Re: Why is there no ServerMinPrincipalType constraint
Bob Scheifler <[email protected]>
| Newsgroups | gmane.comp.java.sun.jini |
|---|---|
| Message-ID | <[email protected]> |
> Is that really true? Assuming I'm in a network and the server is able to > authenticate as some Kerberos principal that means that he has been > granted one in the KDC and that seems a certain level of trust to me. > > Also in a PKI environment in which I have an X.500 principal in my trust > store it means that the entity at the other end is known by me. In restricted circumstations such as you describe, it's also quite likely that simply requiring ServerAuthentication.YES is sufficient, without need for a type constraint. So, I still find server type constraints uninteresting. - Bob -------------------------------------------------------------------------- Getting Started: http://www.jini.org/wiki/Category:Getting_Started Community Web Site: http://jini.org jini-users Archive: http://archives.java.sun.com/archives/jini-users.html Unsubscribing: email "signoff JINI-USERS" to [email protected]