[24702] in Kerberos
Re: Perl question
daemon@ATHENA.MIT.EDU (Tom Yu)
Thu Sep 22 13:56:06 2005
To: Digant C Kasundra <digant@uta.edu>
From: Tom Yu <tlyu@mit.edu>
Date: Thu, 22 Sep 2005 13:54:53 -0400
In-Reply-To: <1127411208.18435.16.camel@localizer.uta.edu> (Digant C.
Kasundra's message of "Thu, 22 Sep 2005 12:46:48 -0500")
Message-ID: <ldv64stoumq.fsf@cathode-dark-space.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: Mike Friedman <mikef@ack.berkeley.edu>
cc: Kerberos <kerberos@mit.edu>
Errors-To: kerberos-bounces@mit.edu
>>>>> "digant" == Digant C Kasundra <digant@uta.edu> writes:
digant> Ah, that work. I tried to get a ticket for kadmin/changepw
digant> instead of a TGT for the realm. Thanks for the lead!
Please remember that you need to verify the ticket you get, or else an
attacker could collude with an imposter KDC to log in. I would hope
that you do not have a key for verifying kadmin/changepw tickets on
your client machines, thus Mike's suggestion for a different principal
with that attribute set.
---Tom
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos