Re: Insecure WWW Access Authorization Protocol?

Peter Lister, Cranfield Computer Centre (P.Lister@cranfield.ac.uk)
Mon, 7 Mar 1994 12:51:35 --100


> So my advice is to use tried and tested public key management. Export

But I want tried and tested Kerberos, Dave!! Many sites use Kerberos now, and
it's much more important for me to be able to authenticate my local users (who
already have Kerberos tickets when they login), rather than off-site users.
While I wouldn't stop local users from using PGP/PEM if they want, I don't
want to have to put another authentication system in place just to
authenticate WWW when I have a perfectly good Kerberos set up already.

Peter Lister Email: p.lister@cranfield.ac.uk
Computer Centre, Cranfield University Voice: +44 234 754200 ext 2828
Cranfield, Bedfordshire MK43 0AL UK Fax: +44 234 750875
--- Go stick your head in a pig. (R) Sirius Cybernetics Corporation ---