[22739] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos + LDAP How-To

daemon@ATHENA.MIT.EDU (Markus Moeller)
Mon Oct 25 13:07:48 2004

From: "Markus Moeller" <huaraz@moeller.plus.com>
Date: Sat, 23 Oct 2004 13:02:54 +0100
Message-ID: <417a4873$0$37982$ed2e19e4@ptn-nntp-reader04.plus.net>
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

Matt,

why do you use SSL and put extra load on the client/server if you already 
use Kerberos ? SASL/GSSAPI does authentication AND encryption !!
Cyrus-sasl may show only a SSF of 56, but this is only because is hardcoded 
in cyrus, it should be calculated from the kerberos key type .e.g. with 
3des,rc4 have a SSF of 128 or so.

Regards
Markus


"Matt Joyce" <syslists@vtsystems.com> wrote in message 
news:4175A85F.6080004@vtsystems.com...
> Thanks much to all of you for your responses.  Much of what I wanted to do 
> is actually answered more in depth on-line.... took me a long time to find 
> good documentation on it.
>
> http://ofb.net/~jheiss/krbldap/howto.html
> Seems to be the best docs i've seen to date on the kerberos ldap link up. 
> Just thought I'd share that.
>
> -Matt Joyce.
> ________________________________________________
> Kerberos mailing list           Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
> 


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post