[14466] in Kerberos

home help back first fref pref prev next nref lref last post

un-kerberized clients

daemon@ATHENA.MIT.EDU (Russell P. Sutherland)
Mon May 21 19:34:50 2001

Date: Mon, 21 May 2001 19:32:26 -0400
From: "Russell P. Sutherland" <russ@madhaus.cns.utoronto.ca>
To: kerberos@MIT.EDU
Message-ID: <20010521193226.A31077@madhaus.cns.utoronto.ca>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

I am beginning a project to bring kerberos into a campus wide
authentication scheme.

Most of our current server-client applications use a WWW browser
as the client.

Two simple questions:

1. What are the options currently available to kerberize WWW browsers?

2. Is it possible for a server/principal to access the KDC and gain
   sufficient information to authenticate an "non-kerberized" request from
   a client (say a WWW browser using a SSL session)?

Thanks in advance.

-- 
Russell P. Sutherland      	Email: russ@madhaus.cns.utoronto.ca
4 Bancroft Ave., Rm. 102	Voice: +1.416.978.0470
University of Toronto		Fax:   +1.416.978.6620
Toronto, ON  M5S 1C1 		WWW:   http://madhaus.cns.utoronto.ca/~russ
CANADA

home help back first fref pref prev next nref lref last post