[2401] in Kerberos-V5-bugs
Re: pending/154: krb4 interface too lax in security
daemon@ATHENA.MIT.EDU (John Gardiner Myers)
Tue Nov 5 19:34:08 1996
Date: Tue, 5 Nov 1996 19:31:53 -0500 (EST)
From: John Gardiner Myers <jgm@CMU.EDU>
To: "Theodore Y. Ts'o" <tytso@MIT.EDU>
Cc: krb5-bugs@MIT.EDU, gnats-admin@rt-11.MIT.EDU, krb5-prs@rt-11.MIT.EDU
In-Reply-To: <9611050417.AA15374@dcl.MIT.EDU>
My patch has the problem that it then also disables being able to get
tickets for authenticating to services which have non-(v4 or afs)
salted keys.
So, to do this, we need to be a bit more sophisticated. Pass in an
argument to the routine which says whether or not arbitrary salts are
ok, or add an option in kdc.conf which turns off the v4 initial ticket
protocol. Do you have any preferences?
--
_.John Gardiner Myers Internet: jgm+@CMU.EDU
LoseNet: ...!seismo!ihnp4!wiscvm.wisc.edu!give!up