[8051] in Kerberos
Re: Kerberos in Java
daemon@ATHENA.MIT.EDU (le.uiu)
Thu Sep 19 14:32:14 1996
Date: Thu, 19 Sep 1996 13:28:36 -0500 (CDT)
From: "le.uiu" <ghermann@ampere.scale.uiuc.edu>
To: Doug Engert <DEEngert@anl.gov>
Cc: jaynes@umich.edu, kerberos@MIT.EDU
In-Reply-To: <199609191550.KAA34462@pembroke.ctd.anl.gov>
Well, I mean, it'd be ok, since the java stuff runs local, anyway..
but the sockets stuff on it is so trashed and protected from itself it'd
be pointless to use.
As a programming language, as well, it has a -long- way to go before it's
useful.
And trojan horses with java will likely become more popular.. It'll be
interesting.. I'd also be interested to see if anyone does anything with
server-side spoofing.. I.E. Hostname spoofing out java applets..
On Thu, 19 Sep 1996, Doug Engert wrote:
> William Jaynes writes:
> > Has anyone developed a Java class to do Kerberos authentication? I'm
> > developing server-side Java web applications and I could use something
> > pretty simplistic, that takes an id and passwd and simply returns
> > whether the password is good.
>
>
> Why, as a user, would I trust a Java application with my Kerberos
> userid and password? I might trust yours, but if users get in the
> habit of giving their password to java applications, someone else
> might WILL along and write one which looks like yours, i.e. a Trojan
> horse. You really don't ever want to send you kerberos password over
> the net.
>
> > --
> > William Jaynes |MCIT, University of Michigan Medical Center
> > jaynes@umich.edu|Arbor Lakes Building, 4251 Plymouth Rd.
> > 313-763-9039 |Ann Arbor, MI 48105-2785
>
> --
>
> Douglas E. Engert <DEEngert@anl.gov>
> Argonne National Laboratory
> 9700 South Cass Avenue
> Argonne, Illinois 60439
> (630) 252-5444 <New Area Code 8/3/96>
> PGP Key fingerprint = 20 2B 0C 78 43 8A 9C A6 29 F7 A3 6D 5E 30 A6 7F
>