[2401] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

Re: pending/154: krb4 interface too lax in security

daemon@ATHENA.MIT.EDU (John Gardiner Myers)
Tue Nov 5 19:34:08 1996

Date: Tue,  5 Nov 1996 19:31:53 -0500 (EST)
From: John Gardiner Myers <jgm@CMU.EDU>
To: "Theodore Y. Ts'o" <tytso@MIT.EDU>
Cc: krb5-bugs@MIT.EDU, gnats-admin@rt-11.MIT.EDU, krb5-prs@rt-11.MIT.EDU
In-Reply-To: <9611050417.AA15374@dcl.MIT.EDU>

My patch has the problem that it then also disables being able to get
tickets for authenticating to services which have non-(v4 or afs)
salted keys.

So, to do this, we need to be a bit more sophisticated.  Pass in an
argument to the routine which says whether or not arbitrary salts are
ok, or add an option in kdc.conf which turns off the v4 initial ticket
protocol.  Do you have any preferences?

-- 
_.John Gardiner Myers	Internet: jgm+@CMU.EDU
			LoseNet:  ...!seismo!ihnp4!wiscvm.wisc.edu!give!up

home help back first fref pref prev next nref lref last post