Re: Does MIT Kerberos flaw extend to MS Kerberos?

From: Joe Richards [MVP] (humorexpress@hotmail.com)
Date: 11/01/02


From: "Joe Richards [MVP]" <humorexpress@hotmail.com>
Date: Fri, 1 Nov 2002 00:06:38 -0500


The company I work for received a broadcast from our MS Premier Support TAM
that this does NOT affect MS Kerberos.

--
---
Joe Richards
www.joeware.net
---
"J Michael Workman" <jworkman@mitre.org> wrote in message
news:7c8d01c280fb$e5e482e0$35ef2ecf@TKMSFTNGXA11...
> I would like to get the word out to a few people that
> sometimes listen to me about the MIT Kerberos 5 flaw
> reported in the last few days.
>
> It is my take that this should not affect Microsoft's
> Kerberos 5 implementation since MSKerb5 is not
> interoperable with non-MS Kerb 4.
>
> Can someone confirm this?
>
> The description of the security flaw can be found at
>     http://www.cert.org/advisories/CA-2002-29.html
>
> Thanks,
>
> Mike Workman