Re: GGF's extensions to GSS in Public Comment

Jeffrey Altman <[email protected]> Mon, 05 Apr 2004 22:12:03 -0400
Newsgroups gmane.ietf.cat
Organization No Longer Affiliated with Columbia University in the City of New York
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------090206070209040408020007
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit

Nicolas Williams wrote:

>(Doesn't the new Kfw MLSA ccache type pretty much mean that Kfw has a
>single credential store peruser on Windows?  Yes, it can still use
>KRB5CCNAME for other ccache types, but those aren't shared with the
>LSA...)
>
MIT krb5_ccache API provides access to multiple
ccache types.  These include "FILE:", "API:",
"MEMORY:", and "MSLSA:" at the current time.
On Windows and Macintosh, the default krb5_ccache type
is "API:" (aka CCAPI).  The "MSLSA:" krb5_ccache type
provides shared access to the LSA cache allowing the
same credentials to be used by both MIT Krb5 API clients
and Kerberos SSP clients.

>[1]  AFS uses Kerberos IV, though it seems possible to use it with
>     Kerberos V and, in any case, with krb524 it's possible to use
>     GSS-API initiator credentials for the Kerberos V mechanism with
>     AFS.
>
OpenAFS and Arla support both Kerberos IV and Kerberos 5 tickets
types.  krb524d is not required when an appropriate aklog is
provided.  MIT KfW 2.6.1 will provide such an aklog.

Jeffrey Altman



--------------090206070209040408020007
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type">
  <title></title>
</head>
<body bgcolor="#ffffff" text="#000000">
<font face="Bitstream Cyberbit">Nicolas Williams wrote:</font><br>
<blockquote cite="[email protected]"
 type="cite">
  <pre wrap=""><font face="Bitstream Cyberbit">(Doesn't the new Kfw MLSA ccache type pretty much mean that Kfw has a
single credential store peruser on Windows?  Yes, it can still use
KRB5CCNAME for other ccache types, but those aren't shared with the
LSA...)
</font></pre>
</blockquote>
MIT krb5_ccache API provides access to multiple<br>
ccache types.&nbsp; These include "FILE:", "API:", <br>
"MEMORY:", and "MSLSA:" at the current time.<br>
On Windows and Macintosh, the default krb5_ccache type<br>
is "API:" (aka CCAPI).&nbsp; The "MSLSA:" krb5_ccache type<br>
provides shared access to the LSA cache allowing the <br>
same credentials to be used by both MIT Krb5 API clients<br>
and Kerberos SSP clients.<br>
<br>
<blockquote cite="[email protected]"
 type="cite">
  <pre wrap=""><font face="Bitstream Cyberbit">[1]  AFS uses Kerberos IV, though it seems possible to use it with
     Kerberos V and, in any case, with krb524 it's possible to use
     GSS-API initiator credentials for the Kerberos V mechanism with
     AFS.
</font></pre>
</blockquote>
OpenAFS and Arla support both Kerberos IV and Kerberos 5 tickets<br>
types.&nbsp; krb524d is not required when an appropriate aklog is <br>
provided.&nbsp; MIT KfW 2.6.1 will provide such an aklog.<br>
<br>
Jeffrey Altman<br>
<br>
<br>
</body>
</html>

--------------090206070209040408020007--
-++**==--++**==--++**==--++**==--++**==--++**==--++**==
This message was posted through the Stanford campus mailing list
server.  If you wish to unsubscribe from this mailing list, send the
message body of "unsubscribe ietf-cat-wg" to [email protected]