Re: Federated realms and PAD
Jeffrey Hutzelman <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 2012-02-16 at 08:36 -0500, Sam Hartman wrote: > >>>>> "Nico" == Nico Williams <[email protected]> writes: > > Nico> so that it can get backed into scripts (I know, use $HOME). > Nico> And if we could rely on a global namespace, then I'd just drop > Nico> the URI thing. But I don't think we can, not in federated > Nico> realms that aren't remotely in the same "administrative > Nico> domain", which I thought was part of what the PAD was all > Nico> about. > > > So, I've been thinking about federated contexts a lot lately mostly for > ABFAB but certainly beyond that. When I explain why Kerberos is not > federated, one of the biggest things I cite is that Kerberos has > assumptions that bind it within one organization. It always confuses me when people say "Kerberos is not federated". Of course it is. I have cross-realm relationships with a variety of organizations, ranging from other parts of CMU to other universities to outside groups with whom our only relationship is that we've agreed to enable authentication to services in one organization by users in another. I use Kerberos-authenticated services in other realms nearly every day. How is this not federated authentication? -- Jeff _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg