Re: If you use kerberos/ssl

2014-08-12 Thread Viktor Dukhovni
On Tue, Aug 12, 2014 at 11:17:36PM -0400, Jeffrey Altman wrote: > > The modern way to combine Kerberos with TLS is GSSAPI with channel > > binding. The old crufty Kerberos support should be deleted from > > "master". No new features should be added to this code. > > RFC 2712 is a Proposed Stand

Re: If you use kerberos/ssl

2014-08-12 Thread Jeffrey Altman
On 8/12/2014 6:06 PM, Viktor Dukhovni wrote: > On Tue, Aug 12, 2014 at 04:22:21PM -0400, Salz, Rich wrote: > >> Can you take a look at http://rt.openssl.org/Ticket/Display.html?id=549 >> And let us know what you think? > > I contribute bits of code to MIT and Heimdal Kerberos and maintain > a Ker

Re: If you use kerberos/ssl

2014-08-12 Thread Viktor Dukhovni
On Tue, Aug 12, 2014 at 04:22:21PM -0400, Salz, Rich wrote: > Can you take a look at http://rt.openssl.org/Ticket/Display.html?id=549 > And let us know what you think? I contribute bits of code to MIT and Heimdal Kerberos and maintain a Kerberos infrastructure for a living. I would like to see O

If you use kerberos/ssl

2014-08-12 Thread Salz, Rich
Can you take a look at http://rt.openssl.org/Ticket/Display.html?id=549 And let us know what you think? -- Principal Security Engineer Akamai Technologies, Cambridge MA IM: rs...@jabber.me Twitter: RichSalz