home *** CD-ROM | disk | FTP | other *** search
- X-Gateway-Source-Info: INTERNET
- Path: sparky!uunet!munnari.oz.au!network.ucsd.edu!mvb.saic.com!tgv.com!info-multinet
- Date: 28 JUL 92 12:48:36 GMT
- Newsgroups: vmsnet.networks.tcp-ip.multinet
- X-Return-path: <info-multinet-relay@TGV.COM>
- X-RFC822-From: "L. Stuart Vance" <VANCE@TGV.COM>
- From: "L. Stuart Vance" <VANCE@TGV.COM>
- Subject: Re: Kerberos -- is it worth doing?
- Message-ID: <712317216.351000.VANCE@TGV.COM>
- Organization: TGV, Incorporated
- X-Phone: 408/427-4366 (work); 408/427-4365 (fax)
- X-Address: 603 Mission Street; Santa Cruz, CA 95060 (work)
- Nntp-Posting-Host: Mvb.Saic.Com
- Lines: 37
-
- >I know that TGV has some Kerberos software in Beta somewhere. We
- >played with Kerberos some years ago, and have an old IBM RT that we
- >could dedicate to the task. We can provide a second ethernet controller
- >on the Admin system and connect it to the big network, and load only TGV --
- >no decnet, no lat, no anything else. We would only allow inbound
- >telnet and smtp mail access. We would like to disable all other
- >IP ports if possible.
- >
- >1) Will it help our situation? i.e. Can passwords ber made less apparent
- > to the casual sniffer?
-
- Kerberized TELNET (not likely to be generally available on all platforms) and
- KLOGIN will allow you to interactively log in from one system to another
- without sending cleartext passwords over the network. Similarly KCP and KSH
- (Kerberized RCP and RSH) give you more secure remote file copying and remote
- command execution. Of course, any data flying between the two systems will
- still be readable via an Ethernet protocol analyzer.
-
- >2) What telnet clients are available that have been tested with TGV's
- > implementation? (Our clients use Macs, PC,s Suns, NeXTstations, and
- > some Iris Indigos.
-
- The TELNET authentication option is still in draft format. We support the
- current draft, but I doubt too many other vendors will be shipping support
- until the spec is at least published as an experimental standard RFC.
-
- >3) Would you do this in a University?
-
- Depends on the application. If you are running RLOGIN/TELNET to access student
- records over the network, then I would NOT recommend using Kerberos until
- we/other companies ship encryption support for KLOGIN, KCP, and KSH (next on
- our list after we get the first MultiNet Authentication Services distribution
- out the door). There is currently no spec for a standard TELNET encryption
- option (although it is in the works).
-
- Regards,
- -----Stuart
-