Notes from the Kerberos meetings at MIT 13-14 Nov 1996

by: Steve Rothwell

See also: the official meeting agenda page at MIT

This is where all the info about the meeting is. The page will be maintained and revised by Paul Hill. I gave him a copy of my notes and presumably others will too … so eventually you might see official minutes.

Disclaimers

Quotes that capture some of the key points


Table of Contents

Wednesday 13 Nov

  1. Introductions
  2. V4 on UNIX
  3.  kTelnet status
  4. encryption spec
  5. Cygnus on windows and Mac NCSA telnet
  6. Vendor support of kerberos
    1. v5 Realm with v4 compatibility
  7. Kclient API
  8. Discussion of multiple APIs available on Windows
  9. Kerberized applications
  10. Kerberos and the web
  11. breakout sessions
    1. Mac programmers to talk about
      1. Mac UI issues for both v4 and v5.
      2. What are the best features from Kconfig, CNS, MacLeland
    2. Windows programmers to talk about
      1. cache issues 16 bit and 32 bit
      2. application support
      3. OLE vs. Thunking
      4. API for a cache DLL (from v5 discussions)

Thursday, November 14th

  1. Kerberos version 5, GSS API, Kerberos and public key cryptography
  2. JGSS, UIUC's Java implementation of GSS
  3. Current status of GSS API / Kerberos v5 from MIT, Cygnus, Open Vision, Microsoft.
  4. Kerberos v5 interoperability issue
  5. NT GINA (Graphical Identification and Authentication) DLL & SUN's PAM (Pluggable Authentication Modules)
  6. Kerberos and public key infrastructures
  7. Higher level APIs to lower the cost to enter the GSS world
  8. What work is currently being done?

Wed 13 Nov

V4 on Unix

MIT


kTelnet status

Unix

PC


encryption spec


Cygnus on windows and Mac NCSA telnet ..


Vendor support of kerberos


V5 Realm with v4 compatibility

 

 


KClient API

Cygnus

Eudora, telnet various, news watcher, Key server, Qualcomm with locus

Stanford

  • out for a while ...
  • 1.0 since Feb. ...
  • uses MIT/Cygnus based code,
  • spent time making UI as they want it, local config, login feature, screen locking,
  • NOT ACTIVE since Andy Moss left ... have been tugging on his sleeve but are currently "between developers""
  • has a shim to support KClient API
  • supposed to look same,
  • beta any day,
  • Cygnus code based,
  • work done by contractor, who has left vendor and prohibited from working on this, can’t even talk about it.
  • planned to support MFC .... were very important ..
  • intended KClient shim

Windows APIs

Vendors

cache interoperability

Problems with

OS/2 support

NT version (MIT)


Kerberized applications

What apps are available or in progress

Need a common source of information for all of us

Plans for Kerberized services on MAC and MS OSs


Kerberos and the web

access control over the web
assume unmodified browser
2 categories
Callback & Proxy

callback

proxy

on callback topic ...

Ted ... on unix?

KLP

??? OSF originated gradient calls this webCrusader ...

??? MIT

Jeff Hutzleman of UIUC http://www.cs.cmu.edu/~visigoth/shelob

digression about telnet spoofing ...

CMU implementation (other)

Bob Morgan Stanford ...

question on now that we’ve authenticated you, how do we enforce acl ...

Ksign Ted MIT ...

Breakouts

Mac UI issues for v4 & v5

I did not attend this breakout

Windows

cache

16/32 bit application support

OLE -vs- Thunking

API for a cache DLL (from v5 discussions)

Ted Ts'o presented his proposal for a Cache DLL API

Problem 1:

problem 2 ...


Thu 14 Nov

JGSS, UIUC’s Java implementation of GSS

return to yesterday’s topic ... secure http

Current status of GSS API

Kerberos v5 from MIT, Cygnus, Open Vision, Microsoft

MIT (Ted)

Cygnus

Microsoft

K5 interoperability issues

v4 support

interoperability with DCE environment

application vendor interoperability (SAP Oracle PowerBuilder Locus)

Ted (MIT) on interoperability

backwards compatibility to v4 in MITs v5

GINAs


Kerberos and public key infrastructures

using krb to obtain X.509 client certificates JEFF Schiller

Kerberos and VM

other efforts

browser issues with this work

what work is currently being done

what apps are available

where should communication from this meeting go

anyone have a page that’s a list already ...

WWW kerberos mailing list from UIUC ... watch for this on agenda page

state of Krb Mac authentication page from ... everette_allen@ncsu.edu ...

Cygnus

FTP

 

RFC1510 cliff Newman promising replacement ... needed ... cliff won’t respond

internal crypto layer needs to know what it’s being used for ...

other sites part of same realm? accept homework on the net, MIT professors permit hand in via net de-permit at appointed time ...

Mac has chooser level LPR kerberized ... Everett from NC ...

MIT has Mac KLPLPR ... not deployed due to bugs ... secure printing from LPD to printer as Thesis project

Stanford has proof of concept from Brown

Cornell Macs chooser to CAP server all sidecar protected ... charge against but students get money up front

Windows SAPLPD makes it a GSSAPI authenticated client prints to LOCAL printer from central server ... SAP has no plans to do SAPLPD on the Mac

windows/Mac how change PW ...

Stanford

MIT

what apps are being worked on

what docs are available

OpenVision

CYGNUS

Mark?? nutshell book

break out reports

discussion about "what if k5 required people to get gmake" ... special free tool or kerberos release self contained ? already forced ZIP

Mac code already required untar

... long discussion on GMAKE and rototilling the makefiles for Mac ...

14:00 higher level API to lower the cost to enter GS world

OV working with C++ Wrappers

will this group cooperate to create an API or wrappers that will cover most of the GSS API programming tasks that application developers need to do

cats = common authentication technology ... seeking volunteers

John Myers promotes SASL as similar idea ... not alternative ...layers above GSS or other security ... SASL is how you do IMAP .. GSSAPI ... SASL fits into family of nntp, smtp, ntp ...

key signing party ... we’re done

 


last updated by sgr@umich.edu on 21 Nov 1996