RE: server secret

Hunter Matthews <[email protected]>
Newsgroups gmane.network.up2date.current.devel
Message-ID <[email protected]>
Should it still be called the 'server_secret' in 1.5? 

Speaketh ye now, or forever shall ye call it.


On Thu, 2002-10-10 at 14:39, Bingner Sam J Contractor CAF CSS/SCHE
wrote:
> how about:
> > # server_secret = text to be appended to relevant fields
> > #                 then hashed to generate a unique client
> > #                 ID that cannot be altered without this secret.
> 
> 
> -----Original Message-----
> From: Hunter Matthews [mailto:[email protected]]
> Sent: Thursday, October 10, 2002 8:39 AM
> To: Current Server Mailing List
> Subject: Re: [Current-server] server secret
> 
> 
> Its deja-vu all over again.
> 
> We just did this in the archives, but here goes.
> 
> How does the server know that a client hasn't surreptiously changed
> their sysid values, perhaps to something that the client isn't supposed
> to be authorized for? 
> 
> It checksums all the important values in the sysid, PLUS a "secret" that
> only the server knows. 
> 
> If the checksums always match, and the server secret isn't published by
> sending it to the list or posting on a web page, then you can assume
> that the sysid has not been tampered with.
> 
> If somebody has suggestions about how to describe all that better, or
> even a better name, suggest them here. Otherwise, it'll never get
> better.
> 
> 
> On Thu, 2002-10-10 at 14:00, Brian K. Jones wrote:
> > Hi all.
> > 
> > I'm a little confused about something.
> > 
> > In the default current.conf file that came with the RPM distribution of
> > 1.4.0, there is a lot of documentation up in the top of the file, most
> > of which is absolutely perfect, except for this one thing that now has
> > me baffled:
> > 
> > ~~~~~~~~ SNIP ~~~~~~~~~~~~~
> > # server_secret = text to get sha1'd for systemid tokens.
> > #                 Must be kept secret, and site specific.
> > ~~~~~~~~~~ SNIP ~~~~~~~~~~~~~
> > 
> > What?  What does "sha1'd" mean?  Why do I need to 'get' this, and the
> > systemid tokens (client or server?)?  What's at risk by not keeping this
> > a secret?  When will I or any of my clients ever need or see this secret
> > again?  What's going on? 
> > 
> > In all of my client testing thus far, I've never used the system secret
> > for anything but to put it in the current.conf file.  
> > 
> > Thanks for any input here.
> > brian.
> > -- 
> > 
> > Brian K. Jones
> > System Administrator
> > Dept. of Computer Science, Princeton University
> > http://www.linuxlaboratory.org
> > [email protected]
> > Voice: (609) 258-6080
> > 
> > _______________________________________________
> > Current-server mailing list
> > [email protected]
> > http://lists.dulug.duke.edu/mailman/listinfo/current-server
> > 
> > 
> -- 
> Hunter Matthews                          Unix / Network Administrator
> Office: BioScience 145/244               Duke Univ. Biology Department
> Key: F0F88438 / FFB5 34C0 B350 99A4 BB02  9779 A5DB 8B09 F0F8 8438
> Never take candy from strangers. Especially on the internet.
> 
> _______________________________________________
> Current-server mailing list
> [email protected]
> http://lists.dulug.duke.edu/mailman/listinfo/current-server
> _______________________________________________
> Current-server mailing list
> [email protected]
> http://lists.dulug.duke.edu/mailman/listinfo/current-server
> 
> 
-- 
Hunter Matthews                          Unix / Network Administrator
Office: BioScience 145/244               Duke Univ. Biology Department
Key: F0F88438 / FFB5 34C0 B350 99A4 BB02  9779 A5DB 8B09 F0F8 8438
Never take candy from strangers. Especially on the internet.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.