[24704] in Kerberos
Re: Perl question
daemon@ATHENA.MIT.EDU (Digant C Kasundra)
Thu Sep 22 16:20:04 2005
From: Digant C Kasundra <digant@uta.edu>
To: Tom Yu <tlyu@mit.edu>
In-Reply-To: <ldv64stoumq.fsf@cathode-dark-space.mit.edu>
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
Date: Thu, 22 Sep 2005 15:19:05 -0500
Message-Id: <1127420345.18435.20.camel@localizer.uta.edu>
Mime-Version: 1.0
cc: Mike Friedman <mikef@ack.berkeley.edu>
cc: Kerberos <kerberos@mit.edu>
Errors-To: kerberos-bounces@mit.edu
Actually, I lied. I did create a new service/checkpw principal and gave
it the pw change service flag and that's what I'm using to check the
password. I should probably verify that ticket with a keytab.
On Thu, 2005-09-22 at 13:54 -0400, Tom Yu wrote:
> >>>>> "digant" == Digant C Kasundra <digant@uta.edu> writes:
>
> digant> Ah, that work. I tried to get a ticket for kadmin/changepw
> digant> instead of a TGT for the realm. Thanks for the lead!
>
> Please remember that you need to verify the ticket you get, or else an
> attacker could collude with an imposter KDC to log in. I would hope
> that you do not have a key for verifying kadmin/changepw tickets on
> your client machines, thus Mike's suggestion for a different principal
> with that attribute set.
>
> ---Tom
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos