[comp.protocols.kerberos] kinit security

doug@zaphod.prime.com (Douglas S. Rand) (08/29/89)

If you give kinit a non-existant principal it immediately gives an
error message. Do people think that it should ask for a password anyway
to prevent discrimination of an invalid principal from a bad password? 
I know this is not that interesting on UNIX where the password file
tends to be readable anyway.

Cheers,
Doug Rand <doug@primerd.prime.com>