[24955] in Kerberos

home help back first fref pref prev next nref lref last post

Re: X.509 Interop

daemon@ATHENA.MIT.EDU (Mark Sirota)
Thu Nov 17 10:24:39 2005

Date: Thu, 17 Nov 2005 10:23:34 -0500
From: Mark Sirota <msirota@isc.upenn.edu>
To: kerberos@mit.edu
Message-ID: <3C96FCAA61DB4D94CB939B10@marmaduke.net.isc.upenn.edu>
In-Reply-To: <SJVef.30778$u43.2018@twister.nyc.rr.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Errors-To: kerberos-bounces@mit.edu

--On November 17, 2005 6:49:22 AM +0000 Jeffrey Altman 
<jaltman2@nyc.rr.com> wrote:
> The CITI group at UMichigan also has a project that allows you to
> use a Kerberos service ticket to obtain an X.509 certificate with
> the same lifetime as the Kerberos ticket.

Assuming I'm thinking of the same project, this is called "KX.509".  We
worked with it extensively here at Penn, hoping to make it our new standard
for web-based authentication.

We made considerable progress and submitted our patches back to Michigan,
but we never deployed into production because there isn't enough browser
support for client-side X.509 certificates.  For non-web applications, this
might be more suitable.

Mark
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post