home *** CD-ROM | disk | FTP | other *** search
- X-Gateway-Source-Info: INTERNET
- Path: sparky!uunet!usc!elroy.jpl.nasa.gov!ames!network.ucsd.edu!mvb.saic.com!tgv.com!info-multinet
- Date: 24 JUL 92 18:37:38 GMT
- Newsgroups: vmsnet.networks.tcp-ip.multinet
- X-Return-path: <info-multinet-relay@TGV.COM>
- X-RFC822-From: bill@nickel.ucs.sfu.ca (Bill Baines)
- From: bill@nickel.ucs.sfu.ca
- Subject: Kerberos -- is it worth doing?
- X-Mailer: ELM [version 2.3 PL11]
- Organization: The INFO-MULTINET Community
- Message-ID: <238034BD24JUL92183738@TGV.COM>
- Nntp-Posting-Host: Mvb.Saic.Com
- Lines: 50
-
- We have two networks.
-
- The administrative systems are VAX/VMS and live on an isoletd network
- that runs around the administrative building. Access from other
- buildings is via several hundred async lines, Gandalf Starmaster, and
- various terminal servers.
-
- The other network is our instructional/research network. It is ethernet
- over fiber, with 4 majour wiring centers, 52 wiring closets, and shielded
- twisted pair into every office that has a telephone. We have physical
- control of the closets, and every department is bridged or routed to the
- backbone.
-
- It would be real advantageous from a 'service' provider point of view
- if we connected these two networks together. The admin system could
- capitalize on the excellent cable plant in place for the
- instructional/research network. There is however, paranoia in the air
- about security. (myself included.)
-
- I think that we could accept that people sniffing the network might
- see administrative data. Most of that data is available in the library
- anyways. We cannot however implement something that might allow
- 'sniffers' to gather passwords.
-
- I know that TGV has some Kerberos software in Beta somewhere. We
- played with Kerberos some years ago, and have an old IBM RT that we
- could dedicate to the task. We can provide a second ethernet controller
- on the Admin system and connect it to the big network, and load only TGV --
- no decnet, no lat, no anything else. We would only allow inbound
- telnet and smtp mail access. We would like to disable all other
- IP ports if possible.
-
- 1) Will it help our situation? i.e. Can passwords ber made less apparent
- to the casual sniffer?
-
- 2) What telnet clients are available that have been tested with TGV's
- implementation? (Our clients use Macs, PC,s Suns, NeXTstations, and
- some Iris Indigos.
-
- 3) Would you do this in a University?
-
- 4) Comments and suggestions about alternate methods would be appreciated. A
- while back we took a look at DEC's hdwr encryptoion box, but it only
- allowed 20 clients per port on the back side, and was a tad expensive
- in Canada.
-
-
- -- Bill Baines, Operations and Tech.
- Support, Simon Fraser University, bill@sfu.ca, bill@SFUVAX.Bitnet,
- (604) 291-3955, (fax 291-4242), VE7FML
-