[27714] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos and one-time-passwords

daemon@ATHENA.MIT.EDU (Russ Allbery)
Thu Apr 26 14:12:15 2007

From: Russ Allbery <rra@stanford.edu>
To: kerberos@mit.edu
In-Reply-To: <20070426135133.6f15e587@tyne.cl.cam.ac.uk> (Ian Grant's message
	of "Thu, 26 Apr 2007 13:51:33 +0100")
Date: Thu, 26 Apr 2007 11:08:49 -0700
Message-ID: <87r6q7ovny.fsf@windlord.stanford.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Ian Grant <Ian.Grant@cl.cam.ac.uk> writes:

> If we allow users kerberised access to their home directories over NFS
> we would like them to be able to login to machines from remote hosts
> without exposing their kerberos keys. The only secure way seems to be
> via one-time-passwords.

I would use GSSAPI-authenticated ssh?  Hm.  I wonder if SecureCRT can do
ticket forwarding, though.  It would work great from Unix systems, at
least.

> Are there any alternatives whereby a trusted agent (daemon) can be
> given user's keytabs and can use them to get tickets on the user's
> behalf after the users authenticate using one time passwords?

Well, you can use:

    http://www.eyrie.org/~eagle/software/kstart/

to do the Kerberos authentication part if you work out the OTP part.  But
you have to trust the system with password equivalents for all of the
users, which seems to somewhat defeat the point.

-- 
Russ Allbery (rra@stanford.edu)             <http://www.eyrie.org/~eagle/>
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post