[14466] in Kerberos
un-kerberized clients
daemon@ATHENA.MIT.EDU (Russell P. Sutherland)
Mon May 21 19:34:50 2001
Date: Mon, 21 May 2001 19:32:26 -0400
From: "Russell P. Sutherland" <russ@madhaus.cns.utoronto.ca>
To: kerberos@MIT.EDU
Message-ID: <20010521193226.A31077@madhaus.cns.utoronto.ca>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
I am beginning a project to bring kerberos into a campus wide
authentication scheme.
Most of our current server-client applications use a WWW browser
as the client.
Two simple questions:
1. What are the options currently available to kerberize WWW browsers?
2. Is it possible for a server/principal to access the KDC and gain
sufficient information to authenticate an "non-kerberized" request from
a client (say a WWW browser using a SSL session)?
Thanks in advance.
--
Russell P. Sutherland Email: russ@madhaus.cns.utoronto.ca
4 Bancroft Ave., Rm. 102 Voice: +1.416.978.0470
University of Toronto Fax: +1.416.978.6620
Toronto, ON M5S 1C1 WWW: http://madhaus.cns.utoronto.ca/~russ
CANADA