kinit sending clear text password

Will Fiveash william.fiveash at sun.com
Wed Apr 21 15:46:14 EDT 2004


On Wed, Apr 21, 2004 at 01:35:57PM -0500, Will Fiveash wrote:
> On Wed, Apr 21, 2004 at 11:49:48AM -0400, Wyllys Ingersoll wrote:
> > Douglas E. Engert wrote:
> > >
> > >As a side comment, the Sun pam_krb5 when passed the debug option writes 
> > >the password to syslog! This is not a good praticis even when testing. 
> > > 
> > 
> > I think that bug has been fixed recently, but I don't have the patchid
> > available right now.
> 
> See:
> 
> <http://sunsolve6.sun.com/search/document.do?assetkey=1-1-5004688-1&searchclause=>

Forget the URL, it's an internal site.  Keep an eye on
<http://sunsolve.sun.com/> for bug ID 5004688 and an associated patch.

-- 
Will Fiveash
Sun Microsystems Inc.
Austin, TX, USA (TZ=CST6CDT)


More information about the Kerberos mailing list