[22969] in Kerberos
daemon@ATHENA.MIT.EDU (Sam Hartman)
Wed Dec 1 17:39:39 2004
To: "Douglas E. Engert" <deengert@anl.gov>
From: Sam Hartman <hartmans@mit.edu>
Date: Wed, 01 Dec 2004 17:39:02 -0500
In-Reply-To: <41AE4221.9060605@anl.gov> (Douglas E. Engert's message of
"Wed, 01 Dec 2004 16:13:53 -0600")
Message-ID: <tslis7lskxl.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: java-security@sun.com
cc: "'kerberos@mit.edu'" <kerberos@mit.edu>
Errors-To: kerberos-bounces@mit.edu
All these issues have been discussed on the ietf-krb-wg list although
never quite in the same place.
Java is wrong in how it handles preauth; the advice in my preauth
draft would be a better approach.
AD is stretching clarifications significantly in how it handles case
of principal names. However it's much more usable than what other
implementations do. There was a long and heated discussion between
Martin Rex and people at Microsoft over this issue.
--Sam
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos