] Several cryptographic vulnerabilities exist in the basic ] Kerberos Version 4 protocol that could allow an attacker ] to impersonate any user in a Kerberos realm and gain any ] privilege authorized through that Kerberos realm. ] Knowledge of the key shared between two realms for ] Kerberos 4 cross-realm authentication or the ability to ] create arbitrary principals in a realm is sufficient to ] print any ticket in the realm. Maybe this will finally kill krb4 ... AFS has been the big holdout and its finally starting to get krb5 support though it only works with MIT krb5 and not heimdal (from kth.se) right now. |