[7960] in Kerberos
Re: Kerberos 5 and S/Key
daemon@ATHENA.MIT.EDU (Jacques Vidrine)
Sat Sep 14 18:13:24 1996
Date: Sat, 14 Sep 1996 16:59:52 -0500 (CDT)
From: Jacques Vidrine <nectar@communique.net>
To: Michael Stein <mas@ucla.edu>
Cc: kerberos@MIT.EDU
In-Reply-To: <51bpan$cv2@uni.library.ucla.edu>
So that someone may log in to a computer from the Internet without
exposing his/her password.
Presumably, there could be a key that the S/Key service could use for
decrypting the TGT.
Jacques Vidrine <nectar@communique.net> Communique, Inc.
On Fri, 13 Sep 1996, Michael Stein wrote:
> nectar@kai.communique.net (Jacques Vidrine) wrote:
>
>
> >Can a user get a TGT when authenticating via S/Key? It seems that
> >this should be possible, but I imagine that it would require some
> >integration between Kerberos 5 and S/Key.
>
> /disclaimer: I'm new to kerberos, I've used S/Key/
>
> What's the point? My understanding of Kerberos is that anyone can
> request a TGT from the kerberos security server, but the reply is
> going to be encrypted in the users secret key (his password).
>
> Can you decrypt a TGT in your head?
>
> If not then you are going to have to tell the local machine your
> password so that it can decrypt the TGT.
>
> What was the purpose of using S/Key instead?
>
>
>