[2424] in Kerberos-V5-bugs
Re: pending/154: krb4 interface too lax in security
daemon@ATHENA.MIT.EDU (John Gardiner Myers)
Fri Nov 8 15:00:44 1996
Date: Fri, 8 Nov 1996 15:00:02 -0500 (EST)
From: John Gardiner Myers <jgm@CMU.EDU>
To: Marc Horowitz <marc@MIT.EDU>, "Theodore Y. Ts'o" <tytso@MIT.EDU>
Cc: krb5-bugs@MIT.EDU, gnats-admin@rt-11.MIT.EDU, krb5-prs@rt-11.MIT.EDU,
"Theodore Y. Ts'o" <tytso@MIT.EDU>
In-Reply-To: <9611081954.AA00525@dcl.MIT.EDU>
I'm a bit less worried about the V4 tgt key, since it tends to have a
bit more entropy than users' private keys.
A flag to turn off the v4 in_tkt code would be just what I'd like.
For now, I'll probably just dike out the appropriate code.
--
_.John Gardiner Myers Internet: jgm+@CMU.EDU
LoseNet: ...!seismo!ihnp4!wiscvm.wisc.edu!give!up