Re: EAP-Kerberos

2005-07-19 Thread Sam Hartman
Saber == Saber Zrelli [EMAIL PROTECTED] writes: Saber I was referring to a KDC instead of an IAKERB proxy. My Saber thoughts are that these proxying functionalities should be Saber moved to the KDC of the visited realm. But this would be Saber another topic that I wish to start

Re: EAP-Kerberos

2005-07-19 Thread Jeffrey Altman
Saber Zrelli wrote: I was referring to a KDC instead of an IAKERB proxy. My thoughts are that these proxying functionalities should be moved to the KDC of the visited realm. But this would be another topic that I wish to start soon. Why would you want to have the KDC from one realm act as a

Kerberos and AAA stds

2005-07-19 Thread Saber Zrelli
Hello , I think that authentication operations should be centralized. I mean by centralized that the whole access network and the access server should rely on a single entity to obtain authentication for users from local realm and roaming users. This schema is more extendable and more organized