[8121] in Kerberos
Re: DCE and Kerberos V5
daemon@ATHENA.MIT.EDU (Terje Normann Marthinussen)
Wed Sep 25 15:43:40 1996
To: kerberos@MIT.EDU
Date: 25 Sep 1996 18:20:20 GMT
From: terjem@cc.uit.no (Terje Normann Marthinussen)
Sean Mullan (mullan_s@apollo.hp.com) wrote:
| Good news. The DCE 1.2.2 release from OSF will provide
| secure versions of rsh and rlogin which do not expose
| the password to the network along with optional forwarding
| of credentials and encrypted sessions (encrypted sessions are
| supported in domestic source only). These also interoperate
^^^^^^^^^^^^^^^^^^^^
Which of course makes it pretty much uninteresting for a rather large
part of the world.
If I've understood right, the first beta of SSH version 2 will be out
within a month or two. I've brought the issue up on the ssh mailing
list, and at least kerberos 5 support is planned, which will probably
make it work with DCE as well (of course a native DCE version would
be very nice).
SSH is made in Finland and is thus exportable to a far greater part of
the world than US products. Also it support authentication with
several methods like RSA public key. As I see it, this makes some very
interesting posibilities for using SSH easily with kerberos/DCE inside
you local organisation while using it with RSA for different hosts
outside which you don't want to establish kerberos/DCE trust
relationships with.
SSH also support encryption of X sessions, compression and forwarding
of tcp sessions.
Here we are using both kerberized rlogin with DCE and SSH and I really
look forward to simplify things by just using SSH.
http://www.cs.hut.fi/ssh/ for more information on SSH.
Terje Marthinussen
terjem@cc.uit.no