Re: Why is there no ServerMinPrincipalType constraint
Mark Brouwer <[email protected]>
| Newsgroups | gmane.comp.java.sun.jini |
|---|---|
| Message-ID | <[email protected]> |
Dan Creswell wrote: > Many customers I've seen using secure solutions don't use Kerberos even > for internal security and very few of them are considering accessing > third party services at this level of sophistication (or even at all). > > Thus I'm wondering, do you have a customer that is looking at doing the > stuff you describe? That would be, IMHO a substantial market shift which > could be very interesting. Sorry Dan, no market shifts that I'm aware of. Many of the questions passing by these days are due to goals set with regard to the configuration flexibility of Seven in relation to Jini security which is slated for the next release. I can't deny these goals are likely beyond customer expectation at this time [1] and really reflect the ambitions that Seven should lower the hurdle to use Jini security in drastic ways without bringing limitations, making it more cost effective (and fun!) to start using Jini security and to take it into directions previously not possible due to restrictions implied by static configuration files or time/cost involved to cater for that. As it appears I hit what I would call "limitations" in places where I would like to mix Kerberos and SSL based security and where I would like to use 'wildcard' facilities, not only because I believe there are use cases for that [2], but also because it would result in a more consistent way of configuring Seven. With access control e.g. people have the wildcard facility to specify all Kerberos principals, or all X.500 principals, combinations of both, etc. For consistency reasons I also would like to provide people the ability to say, trust all Kerberos servers and a particular set of SSL servers, etc. My experience is that exceptions in what people can configure leads to confusion and frustration, and therefore I want to limit the number of exceptions to what is possible, or it should be plain wrong what I don't believe is the case here. [1] which means that once finished I hopefully don't have to touch that subject for a very long time to come. [2] if security was available 3 years ago for Seven together with the work as part of "Jini across the Firewall" (for which the secure part is still missing), the ability to use aggregated endpoints for which trust verification would have been available as part of the Platform and the inverted event model I would have certainly considered it for connecting third parties at that time to a financial trade platform. So in one way one could say this feature, and the others I mentioned, are way too late :-( BTW in the past I've seen a few people asking questions related to Kerberos so I think it is safe to assume that Kerberos is used by some people in corporate environments, but I admit that I have no clue about the average usage or lack thereof of Jini security. -- Mark -------------------------------------------------------------------------- Getting Started: http://www.jini.org/wiki/Category:Getting_Started Community Web Site: http://jini.org jini-users Archive: http://archives.java.sun.com/archives/jini-users.html Unsubscribing: email "signoff JINI-USERS" to [email protected]