The Areas of the Network Where Trust is Placed



next up previous contents
Next: The Areas of Up: Kerberos Previous: The Principals

The Areas of the Network Where Trust is Placed

The key-distribution-center (KDC) stores all secret keys for all users and servers. This machine must be physically secured, as well as have strong access control mechanisms for updating the database of keys. Both clients and servers must trust that the information they receive from the key-distribution-center is correct. A major vulnerability with the Kerberos model is that if the key-distribution-server is compromised, every secret key used on the network is compromised.



John Barkley
Fri Oct 7 16:17:21 EDT 1994