[8057] in Kerberos
Re: Fw: keberos@mit.edu
daemon@ATHENA.MIT.EDU (Sam Hartman)
Thu Sep 19 15:46:05 1996
To: georgesr@wrq.com
Cc: kerberos@MIT.EDU
From: Sam Hartman <hartmans@MIT.EDU>
Date: 19 Sep 1996 15:32:50 -0400
In-Reply-To: georgesr@wrq.com's message of Wed, 18 Sep 1996 09:21:51 -0700
>>>>> "georgesr" == georgesr <georgesr@wrq.com> writes:
georgesr> Note: What was the rational behind all these changes to
georgesr> telnet? Can anyone please give a little detail. Thank
georgesr> you.
The checksums are used to provide enhanced security for
encrypted session startup. The rlogin and rsh daemons have an option
to turn off checksum support, and it might be reasonable to provide an
option to do this on telnetd. However, you should really try to move
away from old clients so you can take advantage of the enhanced
security.
The mutual authentication key change was caused by a change in
the krb5 library. I think the Beta 7 telnetd violates the spec, but
it may be the Beta 4 client that is wrong. Since the telnet
authentication spec needs to be changed for various reasons anyway,
and since the new behavior is more consistent with other applications,
I wouldn't mind seeing the spec change to reflect the current behavior.
georgesr> Regards Georges Rahbani (LFI, FAS, Chapman, GTC,
georgesr> ... grad.) Reflection Secure Group Walker Richer &
georgesr> Quinn, Inc. georgesr@wrq.com
georgesr> ---- End of forwarded message ---- Georges Rahbani (LFI,
georgesr> FAS, Chapman, GTC, ... grad.) Reflection Secure Group
georgesr> Walker Richer & Quinn, Inc. georgesr@wrq.com