[19459] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Forwarding Kerberos Credentials - SSH

daemon@ATHENA.MIT.EDU (Jeffrey Altman)
Fri Jun 20 22:28:04 2003

From: jaltman@columbia.edu (Jeffrey Altman)
Date: 20 Jun 2003 22:19:39 -0400
Message-ID: <bd0fbr$22h$1@watsol.cc.columbia.edu>
To: kerberos@MIT.EDU
Errors-To: kerberos-bounces@mit.edu

In article <p0521060bbb1902beb3a0@[137.78.212.225]>,
Henry B. Hotz <hotz@jpl.nasa.gov> wrote:
: "Me Too" (TM)
: 
: So, is that possible?
: 
: Ideally, is it possible in an application that only talks generic 
: SSL, so that it could in turn call a module that made use of the tgt? 
: (The thread is sshd, but I'm thinking maybe 
: Apache/{PHP,Perl}/{Postgres,AFS}.)

The TLS KRB5 cipher does not support credential forwarding.

SSH and TLS (aka SSL 3.1) are completely different and incompatible
protocols which are used for different purposes.

Jeffrey Altman

-- 
 Jeffrey Altman * Volunteer Developer      Kermit 95 2.1 GUI available now!!!
 The Kermit Project @ Columbia University  SSH, Secure Telnet, Secure FTP, HTTP
 http://www.kermit-project.org/            Secured with MIT Kerberos, SRP, and 
 kermit-support@columbia.edu               OpenSSL.
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post