[729] in Kerberos
secure time synchronization
daemon@TELECOM.MIT.EDU (NESSETT%CCC.MFECC.LLNL.GOV@.MIT.EDU)
Wed May 17 16:19:24 1989
From: NESSETT%CCC.MFECC.LLNL.GOV@.MIT.EDU
To: KERBEROS@ATHENA.MIT.EDU
Dave,
To solve the secure time synchronization problem, you will need more than an
authenticated time service. It must not be possible to replay synchronization
messages thereby setting a local clock back by an arbitrary amount. Perhaps
the protocol you use prevents this. We found that designing a secure
time synchronization protocol to be equivalent to designing a secure
connection protocol.
Dan