RE: server secret
Bingner Sam J Contractor CAF CSS/SCHE <[email protected]>
| Newsgroups | gmane.network.up2date.current.devel |
|---|---|
| Message-ID | <A6B0BFA3B496A24488661CC25B9A0EFA333CE2@himl07.hickam.pacaf.ds.af.mil> |
how about: > # server_secret = text to be appended to relevant fields > # then hashed to generate a unique client > # ID that cannot be altered without this secret. -----Original Message----- From: Hunter Matthews [mailto:[email protected]] Sent: Thursday, October 10, 2002 8:39 AM To: Current Server Mailing List Subject: Re: [Current-server] server secret Its deja-vu all over again. We just did this in the archives, but here goes. How does the server know that a client hasn't surreptiously changed their sysid values, perhaps to something that the client isn't supposed to be authorized for? It checksums all the important values in the sysid, PLUS a "secret" that only the server knows. If the checksums always match, and the server secret isn't published by sending it to the list or posting on a web page, then you can assume that the sysid has not been tampered with. If somebody has suggestions about how to describe all that better, or even a better name, suggest them here. Otherwise, it'll never get better. On Thu, 2002-10-10 at 14:00, Brian K. Jones wrote: > Hi all. > > I'm a little confused about something. > > In the default current.conf file that came with the RPM distribution of > 1.4.0, there is a lot of documentation up in the top of the file, most > of which is absolutely perfect, except for this one thing that now has > me baffled: > > ~~~~~~~~ SNIP ~~~~~~~~~~~~~ > # server_secret = text to get sha1'd for systemid tokens. > # Must be kept secret, and site specific. > ~~~~~~~~~~ SNIP ~~~~~~~~~~~~~ > > What? What does "sha1'd" mean? Why do I need to 'get' this, and the > systemid tokens (client or server?)? What's at risk by not keeping this > a secret? When will I or any of my clients ever need or see this secret > again? What's going on? > > In all of my client testing thus far, I've never used the system secret > for anything but to put it in the current.conf file. > > Thanks for any input here. > brian. > -- > > Brian K. Jones > System Administrator > Dept. of Computer Science, Princeton University > http://www.linuxlaboratory.org > [email protected] > Voice: (609) 258-6080 > > _______________________________________________ > Current-server mailing list > [email protected] > http://lists.dulug.duke.edu/mailman/listinfo/current-server > > -- Hunter Matthews Unix / Network Administrator Office: BioScience 145/244 Duke Univ. Biology Department Key: F0F88438 / FFB5 34C0 B350 99A4 BB02 9779 A5DB 8B09 F0F8 8438 Never take candy from strangers. Especially on the internet. _______________________________________________ Current-server mailing list [email protected] http://lists.dulug.duke.edu/mailman/listinfo/current-server