[24702] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Perl question

daemon@ATHENA.MIT.EDU (Tom Yu)
Thu Sep 22 13:56:06 2005

To: Digant C Kasundra <digant@uta.edu>
From: Tom Yu <tlyu@mit.edu>
Date: Thu, 22 Sep 2005 13:54:53 -0400
In-Reply-To: <1127411208.18435.16.camel@localizer.uta.edu> (Digant C.
 Kasundra's message of "Thu, 22 Sep 2005 12:46:48 -0500")
Message-ID: <ldv64stoumq.fsf@cathode-dark-space.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: Mike Friedman <mikef@ack.berkeley.edu>
cc: Kerberos <kerberos@mit.edu>
Errors-To: kerberos-bounces@mit.edu

>>>>> "digant" == Digant C Kasundra <digant@uta.edu> writes:

digant> Ah, that work.  I tried to get a ticket for kadmin/changepw
digant> instead of a TGT for the realm.  Thanks for the lead!

Please remember that you need to verify the ticket you get, or else an
attacker could collude with an imposter KDC to log in.  I would hope
that you do not have a key for verifying kadmin/changepw tickets on
your client machines, thus Mike's suggestion for a different principal
with that attribute set.

---Tom
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post