Quantcast
Viewing all articles
Browse latest Browse all 14040

Check-password insecure issue in ccs-pykerberos library

Is there any workaround for fixing the following issue or any alternative to the kerberos library?

The python-kerberos checkPassword() method is badly insecure. It does a kinit (AS-REQ) to ask a KDC for a TGT for the given user principal, and interprets the success or failure of that as indicating whether the password is correct:

There is no active response from the maintainers.


Viewing all articles
Browse latest Browse all 14040

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>