Re: HEADS UP! Kerberos5/Heimdal now default!

From: Craig Boston <craig_at_xfoil.gank.org>
Date: 05 May 2003 15:01:16 -0500
Man, I am losing my mind today.  Please disregard, stable -- meant to
send to current_at_

Sorry for the noise

On Mon, 2003-05-05 at 14:59, Craig Boston wrote:
> Sorry for the dupe Garrett, forgot to copy the list......
> 
> > What ``extremely colorful history of ... vulnerabilities''?  I can
> > think of no more than five times I've had to rebuild my KDC in six
> > years.
> 
> ...and nearly every security advisory I've seen for Kerberos 5 in the
> last year or two was actually for the Kerberos 4 compatibility code. 
> One of the reasons I always build the port with "KRB5_KRB4_COMPAT=NO".
> 
> The only exception I can think of at the moment was the XDR/RPC buffer
> overflow, which hit a LOT of software.
> 
> Craig
Received on Mon May 05 2003 - 11:01:25 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:37:06 UTC