[3792] in Kerberos-V5-bugs
[krbdev.mit.edu #31] security flaw in get_in_tkt: address
daemon@ATHENA.MIT.EDU (Sam Hartman via RT)
Mon Jan 27 14:17:31 2003
Date: Mon, 27 Jan 2003 14:16:57 -0500 (EST)
Mail-Followup-To: rt@krbdev.mit.edu
Message-Id: <rt-31-4019.16.889600653148@krbdev.mit.edu>
In-Reply-To: <rt-31@krbdev.mit.edu>
From: "Sam Hartman via RT" <rt-comment@krbdev.mit.edu>
Mail-Copies-To: never
To: tlyu@mit.edu
cc: krb5-prs@mit.edu
Reply-To: rt-comment@krbdev.mit.edu
Errors-To: krb5-bugs-bounces@mit.edu
If this is still actually a problem, we are unlikely to ever fix it. We are moving away from
addresses as a security mechanism. This problem will be reduced somewhat
by checksums introduced into Kerberos extensions.
_______________________________________________
krb5-bugs mailing list
krb5-bugs@mit.edu
http://mailman.mit.edu/mailman/listinfo/krb5-bugs