Re: Why is there no ServerMinPrincipalType constraint
Dan Creswell <[email protected]>
| Newsgroups | gmane.comp.java.sun.jini |
|---|---|
| Message-ID | <[email protected]> |
Hi Mark, Mark Brouwer wrote: > Bob Scheifler wrote: >>> Is that really true? Assuming I'm in a network and the server is able to >>> authenticate as some Kerberos principal that means that he has been >>> granted one in the KDC and that seems a certain level of trust to me. >>> >>> Also in a PKI environment in which I have an X.500 principal in my trust >>> store it means that the entity at the other end is known by me. >> >> In restricted circumstations such as you describe, it's also quite >> likely that simply requiring ServerAuthentication.YES is sufficient, >> without need for a type constraint. So, I still find server type >> constraints uninteresting. > > How do you do that ... I was only wondering something but now I'm > fiercely wanting to have the ServerMinPrincipalType. I guess your "So, I > still find ... uninteresting" does that ;-) > > So for the record "I disagree Bob". Within a corporate environment > Kerberos is likely the most comfortable solution for arranging security, > but it doesn't lend itself very well for securing services involving > third parties (as it requires a trusted third party, the KDC, accessible > by all parties involved), for that kind of interaction a PKI solution > based on TLS is likely better suited. > Many customers I've seen using secure solutions don't use Kerberos even for internal security and very few of them are considering accessing third party services at this level of sophistication (or even at all). Thus I'm wondering, do you have a customer that is looking at doing the stuff you describe? That would be, IMHO a substantial market shift which could be very interesting. Best wishes, Dan. -------------------------------------------------------------------------- Getting Started: http://www.jini.org/wiki/Category:Getting_Started Community Web Site: http://jini.org jini-users Archive: http://archives.java.sun.com/archives/jini-users.html Unsubscribing: email "signoff JINI-USERS" to [email protected]