Re: Cannot get [password_quality] to work with 7.5.0 on Debian buster

2018-11-03 Thread Russ Allbery
> How do I configure it so that heimdal respects the [password_quality] > stanza? Password changes by administrators bypass all password quality checks on Heimdal without https://github.com/heimdal/heimdal/pull/320, which was applied locally to Stanford's build of Heimdal. -

Re: How to disable DNS lookups?

2017-07-26 Thread Russ Allbery
ly overrides everything without having to hunt down software-specific configuration files. -- Russ Allbery (ea...@eyrie.org) <http://www.eyrie.org/~eagle/>

Re: How to disable DNS lookups?

2017-07-25 Thread Russ Allbery
Russ Allbery writes: > My mental model of how an implementation that uses SRV records works is > that it does a SRV query to find the list of hosts and weights, and then, > for each host in weight order, does a gethostinfo(3) call on that > hostname. Apologies, that of course was su

Re: How to disable DNS lookups?

2017-07-25 Thread Russ Allbery
hat people can override their /etc/krb5.conf instead, and now that I know about this I suspect I will be able to make my systems do the right thing, but /etc/hosts is convenient because it overrides *all software* (as opposed to making you go hunt down some specific config file for each piece of soft

Re: How to disable DNS lookups?

2017-07-25 Thread Russ Allbery
andard nsswitch configuration. Now, perhaps my mental model is wrong for a given implementation, but (a) the resulting behavior is very useful for testing and something I've used for years, and (b) it's not an *unreasonable* mental model, or particularly confusing. -- Russ Allbery (ea...@

Re: How to disable DNS lookups?

2017-07-25 Thread Russ Allbery
ss of a host in /etc/hosts, and I expect all software to honor that. -- Russ Allbery (ea...@eyrie.org) <http://www.eyrie.org/~eagle/>

Re: Heimdal 7.3: ext_keytab fails with "Operation requires `get-keys' privilege"

2017-06-27 Thread Russ Allbery
Nico Williams writes: > We do need better key mgmt support though. It'd nice to have automatic > rekeying and expunging of keys too old to be needed for decrypting > extant live tickets. Yes, please, or I will inflict my hideous shell script on you that does this (using wall

Re: Heimdal 7.3: ext_keytab fails with "Operation requires `get-keys' privilege"

2017-06-27 Thread Russ Allbery
se and use that to snoop on traffic and forge sessions. If the attacker has to invalidate the old key in order to download new keys, the detection story is much better and the attacker is a bit more limited in what they can immediately do. -- Russ Allbery (ea...@eyrie.org) <http://www.eyrie.org/~eagle/>

Re: Does pre-authentication help against "insider" attacks?

2017-05-26 Thread Russ Allbery
cation is primarily there to protect weak keys, such as any keys derived from a password. -- Russ Allbery (ea...@eyrie.org) <http://www.eyrie.org/~eagle/>

Re: Re-encrypt on change of master key

2017-03-14 Thread Russ Allbery
ry about. Note that you will need to manually copy the new master key to the slaves before they'll be able to replicate. Also don't forget to keep the old master key around for the length of your backup retention so that you don't invalidate your backups. -- Russ Allbe

Re: which pam-afs to use

2017-01-30 Thread Russ Allbery
module is known to not work properly with systemd user sessions, and fixing that is going to be difficult (and may be beyond the amount of time I can spend on it, given that I'm no longer using AFS and am only using Kerberos very lightly these days). -- Russ Allbery (ea...@eyrie.org

Re: Kerberos authentication to load-balanced services in AWS and reverse DNS

2017-01-06 Thread Russ Allbery
ill accept tickets > for any principal in its keytab. Yup, that was the fix. -- Russ Allbery (ea...@eyrie.org) <http://www.eyrie.org/~eagle/>

Re: Preparing for the Heimdal 7 Release

2016-10-19 Thread Russ Allbery
from Debian unstable and testing with an upload today. I won't want to reintroduce this until there is a stable and security-supported release of Heimdal packaged for Debian. -- Russ Allbery (ea...@eyrie.org) <http://www.eyrie.org/~eagle/>

Re: Where does the Latest Version Work?

2016-08-12 Thread Russ Allbery
long overdue for an actual release that people can just build and use without having to understand the development model or how to work with a Git clone. -- Russ Allbery (ea...@eyrie.org) <http://www.eyrie.org/~eagle/>

Re: /var/heimdal/kpasswdd.history no longer updating after a heimdal upgrade

2016-06-30 Thread Russ Allbery
e. That said, I may be excessively paranoid, since I did hack on the embedded CrackLib until it ran clean under valgrind. That doesn't mean there are no remaining bugs, but I may have already patched or worked around those issues. I'm hoping to find some time over the upcoming long US holi

Re: /var/heimdal/kpasswdd.history no longer updating after a heimdal upgrade

2016-06-29 Thread Russ Allbery
"Henry B (Hank) Hotz, CISSP" writes: > Ah! Then it’s a question for Russ Allbery or Alf Wachsmann. you need > their email addresses? I don't think SLAC was using krb5-strength. (Although maybe now would be a good time to take a look at it? It was working with the versio