Re: [HACKERS] [PATCHES] Removing Kerberos 4 - Mailing list pgsql-general

From Greg Stark
Subject Re: [HACKERS] [PATCHES] Removing Kerberos 4
Date
Msg-id 87br5yyxvx.fsf@stark.xeocode.com
Whole thread Raw
In response to Re: [PATCHES] Removing Kerberos 4  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-general
Tom Lane <tgl@sss.pgh.pa.us> writes:

> Last chance for any Kerberos 4 users to speak up --- otherwise I'll
> apply this soon.

If you just want someone to test it I can do that. I don't actually use it
normally though.

As far as security issues the only issues I'm aware of is a) it uses plain DES
which is just a 56 bit key and crackable by brute force and b) cross-domain
authentication is broken.

But if you just have a single domain it's a lot simpler to set up than the
poster child for second system effect, Kerberos 5.

--
greg

pgsql-general by date:

Previous
From: "Peter Darley"
Date:
Subject: Perl DBI issue
Next
From: "David Parker"
Date:
Subject: dump/restore bytea fields