[27483] in Kerberos

home help back first fref pref prev next nref lref last post

Re: KfW 3.1: Re-directed stderr of kinit/klist displays dialog

daemon@ATHENA.MIT.EDU (Rodney M Dyer)
Tue Feb 20 23:16:29 2007

Message-Id: <6.1.2.0.0.20070220231042.01e37338@unccmail.uncc.edu>
Date: Tue, 20 Feb 2007 23:14:14 -0500
To: kerberos@mit.edu
From: Rodney M Dyer <rmdyer@uncc.edu>
In-Reply-To: <6.1.2.0.0.20070220220824.01e0fec0@unccmail.uncc.edu>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

At 10:24 PM 2/20/2007, Rodney M Dyer wrote:
>The MIT people simply don't want you to be able to pipe in a password to 
>kinit via "stdin", which is the right security practice (in security 
>circles), however they are rather flippant about it, because they allow it 
>under Unix.  If they feel like holding a hard line, then they should nix 
>the 'nix stdin too.

Well it appears that I'm wrong now.  Just testing this under Solaris and I 
find that piping a password to kinit no longer works!  In the intervening 
years they must have fixed this.  I politely retract my statement.  :)

Rodney 

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post