[24959] in Kerberos
Re: X.509 Interop
daemon@ATHENA.MIT.EDU (Mark Sirota)
Thu Nov 17 12:57:29 2005
Date: Thu, 17 Nov 2005 12:56:43 -0500
From: Mark Sirota <msirota@isc.upenn.edu>
To: "Douglas E. Engert" <deengert@anl.gov>, rektide@gmail.com
Message-ID: <20E976489CF9AA9BFF4156D2@marmaduke.net.isc.upenn.edu>
In-Reply-To: <437CB85B.90601@anl.gov>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
--On November 17, 2005 11:05:31 AM -0600 "Douglas E. Engert"
<deengert@anl.gov> wrote:
> There is browser support! Along with the UMich Kx509 that works with
> the IE there is the kpkcs11 for all the others browsers. This implements
> a PKCS11 Security device plugin, and it works on Unix or Windows with
> Netscape, Mozilla or any other browser that can use smatcards
> via a PKCS11 plugin. It should also work on a Mac too.
Might be worth looking into again. Our last investigation (probably two
years ago) showed that while IE pretended to support this, it did goofy
things -- if the server advertised the capability, the browser would ask
the user which certificate to present, even if the user had zero
certificates
in their cache. Support for this would have been nightmarish. Safari
worked, kinda, but required some goofy hackery. I don't remember the rest
off the top of my head.
Mark
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos