This page will capture some of the milestones, progress, and open issues related to the retirement of Kerberos version 4 at MIT.


April 23, 2007

April 7, 2007

February 6, 2007

January 31, 2007

August 28, 2006


The lert client distributed in all Athena releases since Athena 9.2 (released July 2003) has used only krb5 for authentication to the server. The server still supports krb4 for the benefit of old clients, but this could easily be removed in the future.

The version of AFS deployed in all IS&T operated AFS cells uses krb5 for authentication. Are there cells at MIT operated by other departments which do not currently support v5?

The aklog program currently deployed on Athena uses the krb524d service to obtain tickets, but it is not receiving a krb4 ticket when it does so; it is receiving only the encrypted part of a krb5 ticket. The same is true for at least some of the WIN machines, but Paul is not sure if this is true for all WIN machines at this time.

There are also workstations outside of Athena and WIN that have OpenAFS clients installed. It is currently unclear if all of those machines are using v5 for AFS authentication.

We could easily deploy a new aklog that does this directly without accessing krb524d; I believe this is all already in the athena CVS repository but not yet deployed.

August 24, 2006

August 18, 2006