[7725] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos GSSAPI client to DCE GSSAPI service

daemon@ATHENA.MIT.EDU (Bill Sommerfeld)
Mon Aug 5 12:48:52 1996

To: "Barry Jaspan" <bjaspan@MIT.EDU>
Cc: Doug Engert <deengert@anl.gov>, honey@citi.umich.edu, kerberos@MIT.EDU
In-Reply-To: bjaspan's message of Mon, 05 Aug 1996 11:41:20 -0400.
	     <9608051541.AA12290@DUN-DUN-NOODLES.MIT.EDU> 
Date: Mon, 05 Aug 1996 12:31:11 -0400
From: Bill Sommerfeld <sommerfeld@apollo.hp.com>

> At one point I think that DCE was also going to include a Kerberos
> mechanism, but I have no idea about its current status.

DCE's GSSAPI implementation includes two mechanisms: a "DCE"
mechanism, and a "kerberos 5" mechanism.  The latter is interoperable
over-the-wire with other kerberos 5 mechanisms (modulo the "mechanism
OID shuffle"), though for various reasons it uses DCE string name
forms (/.../realm/principal) instead of Kerberos string name forms
(principal@realm) above the API.

					- Bill

home help back first fref pref prev next nref lref last post