Re: trouble deciding which kerberos flavor

2010-10-25 Thread Ken Dreyer
On Thu, Oct 21, 2010 at 1:10 PM, eric krb.h...@hopevaleufsd.org wrote:
 I just want to know any differences that MIT and Heimdal have with each
 other:

I think someone at the 2010 Kerberos Conference summarized it this way:

 MIT is likely to be what your OS vendor ships. Heimdal has more features.

- Ken

Kerberos mailing list   Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos


Re: trouble deciding which kerberos flavor

2010-10-25 Thread Christopher D. Clausen
Ken Dreyer ktdre...@ktdreyer.com wrote:
 On Thu, Oct 21, 2010 at 1:10 PM, eric krb.h...@hopevaleufsd.org wrote:
 I just want to know any differences that MIT and Heimdal have with each
 other:

 I think someone at the 2010 Kerberos Conference summarized it this way:

 MIT is likely to be what your OS vendor ships. Heimdal has more features.

I'd say that depends on the features you want.

Unless my information is out of date, MIT KDCs support policies where you 
can setup groups of principals with different security requirements (like 
say, students, faculty, staff, hosts, services, etc.) and then customize 
password length, strength, expiration and other settings for each of these 
groups.  In Heimdal this needs to be set on each principal which makes it 
really annoying to change after initial account creation.

CDC


Kerberos mailing list   Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos