Re: SSH and The requires_pre_auth attribute

Russ Allbery <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.general
Organization The Eyrie
Message-ID <[email protected]>
"Dan Mahoney (Gushi)" <[email protected]> writes:

> 1) Is my "if it's on the host entry, it must be on the user entry" 
> basically accurate?

Yes.

Therefore, because of this, unless you are *certain* that every principal
that needs to authenticate to another principal will have requires
pre-auth set, you should not set requires pre-auth on server principals.

There is in general no strong reason to set requires pre-auth on
randomly-generated keys unless you want to force exactly this client
behavior.  Yes, not having it set means that in theory an attacker can try
to brute-force the randomly-generated key, but... it's randomly generated.
So if there is any realistic chance of success in this, you have much
larger problems.

(I don't have off-the-cuff answers to your other questions.)

-- 
Russ Allbery ([email protected])             <https://www.eyrie.org/~eagle/>
________________________________________________
Kerberos mailing list           [email protected]
https://mailman.mit.edu/mailman/listinfo/kerberos
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.