Re: Wishlist: credential file update/access collision avoidance?

[email protected]
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Message-ID <[email protected]>
On Mon, Oct 03, 2011 at 03:19:37PM +0200, Harald Barth wrote:
> >> So I do not suggest putting ccaches on distributed file systems as a
> >> default, this should be done with great care, but nothing says
> >> that it is impossible, never useful or inherently insecure.
> 
> The likelyhood that such a credential is snatched from the user is
> much higher, isn't it? Even if you can ensure that your network file
> system has "sufficient" encryption.

Right. As I said above, it should be exercised with great care (as with
everything where distributed access is involved).

Otherwise, as long as the file system in question is more valuable or
the main part of what the tickets allow to access, the resulting
setup will not become more vulnerable.

I have a distributed file system which is stronger than some of
the tickets I use every day.  May be it is unusual but it is a real
situation. I could put the tickets there without losing any security
but gaining usability.

YMMV depending on the actual setup details, so do not follow this approach
lightly. My point is that this should not be disallowed by design,
that's it.

> Just as a side track: What about using Linux keyrings as credential
> caches for computers which do not have any local file system and where
> you don't want to have a tmpfs just for credential caches?

I'd rather run a (lightweight which it ought to be) credentials server.
This would be more portable and maintainable (and documentable, too,
without a need to refer to platform-specific features; hence actually
more secure in the long run).

Regards,
Rune
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.