OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

wss message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [wss] Groups - wss-kerberos-interop.doc uploaded


> Detailed Kerberos interop scenarios

Some folks here took a look at this.

We understand that only using a single realm makes things simpler; it may
in fact reflect the most common use pattern.  Unless the interop is
on-site, however, this is going to cause issues as few firewalls will
allow UDP traffic.

The primary difference between the two scenarios is who "owns" the KDC;
this makes sense.  Unfortunately, the phrase used is "manufactured" which
doesn't make sense, as it would seem to prevent a broad class of
vendors, as well as those running the MIT reference implementation, from
participating.  Perhaps "run by" is a better word?

	/r$

-- 
Rich Salz                  Chief Security Architect
DataPower Technology       http://www.datapower.com
XS40 XML Security Gateway  http://www.datapower.com/products/xs40.html
XML Security Overview      http://www.datapower.com/xmldev/xmlsecurity.html



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]