Re: Federated realms and PAD

Jeffrey Hutzelman <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
On Thu, 2012-02-16 at 08:36 -0500, Sam Hartman wrote:
> >>>>> "Nico" == Nico Williams <[email protected]> writes:
> 
>     Nico> so that it can get backed into scripts (I know, use $HOME).
>     Nico> And if we could rely on a global namespace, then I'd just drop
>     Nico> the URI thing.  But I don't think we can, not in federated
>     Nico> realms that aren't remotely in the same "administrative
>     Nico> domain", which I thought was part of what the PAD was all
>     Nico> about.
> 
> 
> So, I've been thinking about federated contexts a lot lately mostly for
> ABFAB but certainly beyond that.  When I explain why Kerberos is not
> federated, one of the biggest things I cite is that Kerberos has
> assumptions that bind it within one organization.


It always confuses me when people say "Kerberos is not federated".
Of course it is.

I have cross-realm relationships with a variety of organizations,
ranging from other parts of CMU to other universities to outside groups
with whom our only relationship is that we've agreed to enable
authentication to services in one organization by users in another.  I
use Kerberos-authenticated services in other realms nearly every day.
How is this not federated authentication?

-- Jeff

_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.