[7267] in Kerberos

home help back first fref pref prev next nref lref last post

Re: DCE and terminal servers

daemon@ATHENA.MIT.EDU (Rich Salz)
Mon May 13 20:41:26 1996

To: kerberos@MIT.EDU
Date: 14 May 1996 00:17:41 GMT
From: rsalz@osf.org (Rich Salz)

In <4mvnp2$kde@news.fsu.edu> houle@zeppo (Art Houle) writes:
>  Multiple other  
>terminal server vendors also support kerberos but to my knowledge none
>support DCE.

You will probably be able to use your DCE security server as your Krb5
server.  OSF has never tested this, but the Kerberos code is there and
at least some folks have it working.  This will be tested and "guaranteed"
in DCE 1.2.2.

>   Please correct me if wrong, but kerberos only authenticates, does not 
>authorize and also uses the TCP/IP wire protocol.  DCE however does both 
>authentication and authorization and uses RPC on UDP (?) to exchange packets.

I assume the Kerberized terminal server maps the krb-provided name as an
index into the terminal server's authorization database.

>  Any suggestions for a terminal server that can integrate in the DCE 
>environment is greatly apreciated.

Short answer:  any Kerberos server will probably "just work."
	/r$

home help back first fref pref prev next nref lref last post