[13178] in Athena Bugs

home help back first fref pref prev next nref lref last post

NetProb ticket #3029, sun4 7.7K: login

daemon@ATHENA.MIT.EDU (mbarker@MIT.EDU)
Fri Feb 3 16:20:35 1995

From: mbarker@MIT.EDU
Date: Fri, 3 Feb 1995 16:20:30 -0500
To: aja@MIT.EDU
Cc: bugs@MIT.EDU

actually, the problem is not related to your workstation.  there is a
lag in time between updating of the kerberos passwords, and apparently
you got in touch with a slave server that hadn't yet gotten the update.
this made your old password temporarily acceptable in a limited way.

thank you for reporting this
mike

>From aja@MIT.EDU Fri Feb  3 10:20:02 1995
>Received: by gregor.MIT.EDU (5.57/4.7) id AA00594; Fri, 3 Feb 95 10:20:01 -050>0
>Received: from EECS-ATH-12.MIT.EDU by MIT.EDU with SMTP
>	id AA20869; Fri, 3 Feb 95 10:19:59 EST
>Received: by eecs-ath-12.MIT.EDU (5.0/4.7) id AA19968; Fri, 3 Feb 1995 10:19:5>8 +0500
>Message-Id: <9502031519.AA19968@eecs-ath-12.MIT.EDU>
>To: bugs@MIT.EDU
>Subject: sun4 7.7K: login
>Date: Fri, 03 Feb 1995 10:19:57 EST
>From: "A.J. Aranyosi" <aja@MIT.EDU>
>Content-Length: 864
>
>System name:		eecs-ath-12
>Type and version:	SPARC/Classic 7.7K (1 update(s) to same version)
>Display type:		cgthree
>
>What were you trying to do?
>	Log in to a workstation, accidentally using my old password.
>
>What's wrong:
>	I changed my password yesterday on this same machine.  When
>	I tried to log in this morning, I accidentally used the old
>	password.  Rather than telling me that the password was
>	incorrect, the machine tried to log me in, but failed to 
>	obtain any Kerberos instances, attach my home directory, etc.
>	Eventually I did get a generic login.  Note that on any
>	other machine, entering the old password generates a
>	"login failed" message.  Kind of an ugly security breach,
>	isn't it?
>
>What should have happened:
>	I should've gotten a message saying "login failed".
>
>Please describe any relevant documentation references:
>	None that I know of.
>
>

home help back first fref pref prev next nref lref last post