Yes, but the BSDI kerberosIV implementation does not appear to
have the problem (the tf_init() routine which opens the ticket
file checks to see that the real uid of the process is either
root or owns the ticket file).
Jeff
-- /\ Jeff Polk Berkeley Software Design, Inc. (BSDI) /\/ \ polk@BSDI.COM 5575 Tech Center Dr. #110, Colo Spgs, CO 80919 / \ \ Voice: 719-260-8114 http://www.BSDI.COM/people/polkFor years, we thought that a million monkeys sitting at a million keyboards would produce the complete works of Shakespeare. Today, thanks to the Internet, we know that's not true.