[23219] in Kerberos
Re: Krb5 API vs. GSSAPI
daemon@ATHENA.MIT.EDU (Sam Hartman)
Tue Jan 18 18:10:09 2005
To: Fredrik Tolf <fredrik@dolda2000.com>
From: Sam Hartman <hartmans@mit.edu>
Date: Tue, 18 Jan 2005 18:09:33 -0500
In-Reply-To: <1106079564.4883.39.camel@pc7> (Fredrik Tolf's message of "Tue,
18 Jan 2005 21:19:24 +0100")
Message-ID: <tslvf9u5o7m.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
>>>>> "Fredrik" == Fredrik Tolf <fredrik@dolda2000.com> writes:
Fredrik> However, looking around at other programs, it seems that
Fredrik> most (all?) are using GSSAPI. Thus, I'm wondering what
Fredrik> the advantages of using GSSAPI are, and when you should
Fredrik> use GSSAPI and when you should use the native API.
In general if you can use GSSAPI you should do so. We have some
better GSSAPI examples (Alexis wrote them) but for some silly license
reasons we cannot currently distribute them. I'll prod the appropriate people on that issue again.
Fredrik> I know
Fredrik> that GSSAPI is supposed to be able to support other
Fredrik> mechanism apart from Kerberos, but from what I know, this
Fredrik> hasn't happened so far, so that doesn't really seem to be
Fredrik> a very great advantage of using GSSAPI.
no there are several GSSAPI mechanisms besides Kerberos. Most of them
are fairly expensive.
--Sam
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos