Re: Heads-up: Kerberos default user credential cache location is changing

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Fri, 2012-06-22 at 09:36 +0100, David Howells wrote:
> Stephen Gallagher <sgallagh@xxxxxxxxxx> wrote:
> 
> > 1) Credential caches are now stored in a tmpfs location. This is a
> > security feature, as a stolen laptop may not be booted in single-user
> > mode to extract a valid TGT.
> 
> Is it?  Can't tmpfs move stuff arbitrarily out to swap?

Ah, true. This could happen in a low-memory case. I should perhaps
revise this statement then to be "This is a security feature, as a
stolen laptop booted in single user mode will have a much more difficult
time of extracting a valid TGT".

This of course can be further mitigated by the use of encrypted swap
space.

Attachment: signature.asc
Description: This is a digitally signed message part

-- 
devel mailing list
devel@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/devel

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux