sambaXP 2024: Bronze-Bit attack mitigation for old MIT Kerberos versions

Опубликовано: 03 Апрель 2026
на канале: SAMBA
56
0

Talk by Julien Rische (Red Hat)

Abstract:
The FreeIPA project relies on MIT Kerberos for its KDC service. Fixing the Bronze-Bit vulnerability (CVE-2020-17049) has been particularly challenging on CentOS Stream/RHEL 8, because the solution designed by Microsoft was not practicable in this context.

In this presentation, Julien Rische explains what this vulnerability is, how it is meant to be fixed, and how it was actually handled on CentOS Stream/RHEL 8. He supports these explanations with step-by-step sequence diagrams.

Slides: https://sambaxp.org/fileadmin/user_up...

Visit the conference website at: https://sambaxp.org​