[3792] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

[krbdev.mit.edu #31] security flaw in get_in_tkt: address

daemon@ATHENA.MIT.EDU (Sam Hartman via RT)
Mon Jan 27 14:17:31 2003

Date: Mon, 27 Jan 2003 14:16:57 -0500 (EST)
Mail-Followup-To: rt@krbdev.mit.edu
Message-Id: <rt-31-4019.16.889600653148@krbdev.mit.edu>
In-Reply-To: <rt-31@krbdev.mit.edu>
From: "Sam Hartman via RT" <rt-comment@krbdev.mit.edu>
Mail-Copies-To: never
To: tlyu@mit.edu
cc: krb5-prs@mit.edu
Reply-To: rt-comment@krbdev.mit.edu
Errors-To: krb5-bugs-bounces@mit.edu

If this is still actually a problem, we are unlikely to ever fix it.  We are moving away from
addresses as a security mechanism.  This problem will be reduced somewhat
by checksums introduced into Kerberos extensions.
_______________________________________________
krb5-bugs mailing list
krb5-bugs@mit.edu
http://mailman.mit.edu/mailman/listinfo/krb5-bugs

home help back first fref pref prev next nref lref last post