[7955] in Kerberos

home help back first fref pref prev next nref lref last post

Confused on internet wide kerberos encryption

daemon@ATHENA.MIT.EDU (Nick Kralevich)
Sat Sep 14 01:56:24 1996

Date: Fri, 13 Sep 1996 22:36:34 -0700 (PDT)
From: Nick Kralevich <nickkral@ferrari.autobahn.org>
To: kerberos@MIT.EDU


I've been reading though the documentation for Kerberos, but there are 
still some things I don't understand.

In the documentation, it says:

   Since Kerberos negotiates authenticated, and optionally encrypted, 
   communications between any two points on the internet, it provides a 
                               ^^^^^^^^^^^^^^^^^^^^^^^^^
   layer of security that is not dependent on which side of a firewall 
   either client is on.

Let's say I choose two computers at random, both of which are running 
kerberos aware clients, but are not in the same relm.  For example, I 
might setup a kerberos system at home, and one at work, completely 
independent.  

How can I get an encrypted session from work to home, or visa versa.  My 
understanding is that the kerberos program needs to be aware of any other 
kerberos tickets, and must know how to contact other key distribution 
centers.

I'm confused on how exactly this would be done, without modifying either 
client's config files.

Take care, and thanks in advance for a response.

-- Nick Kralevich
   nickkral@autobahn.org


home help back first fref pref prev next nref lref last post