Re: IPsec vs SSH (Was Re: in.telnetd vulnerability??)

From: Darren Moffat (Darren.Moffat@eng.sun.com)
Date: 08/04/01


Message-Id: <200108032220.f73MKlb108230@jurassic.eng.sun.com>
Date: Fri, 3 Aug 2001 15:19:29 -0700 (PDT)
From: Darren Moffat <Darren.Moffat@eng.sun.com>
Subject: Re: IPsec vs SSH (Was Re: in.telnetd vulnerability??)
To: adam@gmi.com


>is kerberos pretty easy to configure and manage? straightforward? the one
>thing i remember about kerberos is that one has to login to ones key or get
>their ticket or something to that effect. or is that handled on login?

On Solaris you don't need to do the kinit because it can be handled by
the pam_krb5 module when you login via dtlogin or telnet/rlogin etc.

Personally I don't think kerberos is any more difficult to manage than
NIS but then I'm pretty familiar with it and I also think NIS+ is easier
than NIS but I know NIS and NIS+ at the code level too so I'm not a good
one to judge how easy they are to use for a sysadmin.

Kerberos setup is well documented in on docs.sun.com, just search for
SEAM and this will tell you everything from the KDC setup to setup of
telnetd and NFS.

Given what you said though I think IPsec is probably more where you
should be going if you have traffic other than "remote login" and NFS.

--
Darren J Moffat



Relevant Pages

  • Re: Solaris 10 ssh logins + w2k3 AD native mode
    ... SEAM, Kerberos). ... Unix system to map from the AD user attributes ... a Unix login session. ... Does putty support GSSAPI authentication for SSH and can it ...
    (comp.protocols.kerberos)
  • RE: Passwords with Lan Manager (LM) under Windows
    ... First "You can't precompile that data into a rainbow, ... As I said earlier "Kerberos support with IPsec" And by this yes ... Passwords with Lan Manager under Windows ...
    (Pen-Test)
  • Re: IPSec without encryption between intranet and standalone
    ... I've also unassinged the IPSec polcy and instantly the 'lag' disappears ... I was not aware I could enter a nonsense string as a shared ... security associations (Kerberos and talk of shared key). ... If I used a sharedkey how ...
    (microsoft.public.win2000.security)
  • Re: Problem with kerberos telnet option
    ... I am trying to setup a test kdc server and workstation. ... After I did the setup I can login as user5 using the kerberos ... from ssh from station6 to station5 it request another login. ...
    (comp.protocols.kerberos)
  • Re: Unexplained Failed Logins
    ... if the DC is attempting a login via a delegation, ... and directly attempt Kerberos authN on network exposed ... authentication which would show IIS and use NTLM. ... Can you suggest any other places/logs to check for external activity? ...
    (microsoft.public.win2000.security)