[2424] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

Re: pending/154: krb4 interface too lax in security

daemon@ATHENA.MIT.EDU (John Gardiner Myers)
Fri Nov 8 15:00:44 1996

Date: Fri,  8 Nov 1996 15:00:02 -0500 (EST)
From: John Gardiner Myers <jgm@CMU.EDU>
To: Marc Horowitz <marc@MIT.EDU>, "Theodore Y. Ts'o" <tytso@MIT.EDU>
Cc: krb5-bugs@MIT.EDU, gnats-admin@rt-11.MIT.EDU, krb5-prs@rt-11.MIT.EDU,
        "Theodore Y. Ts'o" <tytso@MIT.EDU>
In-Reply-To: <9611081954.AA00525@dcl.MIT.EDU>

I'm a bit less worried about the V4 tgt key, since it tends to have a
bit more entropy than users' private keys.

A flag to turn off the v4 in_tkt code would be just what I'd like.
For now, I'll probably just dike out the appropriate code.

-- 
_.John Gardiner Myers	Internet: jgm+@CMU.EDU
			LoseNet:  ...!seismo!ihnp4!wiscvm.wisc.edu!give!up

home help back first fref pref prev next nref lref last post