[25198] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Common keytab file for all the application servers - Is

daemon@ATHENA.MIT.EDU (Markus Moeller)
Tue Jan 3 15:04:33 2006

From: "Markus Moeller" <huaraz@moeller.plus.com>
Date: Mon, 2 Jan 2006 12:03:35 -0000
Message-ID: <43b91697$0$2678$ed2619ec@ptn-nntp-reader02.plus.net>
To: kerberos@mit.edu
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

If you use the same keytab, the compromise of one device means you loose the 
security of all devices as the keytab can be used to sniff the traffic.

Markus

""Barbat, Calin"" <c.barbat@osram.de> wrote in message 
news:60DE0C5FDA5A594EAB0F71425A0A3CEF03B996@exc-mch01.mch.osram.de...
> Hi Sandy,
>
> of course you can use the same keytab on every device. At least, I can't
> see why it should not be possible - technically
> speaking. You should only consider if you want this scenario - all 100
> devices connecting as the same user.
>
> Try it with 2 devices first - copy the same keytab to both of them, then
> interact with them, it should work fine.
>
> Best regards,
>
> - Calin.
>
> ________________________________________________
> Kerberos mailing list           Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
> 


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post