Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 4 Feb 2003 18:47:09 -0800
From:      Avleen Vig <lists-freebsd@silverwraith.com>
To:        freebsd-security@freebsd.org
Subject:   Re: krb5-realm.com
Message-ID:  <20030205024709.GC37185@silverwraith.com>

next in thread | raw e-mail | index | archive | help
On Sat, Feb 01, 2003 at 11:01:39AM +0100, bas wrote:
> isnt it a bad thing if every sshd on the world ends up contacting
> krb5-realm.com by default? is this also true for newer versions of
> sshd
> (with kerberos disabled)? i mean it may make the owners of
> krb5-realm.com powerful beings. sounds a bit .NET to me.

Well it could conceivably cause breakage (as described), but nothing
worse.  The krb5-realm.com domain administrator cannot possibly
leverage the situation in order to subvert authentication.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030205024709.GC37185>