[2239] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos & X.509

daemon@ATHENA.MIT.EDU (John Gardiner Myers)
Thu Oct 1 14:53:15 1992

Date: 1 Oct 92 08:28:20 GMT
From: jgm+@cmu.edu (John Gardiner Myers)
To: kerberos@shelby.Stanford.EDU

dyer@spdcc.com (Steve Dyer) writes:
> The AFS V4 KDC does interoperate with most clients; jgm said "most"
> because kinit/login-type programs which prompt for passwords run into
> the annoying problem that the AFS KDC stores keys using a different
> string-to-key algorithm than the MIT standard server.

Technically, the string-to-key algorithm has nothing to do with the
KDC.  It's just that the AFS administrative commands store keys in the
KDC with the different algorithm.  The work to configure an AFS KDC
site to use the MIT string-to-key hasn't been done yet, but it's
feasable.

The mechanism for changing passwords is different, which is the
primary reason I said "most".

AFS/MIT Kerberos interoperability issues are continuously rehashed on
the info-afs-kerberos@transarc.com list.  Subscription requests to
info-afs-kerberos-request@transarc.com.

				_.John

home help back first fref pref prev next nref lref last post