[8065] in Kerberos
Re: Can't forward credentials with beta7
daemon@ATHENA.MIT.EDU (Ken Raeburn)
Thu Sep 19 21:29:00 1996
To: Sam Hartman <hartmans@MIT.EDU>
Cc: mbeattie@sable.ox.ac.uk (Malcolm Beattie), kerberos@MIT.EDU
From: Ken Raeburn <raeburn@cygnus.com>
Date: 19 Sep 1996 21:17:29 -0400
In-Reply-To: Sam Hartman's message of 19 Sep 1996 15:07:20 -0400
> The inability to forward credentials was introduced by a
> last-minute (well, last-hour at least) patch to fix a political bug.
> Basically, there was a potential security problem if /tmp didn't have
> the sticky bit set and you run login.krb5. This isn't really a
> problem because many other products and other parts of Kerberos assume
> that/tmp has the sticky bit set.
That's why I wasn't too concerned by this point when I looked over the
patch for Barry.
> This is fairly substantially my fault as I had an opportunity
> to audit the patch and missed the fairly obvious fact that it
> completely broke forwarding tickets.
I didn't even notice that. I recommended not using it because it
appeared to prevent Kerberos-authenticated logins in certain cases
when /tmp is overfull. (If the ccache can't be rewritten as the user,
login exits.) But I was about 10 minutes late in getting my response
back to MIT...