[23218] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Krb5 API vs. GSSAPI

daemon@ATHENA.MIT.EDU (Frank Balluffi)
Tue Jan 18 17:46:52 2005

To: "Fredrik Tolf <fredrik" <fredrik@dolda2000.com>
MIME-Version: 1.0
Message-ID: <OF4E4B4758.C7A5EA49-ON85256F8D.00790DE6-85256F8D.00794023@db.com>
From: "Frank Balluffi" <frank.balluffi@db.com>
Date: Tue, 18 Jan 2005 17:04:27 -0500
Content-Type: text/plain; charset="us-ascii"
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

Fredrik,

GSSAPI is a standard. Kerberos APIs are implementation specific. Also, 
GSSAPI supports many mechanisms.

Frank





Fredrik Tolf <fredrik@dolda2000.com>
Sent by: kerberos-bounces@MIT.EDU
01/18/2005 03:19 PM

 
        To:     kerberos@MIT.EDU
        cc: 
        Subject:        Krb5 API vs. GSSAPI


Hi!

I've been writing a couple of programs that use Kerberos for
authentication. I've been using the Krb5 native API, since the example
programs that came with the MIT Krb5 source distribution that were using
the native API seemed much simpler than those that used GSSAPI.

However, looking around at other programs, it seems that most (all?) are
using GSSAPI. Thus, I'm wondering what the advantages of using GSSAPI
are, and when you should use GSSAPI and when you should use the native
API. I know that GSSAPI is supposed to be able to support other
mechanism apart from Kerberos, but from what I know, this hasn't
happened so far, so that doesn't really seem to be a very great
advantage of using GSSAPI.

Can someone enlighten me on this issue, please?

Fredrik Tolf


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos




________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post