[19083] in Kerberos_V5_Development
Kerberos PAKE Preauth Mechanism
daemon@ATHENA.MIT.EDU (Nathaniel McCallum)
Tue Jan 27 02:06:13 2015
Message-ID: <1422342351.26683.9.camel@redhat.com>
From: Nathaniel McCallum <npmccallum@redhat.com>
To: krbdev@mit.edu
Date: Tue, 27 Jan 2015 02:05:51 -0500
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
For some background to where we are going, please check out this page:
http://k5wiki.kerberos.org/wiki/Projects/Improve_OTP_deployability
I plan to document all this stuff in the coming weeks. But the big
reveal is a new preauth mech: https://github.com/npmccallum/krb5-pake
All the caveats apply: this is completely insecure and will steal your
passwords. Don't use it anywhere but a test setup.
You will also need a patch to enable support for
KDC_ERR_MORE_PREAUTH_DATA_REQUIRED:
https://github.com/krb5/krb5/pull/245
Comments/reviews welcome.
Nathaniel
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev