[2257] in Kerberos
Re: Kerberos/PK and SecurID ??
daemon@ATHENA.MIT.EDU (Charlie Kaufman)
Tue Oct 6 05:46:43 1992
Date: Mon, 5 Oct 92 19:01:17 EDT
From: Charlie Kaufman <kaufman@kibitz.enet.dec.com>
To: looi@qut.edu.au
Cc: kerberos@Athena.MIT.EDU, kaufman@kibitz.enet.dec.com
Apparently-To: looi@qut.edu.au, kerberos@athena.mit.edu
>There has been some mention of a mythical beast called Kerberos/PK (Public
>Key).
>
>Does anyone know anything about this - like:
>
> - does it exist (perhaps under another name)
> - who is developing / implementing it
There may be multiple efforts vaguely fitting this description, though
I've never heard the name Kerberos/PK used.
DASS/SPX is a design/model implementation of a public key based
authentication protocol loosely modelled after Kerberos V4. SPX code
is available by anonymous ftp, but unfortunately like Kerberos it is
not exportable and unfortunately unlike Kerberos there is no "Bones"
version. The DASS spec has timed out as an internet draft; we're
trying to figure out the appropriate way to make it available again in that context.
There were discussions early this year in the context of the IETF-CAT
working group about merging the DASS and Kerberos V5 designs into an
"IAM" (Internet Authentication Mechanism) supporting either public or
secret key technology. While all participants remain enthusiastic
about the technical viability of such an approach, I believe it has
fallen victim to competing priorities at least for the moment (someone
please correct me if there is progress I haven't heard about).
There is a group in Europe called SESAME that is working on a public
key based enhancement to OSF-DCE security that may offer some of the
properties of a public key based Kerberos. A working prototype of
SESAME exists, but neither code nor spec are readily available.
And there may be yet other such efforts, either clandestine or that I
simply haven't heard about.
>Also, does anyone have contact details for the group involved with Kerberos
>and SecurID?
There may be multiple efforts here as well. I have been working with
Jim Kotanchik of Security Dynamics (1-617-354-8836) on ways of
integrating SecurID with Kerberos. Unfortunately, he is not on the
net. I don't feel free to discuss the protocol, and I don't know what
their plans are for deploying it, but he gave me permission to give out
his name. I expect they are planning to go public with their proposal
at some point, but I don't know whether it will be through MIT or through OSF.
He also mentioned that there exists at least one third party product
today that integrates Kerberos with SecurID cards and that "any SecurID
salesman" could point you to it.
--Charlie Kaufman