IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

RE: gss userauth



Title: RE: gss userauth

[Joe] If the GSSAPI exchange is not bound to the session then you do not have assurance that the client actually was performing the GSSAPI exchange to authenticate itself to the SSH server.  The client may actually be trying to authenticate to some other service in some other context and his authentication may be proxied by a third party.  Part of the problem is that the target name suggested is "host@" which can be used by multiple services on a host. 

Tim> Perhaps a target service name such as "ssh@" should be suggested instead ? Would this avoid the problem under discussion ?



Home | Main Index | Thread Index | Old Index