Movatterモバイル変換
[0]ホーム
Kerberos 5 Release 1.9
The MIT Kerberos Team announces the availability of the krb5-1.9 release. Thedetached PGP signature is available without going through the download page, if you wish to verify the authenticity of a distribution you have obtained elsewhere.
Please see theREADME file for a more complete list of changes.
You may also see the current fulllistof fixed bugs tracked in our RT bugtracking system.
DES transition
The Data Encryption Standard (DES) is widely recognized as weak. The krb5-1.7 release contains measures to encourage sites to migrate away from using single-DES cryptosystems. Among these is a configuration variable that enables "weak" enctypes, which now defaults to "false" beginning with krb5-1.8.
Major changes in 1.9
- Code quality
- Fix MITKRB5-SA-2010-007 checksum vulnerabilities (CVE-2010-1324 and others).
- Add a Python-based testing framework.
- Perform DAL cleanup.
- Developer experience
- Add NSS crypto back end.
- Improve PRNG modularity.
- Add a Fortuna-like PRNG back end.
- Performance
- Account lockout performance improvements -- allow disabling of some account lockout functionality to reduce the number of write operations to the database during authentication
- Add support for multiple KDC worker processes.
- Administrator experience
- Add Trace logging support to ease the diagnosis of configuration problems.
- Add support for purging old keys (e.g. from "cpw -randkey -keepold").
- Add plugin interface for password sync -- based on proposed patches by Russ Allbery that support his krb5-sync package
- Add plugin interface for password quality checks -- enables pluggable password quality checks similar to Russ Allbery's krb5-strength package.
- Add a configuration file validator script.
- Add KDC support for SecurID preauthentication -- this is the old SAM-2 protocol, implemented to support existing deployments, not the in-progress FAST-OTP work.
- Add "cheat" capability for kinit when running on a KDC host.
- Protocol evolution
- Add support for IAKERB -- a mechanism for tunneling Kerberos KDC transactions over GSS-API, enabling clients to authenticate to services even when the clients cannot directly reach the KDC that serves the services.
- Add support for Camellia encryption (experimental; disabled by default).
- Add GSS-API support for implementors of the SASL GS2 bridge mechanism.
Known Bugs
Known bugs reported against krb5-1.9 are listedhere.
Please note that the HTML versions of these documents are converted from texinfo, and that the conversion is imperfect. If you want PostScript or GNU info versions, please download the documentation tarball.
You may retrieve the Kerberos 5 Release 1.9 source fromhere. If you need to acquire the sources from some other distribution site, you may verify them against thedetached PGP signature for krb5-1.9.
$Id: krb5-1.9.html,v 1.5 2010/12/22 21:22:43 tlyu Exp $
MIT Kerberos [ home ] [ contact ]
[8]ページ先頭