[2560] in Kerberos
Re: Help needed with Kerb. procedures
daemon@ATHENA.MIT.EDU (Shawn Mamros)
Sat Feb 6 02:11:17 1993
Date: 5 Feb 93 23:35:04 GMT
From: mamros@athena.lkg.dec.com (Shawn Mamros)
Reply-To: mamros@athena.lkg.dec.com (Shawn Mamros)
To: kerberos@shelby.Stanford.EDU
Kerberos really only implements authentication (identifying who the
communicating principals are to each other, and allowing them to
communicate securely), not authorization (deciding who's allowed to
do what to whom). It's up to the application/service to decide how it
wants to do authorization.
While both are necessary, trying to come up with a general-purpose
authorization mechanism for *any* possible application is extremely
difficult. Either it winds up being too simple-minded and not really
useful, or it ends up being horribly complex, difficult to understand,
and therefore not really useful (or, even worse, potentially dangerous
if used by someone who only "sort of" understands them). Sadly, IMO,
DCE Security's ACL mechanism falls squarely into the latter camp...
-Shawn Mamros
E-mail to: mamros@athena.lkg.dec.com
All stated opinions are mine, and probably mine alone...