Re: [OpenAFS] Re: [OpenAFS-announce] OpenAFS Security Advisory 2013-0003

2013-07-24 Thread Benjamin Kaduk
On Wed, 24 Jul 2013, Douglas E. Engert wrote: On 7/24/2013 11:10 AM, Benjamin Kaduk wrote: On Wed, 24 Jul 2013, Douglas E. Engert wrote: Question: Once the 1.6.5 binaries are in place, and the servers start using the rxkad.keytab, will the server still accept existing DES based tokens that

Re: [OpenAFS] Re: [OpenAFS-announce] OpenAFS Security Advisory 2013-0003

2013-07-24 Thread Douglas E. Engert
On 7/24/2013 11:10 AM, Benjamin Kaduk wrote: On Wed, 24 Jul 2013, Douglas E. Engert wrote: Question: Once the 1.6.5 binaries are in place, and the servers start using the rxkad.keytab, will the server still accept existing DES based tokens that use keys and kvno that are only in the KeyFile?

Re: [OpenAFS] Re: [OpenAFS-announce] OpenAFS Security Advisory 2013-0003

2013-07-24 Thread Benjamin Kaduk
On Wed, 24 Jul 2013, Douglas E. Engert wrote: Question: Once the 1.6.5 binaries are in place, and the servers start using the rxkad.keytab, will the server still accept existing DES based tokens that use keys and kvno that are only in the KeyFile? Yes. In fact, the code path for tokens using

[OpenAFS] Re: [OpenAFS-announce] OpenAFS Security Advisory 2013-0003

2013-07-24 Thread Douglas E. Engert
Question: Once the 1.6.5 binaries are in place, and the servers start using the rxkad.keytab, will the server still accept existing DES based tokens that use keys and kvno that are only in the KeyFile? On 7/24/2013 9:05 AM, Simon Wilkinson wrote: OpenAFS Security Advisory 2013-0003 Topic: Bru