[5434] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Using TCP for authentication

daemon@ATHENA.MIT.EDU (Jonathan I. Kamens)
Wed Jun 28 14:40:05 1995

To: kerberos@MIT.EDU
Date: 28 Jun 1995 18:26:23 GMT
From: jik@cam.ov.com (Jonathan I. Kamens)

Kerberos has always used UDP rather than TCP.  I don't believe there's any
implementation of the Kerberos protocol out there which uses TCP instead of
UDP, although there's always the OSF DCE Kerberos-like thing, i.e., the DCE
protocol which encapsulates Kerberos protocol inside DCE RPC packets, which
can probably be made to use TCP instead of UDP.

RFC 1510 even specifies that when IP is used as the transport layer for
talking to the KDC, UDP should be used.

I suspect that the people who "reserved" (I put that in quotes because they
never actually got the port officially assigned) port 750 for Kerberos, they
reserved both the TCP and UDP entries in /etc/services to avoid confusion. 
The same is probably true of port 88, the officially assigned Kerberos port.

-- 
Jonathan Kamens  |  OpenVision Technologies, Inc.  |   jik@cam.ov.com

home help back first fref pref prev next nref lref last post