URG: PKINIT error

2010-02-16 Thread vinay kumar
Hi all, I am implementing PKINIT. My krb5.conf and kdc.conf are as follows *krb5.conf [logging] default = FILE:/var/log/krb5libs.log kdc = FILE:/var/log/krb5kdc.log admin_server = FILE:/var/log/kadmind.log [libdefaults] ticket_lifetime = 24000 default_realm

Re: URG: PKINIT error

2010-02-16 Thread Kevin Coffman
On Tue, Feb 16, 2010 at 1:30 AM, vinay kumar wrote: > Hi all, > >         I am implementing PKINIT. My krb5.conf and kdc.conf are as follows > > *krb5.conf > [logging] >  default = FILE:/var/log/krb5libs.log >  kdc = FILE:/var/log/krb5kdc.log >  admin_server = FILE:/var/log

MITKRB5-SA-2010-001 [CVE-2010-0283] krb5-1.7 KDC denial of service

2010-02-16 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 MITKRB5-SA-2010-001 MIT krb5 Security Advisory 2010-001 Original release: 2010-02-16 Last update: 2010-02-16 Topic: krb5-1.7 KDC denial of service CVE-2010-0283 krb5-1.7 KDC denial of service CVSSv2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:O/RC:C

krb5-strength 1.0 released

2010-02-16 Thread Russ Allbery
I'm pleased to announce release 1.0 of krb5-strength. krb5-strength provides mechanisms for checking the strength of Kerberos passwords against an external dictionary when a user changes passwords in a Kerberos KDC. It is roughly equivalent to checking password strength via CrackLib, except that