[8065] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Can't forward credentials with beta7

daemon@ATHENA.MIT.EDU (Ken Raeburn)
Thu Sep 19 21:29:00 1996

To: Sam Hartman <hartmans@MIT.EDU>
Cc: mbeattie@sable.ox.ac.uk (Malcolm Beattie), kerberos@MIT.EDU
From: Ken Raeburn <raeburn@cygnus.com>
Date: 19 Sep 1996 21:17:29 -0400
In-Reply-To: Sam Hartman's message of 19 Sep 1996 15:07:20 -0400


> 	The inability to forward credentials was introduced by a
> last-minute (well, last-hour at least) patch to fix a political bug.
> Basically, there was a potential security problem if /tmp didn't have
> the sticky bit set and you run login.krb5.  This isn't really a
> problem because many other products and other parts of Kerberos assume
> that/tmp has the sticky bit set.  

That's why I wasn't too concerned by this point when I looked over the
patch for Barry.

> 	This is fairly substantially my fault as I had an opportunity
> to audit the patch and missed the fairly obvious fact that it
> completely broke forwarding tickets.

I didn't even notice that.  I recommended not using it because it
appeared to prevent Kerberos-authenticated logins in certain cases
when /tmp is overfull.  (If the ccache can't be rewritten as the user,
login exits.)  But I was about 10 minutes late in getting my response
back to MIT...

home help back first fref pref prev next nref lref last post