Penn Computing
Computing Menu Computing A-Z
Computing Home Information Systems & Computing Penn

Critical Host Compliance: Telnet Clients

At the end of January 2003, Telnet connections to critical hosts that allow passwords to travel over the network in clear text will no longer be permitted. This change is mandated by the Critical Host Policy. As part of an earlier phase of the policy, critical servers on campus were already configured to support secure connections. The next phase is to make sure that Telnet client software on campus is also in compliance.

For users, this means that some Telnet clients will no longer work and individuals using them to access email and other services will need to install new software.

The chart below summarizes a few of the ways users currently access host-based email and other Telnet services that will no longer work:

Protocol Client Software Critical Host Compliant?
Plain Telnet
  • Windows built-in Telnet client
  • Mac OS built-in Telnet client
  • Host Explorer (not configured for Kerberos)
  • NCSA Telnet
No

To ease the transition and to avoid any concerns as the deadline approaches, LSPs are strongly encouraged to help users update their desktops as soon as possible.

After the Critical Host Policy for Telnet clients goes into effect, users on most servers will have two secure alternatives:

  • Use a Kerberos-configured Telnet client in conjunction with a Kerberos ticket manager; or
  • Access the server using the Secure SHell (SSH) protocol, instead of Telnet.

Once users connect to the server using either secure alternative, their experience will be identical to what they experienced using plain Telnet.

The chart below summarizes the various secure ways in which users can currently access host-based email and other Telnet services:

Protocol Client Software Critical Host Compliant?
Telnet with Kerberos Authentication
  • dataComet Secure configured for Kerberos AND Kerberos for Macintosh 4.x ticket manager
  • Mac OS X Jaguar built-in telnet client AND Kerberos for Macintosh 4.x ticket manager
  • Host Explorer 7.1.0.4 configured for Kerberos AND Leash32 ticket manager
Yes
Secure Shell (SSH)
  • dataComet Secure configured for SSH
  • Mac OS X and above built-in terminal client configured for SSH
  • SecureCRT configured for SSH
Yes

For more information about clients and configuration, please see the Supported Products page.

top

Information Systems and Computing
University of Pennsylvania
Comments & Questions


University of Pennsylvania Penn Computing University of Pennsylvania Information Systems & Computing (ISC)
Information Systems and Computing, University of Pennsylvania