[24704] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Perl question

daemon@ATHENA.MIT.EDU (Digant C Kasundra)
Thu Sep 22 16:20:04 2005

From: Digant C Kasundra <digant@uta.edu>
To: Tom Yu <tlyu@mit.edu>
In-Reply-To: <ldv64stoumq.fsf@cathode-dark-space.mit.edu>
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
Date: Thu, 22 Sep 2005 15:19:05 -0500
Message-Id: <1127420345.18435.20.camel@localizer.uta.edu>
Mime-Version: 1.0
cc: Mike Friedman <mikef@ack.berkeley.edu>
cc: Kerberos <kerberos@mit.edu>
Errors-To: kerberos-bounces@mit.edu

Actually, I lied.  I did create a new service/checkpw principal and gave
it the pw change service flag and that's what I'm using to check the
password.  I should probably verify that ticket with a keytab.


On Thu, 2005-09-22 at 13:54 -0400, Tom Yu wrote:
> >>>>> "digant" == Digant C Kasundra <digant@uta.edu> writes:
> 
> digant> Ah, that work.  I tried to get a ticket for kadmin/changepw
> digant> instead of a TGT for the realm.  Thanks for the lead!
> 
> Please remember that you need to verify the ticket you get, or else an
> attacker could collude with an imposter KDC to log in.  I would hope
> that you do not have a key for verifying kadmin/changepw tickets on
> your client machines, thus Mike's suggestion for a different principal
> with that attribute set.
> 
> ---Tom
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post