5k5e$21c@narnia.cs.purdue.edu>,
Steve Lodin <swlodin@cs.purdue.edu> wrote:
>
>In article <4g5jdd$iv4@umbc7.umbc.edu>, pauld@umbc.edu (Paul Danckaert) writes:
>> I am somewhat concerned about this.. does anybody have any more information
>> on the extent of the problems here, or the status on any bug-fixes?
>
>Contact your Kerberos vendor or MIT for fixes.  Further details will be
>released later.

One thing I am curious about are distributions like eBones, which don't really
have a vendor.  I guess it will get fixed at some point..

>My first suggestion is don't use any kerberos based on MIT Kerberos
>Version 4 for military-grade security requirements.

Damn.. time to move those launch codes to a different machine.  :)

thanks for the info,

paul
-- 



home help back first fref pref prev next nref lref last post