[2154] in Kerberos
Re: Is Kerberos V5 supported by AFS, is Kerberos V5 preferred and stable?
daemon@ATHENA.MIT.EDU (dean@ksr.com)
Wed Sep 2 18:33:28 1992
Date: Wed, 2 Sep 1992 18:09:20 -0400
From: dean@ksr.com
To: long-morrow@cs.yale.edu ("H. Morrow Long")
Cc: dean@ksr.com, kerberos@Athena.MIT.EDU, info-afs-kerberos@transarc.com
3stable adj sta7bler \-b(e-)ler\; sta7blest \-b(e-)lest\
[ME, fr. MF estable, fr. L stabilis, fr. stare to stand]
(14c)
1a: firmly established: FIXED, STEADFAST
b: not changing or fluctuating: UNVARYING
c: PERMANENT, ENDURING
2a: steady in purpose: firm in resolution
b: not subject to insecurity or emotional illness: SANE, RATIONAL aa
stable personalityq
3a1 : placed so as to resist forces tending to cause motion or change
of motion
(2): designed so as to develop forces that restore the original
condition when disturbed from a condition of equilibrium or steady
motion
b (1): not readily altering in chemical makeup or physical state
astable emulsionsq
(2): not spontaneously radioactive
syn see LASTING
Kerberos V5 is in beta. Its been in beta for a year (there is a new
beta version out Real Soon Now). So I guess that can be called
stable.
OSF DCE is derived from Kerberos, but is substantially different from
MIT kerberosV5. You may have problems using this for general
authentication purposes unless you have source code for your clients
and their servers. (and are willing to change your clients and
servers to use DCE RPC).
If your clients/servers use encryption, you may have some problems
using the DCE server because the encryption subroutines (or
krb_mk_priv, etc) are not available in the libraries unless you have
DCE source (I'm not sure this is right, it doesn't matter for me,
because I'm planning to run both. MIT kerberos for authentication,
and OSF DCE for itself).
--Dean
Dean Anderson
KSR Computing Facilities
Kendall Square Research