[24869] in Kerberos

home help back first fref pref prev next nref lref last post

How do you have your Kerberos service set up?

daemon@ATHENA.MIT.EDU (Daniel Henninger)
Mon Oct 31 15:13:13 2005

Mime-Version: 1.0 (Apple Message framework v734)
Content-Transfer-Encoding: 7bit
Message-Id: <EBB71BBD-F529-477B-9EAA-5BE1375F30C9@ncsu.edu>
Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed
To: kerberos@mit.edu
From: Daniel Henninger <daniel@ncsu.edu>
Date: Mon, 31 Oct 2005 15:13:11 -0500
Errors-To: kerberos-bounces@mit.edu

Howdy folk,

We have been pressured recently about how our Kerberos service is  
"insecure" because it does not account for folk failing to type the  
right password in X number of times, or something like that.   
(intrusion detection)  Like, why doesn't the account "lock" at that  
point because 'clearly someone is trying to break in at that point'.   
So, first off, let me describe our setup.  We have a single master  
kerberos server, replicated to 6 slaves.  Now, if I look in our  
database at various entries, I can see the "last password failure"  
and such fields, and have seen that there is a lot of functionality  
present in Kerberos for handling situations like this.  However, what  
I'm also to understand is that this requires only writable Kerberos  
servers.  (in other words, no slaves)  Dropping to a single writable 
(master) kerberos server and no slaves just flat out makes me  
nervous, and doesn't seem like a good idea.  So... what then?  Are  
you stuck with the decision of:

A. replicated redundant authentication service, no 'intrusion detection'
B. intrusion detection, but no replication or redundancy

What are other universities and/or corporations doing?  MIT, my  
apologies for singling you out, but would you mind describing your  
own set up a bit and if you have run into this issue before/what you  
did about it/etc?

Thanks for any thoughts anyone might have!

Daniel

-- 
Daniel Henninger <daniel@ncsu.edu>
Systems Programmer
Information Technology Division


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post