Rather than going back and forth, might I refer anyone interested to
the documents available on the subject of Kerberos security [and AFS].
Kerberos: An Authentication Service for Open Network Systems
Jennifer G. Steiner, Clifford Neuman, Jeffrey I. Schiller
athena-dist.mit.edu:/pub/kerberos/doc/usenix.PS
Limitations of the Kerberos Authentication System
Steven M. Bellovin, Michael Merritt
research.att.com:/dist/internet_security/kerblimit.usenix.ps
Hijacking AFS
P. Honeyman, L.B. Huston, M.T. Stolarchuk
ftp.sage.usenix.org:/pub/usenix/winter92/hijacking-afs.ps.Z
A bibliography of other papers and information can be found in the
comp.protocols.kerberos FAQ - "Kerberos Users' Frequently Asked Questions"
which is available for via ftp from:
rtfm.mit.edu:/pub/usenet/news.answers/kerberos-faq/user
Aydin
Follow-Ups:
|
|