Received: from SOUTH-STATION-ANNEX.MIT.EDU by po7.MIT.EDU (5.61/4.7) id AA24481; Tue, 26 Dec 95 20:36:33 EST
Received: by MIT.EDU 
	id AA08643; Tue, 26 Dec 95 20:35:19 EST
Date: Tue, 26 Dec 95 20:35:19 EST
From: MAILER-DAEMON@MIT.EDU (Mail Delivery Subsystem)
Subject: Returned mail: Cannot send message for 3 days
Message-Id: <9512270135.AA08643@MIT.EDU>
To: <cgs@cldc.howard.edu>
To: proven@PO7.LOCAL
To: tytso@PO9.LOCAL
To: basch@lehman.com
To: jis@E40-PO.LOCAL
To: tlyu@PO9.LOCAL

   ----- Transcript of session follows -----
421 pyro.rh.imsa.edu.tcp... Deferred: Connection timed out during user open with pyro.rh.imsa.edu
451 hangman@pyro.rh.imsa.edu... Cannot send message for 3 days
hangman@pyro.rh.imsa.edu... Cannot send message for 3 days

   ----- Unsent message follows -----
Received: from excelsior.cldc.howard.edu by MIT.EDU with SMTP
	id AA03697; Sat, 23 Dec 95 20:20:44 EST
Received: (from cgs@localhost) by excelsior.cldc.howard.edu (8.6.12/8.6.6) id VAA03132; Sat, 23 Dec 1995 21:17:12 -0500
Date: Sat, 23 Dec 1995 21:17:10 -0500 (EST)
From: "Calvin G. Smith" <cgs@cldc.howard.edu>
X-Sender: cgs@excelsior
To: Derek Atkins <warlord@MIT.EDU>
Cc: kerberos@MIT.EDU
Subject: Re: Thinking of moving to kerberos, lots of questions
In-Reply-To: <199512232220.RAA06415@toxicwaste.media.mit.edu>
Message-Id: <Pine.LNX.3.91.951223204028.3021A-100000@excelsior>
Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII

On Sat, 23 Dec 1995, Derek Atkins wrote:

> Hi.
> 
> > We are considering moving our system from YP to Kerberos. Before I
> > undertake this, are there any pitfalls, etc. to watch out for?
> 
> First, remember that kerberos is an authentication system, YP is a
> naming service.

OK, I got that. We don't us YP for anything else but user and group 
validation.

> 
> > How would I move the password database from the YP files to the Kerberos
> > KDC? Would everyone have to reenter their passwords, or is there a way
> > that it could be done so that it is as transparent as possible to the
> > users?
> 
> You cannot directly convert from YP passwords to Kerberos passwords.
> You will need to create each user in the KDC by hand, which does
> require everyone to enter their password.  Or, perhaps, you can
> provide a program that will use the YP password and stuff it into the 
> KDC (this _can_ be a security hole if left too long).  For example,
> you can hack login to first try the KDC for a password, and if that
> fails, try YP.  If YP succeeds, then add the password to the KDC.
> This just requires the hacked login program to understand the kadmin
> protocol and have a kadmin password stored inside.
> 

drat. I was afraid of that. Any sources out there that I can use?

> -derek
> 

						-Calvin
---------------------------------------------------------------------
"Information - the currency of the future"		cgs@cldc.howard.edu
---------------------------------------------------------------------


