[OpenAFS] krb4 3des vulnerability

Brent Johnson Brent.A.Johnson@jpl.nasa.gov
Mon, 17 Mar 2003 11:18:24 -0800


Hello,

So does this mean if you're using kaserver you're vulnerable to this?

Does kaserver use 3des encryption?  Is there any way to turn cross-realm 
authentication off?

http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt

-Brent

-- 
Brent A. Johnson
JPL File Services Engineer
Jet Propulsion Laboratory 
Telephone: 4-2138 or 818-354-2138	Pager: 1-800-759-8888 PIN=1256866