[24320] in Kerberos

home help back first fref pref prev next nref lref last post

Re: EAP-Kerberos

daemon@ATHENA.MIT.EDU (Jeffrey Altman)
Tue Jul 19 14:02:40 2005

From: Jeffrey Altman <jaltman2@nyc.rr.com>
Message-ID: <Y7bDe.5295$Y54.3586@twister.nyc.rr.com>
Date: Tue, 19 Jul 2005 17:55:04 GMT
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

Saber Zrelli wrote:
> I was referring to a KDC instead of an IAKERB proxy. My thoughts are
> that these proxying functionalities should be moved to the KDC of
> the visited realm. But this would be another topic that I wish to
> start soon.

Why would you want to have the KDC from one realm act as a proxy to
other realms?

You already have a proxy that will be communicating with the KDC
from the local realm.   Why wouldn't that proxy act like a normal
Kerberos client and communicate with each of the realms necessary
to obtain service tickets for the source client?

Jeffrey Altman
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post