[308] in Kerberos
Re: Yet another addendum
daemon@TELECOM.MIT.EDU (Jeffrey I. Schiller)
Thu Jan 28 20:30:29 1988
From: Jeffrey I. Schiller <jis@BITSY.MIT.EDU>
To: bcn@JUNE.CS.WASHINGTON.EDU
Cc: treese@ATHENA.MIT.EDU, kerberos@ATHENA.MIT.EDU
In-Reply-To: Clifford Neuman's message of Thu, 28 Jan 88 17:22:56 PST <8801290122.AA17383@june.cs.washington.edu>
Date: Thu, 28 Jan 88 17:22:56 PST
From: bcn@june.cs.washington.edu (Clifford Neuman)
The answer to Jeff's problem is to require that the response to a
request from kerberos for a ticket with a different internet address
come back encrypted in the users secret key instead of the session
key. As such, the user would be required to type in his password
again.
I'll buy off on this one...
-Jeff