[22971] in Kerberos

home help back first fref pref prev next nref lref last post

Re: JAVASEC - Using Java client with Windows 2003 AD with mixed

daemon@ATHENA.MIT.EDU (Douglas E. Engert)
Wed Dec 1 17:51:09 2004

Message-ID: <41AE4A33.4050804@anl.gov>
Date: Wed, 01 Dec 2004 16:48:19 -0600
From: "Douglas E. Engert" <deengert@anl.gov>
MIME-Version: 1.0
To: Sam Hartman <hartmans@mit.edu>
In-Reply-To: <tslis7lskxl.fsf@cz.mit.edu>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
cc: java-security@sun.com
cc: "'kerberos@mit.edu'" <kerberos@mit.edu>
Errors-To: kerberos-bounces@mit.edu



Sam Hartman wrote:

> All these issues have been discussed on the ietf-krb-wg list although
> never quite in the same place.
> 
> Java is wrong in how it handles preauth; the advice in my preauth
> draft would be a better approach.

I agree it is wrong. What I would like to see is the Java people
admit this and fix it and work in the krb-wg too.

> 
> AD is stretching clarifications significantly in how it handles case
> of principal names.  However it's much more usable than what other
> implementations do.  There was a long and heated discussion between
> Martin Rex and people at Microsoft over this issue.

Some how I miss that point. Hopefully the explaination I put together
will get the Java people to do something about the preauth.


> 
> --Sam
> 
> 
> 
> 

-- 

  Douglas E. Engert  <DEEngert@anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post