[8060] in Kerberos
Re: Fw: keberos@mit.edu
daemon@ATHENA.MIT.EDU (Sam Hartman)
Thu Sep 19 17:05:09 1996
To: georgesr@wrq.com
Cc: kerberos@MIT.EDU
From: Sam Hartman <hartmans@MIT.EDU>
Date: 19 Sep 1996 16:45:27 -0400
In-Reply-To: georgesr@wrq.com's message of Thu, 19 Sep 1996 12:58:49 -0700
>>>>> "georgesr" == georgesr <georgesr@wrq.com> writes:
georgesr> Thank you Sam for your reply on the telnet questions I
georgesr> had. However I still have couple more questions
georgesr> I agree that a checksum is good to enhance
georgesr> authentication. However at this time it still looks
georgesr> pretty week in telnet since it checksums a known value
georgesr> (i.e. two bytes) and the checksum itself is CRC32
georgesr> (granted that it is included in the encrypted
georgesr> ap_req). Does this mean that future telnet clients can
georgesr> be configured to use stronger checksums (like
georgesr> RSA_DES_MD5)?
I certainly think that the strength of the checksum will
improve, although I don't expect telnet to benefit much from this. As
you point out, it's a known value being checksumed, so the benefit of
a cryptographic checksum is not likely to be very great. It's not a
major problem since the checksum is encrypted in the authenticator.
I see a need for new telnet authentication spec about a year
ago. I do not know of anyone who is close to getting them to happen.
I do not know of any product (comercial or otherwise) who actually
follows current specs.
--Sam
georgesr> Also my concern (which I am dealing with
georgesr> anyway) is that, there are commercial telnetd out there
georgesr> that use the older stuff. And I (like others) have to
georgesr> support both versions in my clients. At this time I
georgesr> succeeded to make my telnet client work with both
georgesr> versions and I see the benefit of the newer stuff. So
georgesr> in short, do you forsee new telnet authentication specs
georgesr> comming out in the near future? Thank you again for
georgesr> your reply Regards Georges Rahbani (LFI, FAS, Chapman,
georgesr> GTC, ... grad.) Reflection Secure Group Walker Richer &
georgesr> Quinn, Inc. georgesr@wrq.com