RE: server secret
Hunter Matthews <[email protected]>
| Newsgroups | gmane.network.up2date.current.devel |
|---|---|
| Message-ID | <[email protected]> |
Should it still be called the 'server_secret' in 1.5? Speaketh ye now, or forever shall ye call it. On Thu, 2002-10-10 at 14:39, Bingner Sam J Contractor CAF CSS/SCHE wrote: > how about: > > # server_secret = text to be appended to relevant fields > > # then hashed to generate a unique client > > # ID that cannot be altered without this secret. > > > -----Original Message----- > From: Hunter Matthews [mailto:[email protected]] > Sent: Thursday, October 10, 2002 8:39 AM > To: Current Server Mailing List > Subject: Re: [Current-server] server secret > > > Its deja-vu all over again. > > We just did this in the archives, but here goes. > > How does the server know that a client hasn't surreptiously changed > their sysid values, perhaps to something that the client isn't supposed > to be authorized for? > > It checksums all the important values in the sysid, PLUS a "secret" that > only the server knows. > > If the checksums always match, and the server secret isn't published by > sending it to the list or posting on a web page, then you can assume > that the sysid has not been tampered with. > > If somebody has suggestions about how to describe all that better, or > even a better name, suggest them here. Otherwise, it'll never get > better. > > > On Thu, 2002-10-10 at 14:00, Brian K. Jones wrote: > > Hi all. > > > > I'm a little confused about something. > > > > In the default current.conf file that came with the RPM distribution of > > 1.4.0, there is a lot of documentation up in the top of the file, most > > of which is absolutely perfect, except for this one thing that now has > > me baffled: > > > > ~~~~~~~~ SNIP ~~~~~~~~~~~~~ > > # server_secret = text to get sha1'd for systemid tokens. > > # Must be kept secret, and site specific. > > ~~~~~~~~~~ SNIP ~~~~~~~~~~~~~ > > > > What? What does "sha1'd" mean? Why do I need to 'get' this, and the > > systemid tokens (client or server?)? What's at risk by not keeping this > > a secret? When will I or any of my clients ever need or see this secret > > again? What's going on? > > > > In all of my client testing thus far, I've never used the system secret > > for anything but to put it in the current.conf file. > > > > Thanks for any input here. > > brian. > > -- > > > > Brian K. Jones > > System Administrator > > Dept. of Computer Science, Princeton University > > http://www.linuxlaboratory.org > > [email protected] > > Voice: (609) 258-6080 > > > > _______________________________________________ > > Current-server mailing list > > [email protected] > > http://lists.dulug.duke.edu/mailman/listinfo/current-server > > > > > -- > Hunter Matthews Unix / Network Administrator > Office: BioScience 145/244 Duke Univ. Biology Department > Key: F0F88438 / FFB5 34C0 B350 99A4 BB02 9779 A5DB 8B09 F0F8 8438 > Never take candy from strangers. Especially on the internet. > > _______________________________________________ > Current-server mailing list > [email protected] > http://lists.dulug.duke.edu/mailman/listinfo/current-server > _______________________________________________ > Current-server mailing list > [email protected] > http://lists.dulug.duke.edu/mailman/listinfo/current-server > > -- Hunter Matthews Unix / Network Administrator Office: BioScience 145/244 Duke Univ. Biology Department Key: F0F88438 / FFB5 34C0 B350 99A4 BB02 9779 A5DB 8B09 F0F8 8438 Never take candy from strangers. Especially on the internet.