[23219] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Krb5 API vs. GSSAPI

daemon@ATHENA.MIT.EDU (Sam Hartman)
Tue Jan 18 18:10:09 2005

To: Fredrik Tolf <fredrik@dolda2000.com>
From: Sam Hartman <hartmans@mit.edu>
Date: Tue, 18 Jan 2005 18:09:33 -0500
In-Reply-To: <1106079564.4883.39.camel@pc7> (Fredrik Tolf's message of "Tue,
 18 Jan 2005 21:19:24 +0100")
Message-ID: <tslvf9u5o7m.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

>>>>> "Fredrik" == Fredrik Tolf <fredrik@dolda2000.com> writes:

    Fredrik> However, looking around at other programs, it seems that
    Fredrik> most (all?) are using GSSAPI. Thus, I'm wondering what
    Fredrik> the advantages of using GSSAPI are, and when you should
    Fredrik> use GSSAPI and when you should use the native API. 

In general if you can use GSSAPI you should do so.  We have some
better GSSAPI examples (Alexis wrote them) but for some silly license
reasons we cannot currently distribute them.  I'll prod the appropriate people on that issue again.


    Fredrik> I know
    Fredrik> that GSSAPI is supposed to be able to support other
    Fredrik> mechanism apart from Kerberos, but from what I know, this
    Fredrik> hasn't happened so far, so that doesn't really seem to be
    Fredrik> a very great advantage of using GSSAPI.

no there are several GSSAPI mechanisms besides Kerberos.  Most of them
are fairly expensive.  

--Sam

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post