Re: Why is there no ServerMinPrincipalType constraint

Mark Brouwer <[email protected]>
Newsgroups gmane.comp.java.sun.jini
Message-ID <[email protected]>
Dan Creswell wrote:

> Many customers I've seen using secure solutions don't use Kerberos even
> for internal security and very few of them are considering accessing
> third party services at this level of sophistication (or even at all).
>
> Thus I'm wondering, do you have a customer that is looking at doing the
> stuff you describe? That would be, IMHO a substantial market shift which
> could be very interesting.

Sorry Dan, no market shifts that I'm aware of. Many of the questions
passing by these days are due to goals set with regard to the
configuration flexibility of Seven in relation to Jini security which is
slated for the next release. I can't deny these goals are likely beyond
customer expectation at this time [1] and really reflect the ambitions
that Seven should lower the hurdle to use Jini security in drastic ways
without bringing limitations, making it more cost effective (and fun!)
to start using Jini security and to take it into directions previously
not possible due to restrictions implied by static configuration files
or time/cost involved to cater for that.

As it appears I hit what I would call "limitations" in places where I
would like to mix Kerberos and SSL based security and where I would like
to use 'wildcard' facilities, not only because I believe there are use
cases for that [2], but also because it would result in a more
consistent way of configuring Seven. With access control e.g. people
have the wildcard facility to specify all Kerberos principals, or all
X.500 principals, combinations of both, etc. For consistency reasons I
also would like to provide people the ability to say, trust all Kerberos
servers and a particular set of SSL servers, etc. My experience is that
exceptions in what people can configure leads to confusion and
frustration, and therefore I want to limit the number of exceptions to
what is possible, or it should be plain wrong what I don't believe is
the case here.

[1] which means that once finished I hopefully don't have to touch that
subject for a very long time to come.

[2] if security was available 3 years ago for Seven together with the
work as part of "Jini across the Firewall" (for which the secure part is
still missing), the ability to use aggregated endpoints for which
trust verification would have been available as part of the Platform and
the inverted event model I would have certainly considered it for
connecting third parties at that time to a financial trade platform. So
in one way one could say this feature, and the others I mentioned, are
way too late :-(

BTW in the past I've seen a few people asking questions related to
Kerberos so I think it is safe to assume that Kerberos is used by some
people in corporate environments, but I admit that I have no clue about
the average usage or lack thereof of Jini security.
--
Mark

--------------------------------------------------------------------------
Getting Started:     http://www.jini.org/wiki/Category:Getting_Started
Community Web Site:  http://jini.org
jini-users Archive:  http://archives.java.sun.com/archives/jini-users.html
Unsubscribing:       email "signoff JINI-USERS"  to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.