Re: Why is there no ServerMinPrincipalType constraint

Dan Creswell <[email protected]>
Newsgroups gmane.comp.java.sun.jini
Message-ID <[email protected]>
Hi Mark,

Mark Brouwer wrote:
> Bob Scheifler wrote:
>>> Is that really true? Assuming I'm in a network and the server is able to
>>> authenticate as some Kerberos principal that means that he has been
>>> granted one in the KDC and that seems a certain level of trust to me.
>>>
>>> Also in a PKI environment in which I have an X.500 principal in my trust
>>> store it means that the entity at the other end is known by me.
>>
>> In restricted circumstations such as you describe, it's also quite
>> likely that simply requiring ServerAuthentication.YES is sufficient,
>> without need for a type constraint.  So, I still find server type
>> constraints uninteresting.
>
> How do you do that ... I was only wondering something but now I'm
> fiercely wanting to have the ServerMinPrincipalType. I guess your "So, I
> still find ... uninteresting" does that ;-)
>
> So for the record "I disagree Bob". Within a corporate environment
> Kerberos is likely the most comfortable solution for arranging security,
> but it doesn't lend itself very well for securing services involving
> third parties (as it requires a trusted third party, the KDC, accessible
> by all parties involved), for that kind of interaction a PKI solution
> based on TLS is likely better suited.
>

Many customers I've seen using secure solutions don't use Kerberos even
for internal security and very few of them are considering accessing
third party services at this level of sophistication (or even at all).

Thus I'm wondering, do you have a customer that is looking at doing the
stuff you describe? That would be, IMHO a substantial market shift which
could be very interesting.

Best wishes,

Dan.

--------------------------------------------------------------------------
Getting Started:     http://www.jini.org/wiki/Category:Getting_Started
Community Web Site:  http://jini.org
jini-users Archive:  http://archives.java.sun.com/archives/jini-users.html
Unsubscribing:       email "signoff JINI-USERS"  to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.