shibboleth-dev - Re: Shibboleth and Kerberos Tickets
Subject: Shibboleth Developers
List archive
- From: "RL 'Bob' Morgan" <>
- To: Shibboleth Dev Team <>
- Subject: Re: Shibboleth and Kerberos Tickets
- Date: Thu, 12 Jul 2007 09:36:38 -0700 (PDT)
On Wed, 11 Jul 2007, Chad La Joie wrote:
I'm pretty much a Kerb noob, so maybe this is a silly question, but isn't it the case that this feature would only be usable intra-organizationally (unless you wanted to do realm trust relationships)? Not that such a limit makes this unworthy of pursuit, but I just want to make sure I understand things correctly.
Right, the KDC (or KDCs?) that are issuing the tickets passed along by the IdP to the middle tier would have to be able to issue tickets consumable by the backend service. In typical Kerberos usage today that would mean that both the backend service and the user would be principals in that one KDC. Kerberos can certainly be set up in a multi-realm way, and some sites run that way (using AD mostly, probably). I don't think this would have any impact on the proposed work, but I've added it as a desired feature.
- RL "Bob"
- Re: Shibboleth and Kerberos Tickets, RL 'Bob' Morgan, 07/11/2007
- Re: Shibboleth and Kerberos Tickets, Chad La Joie, 07/11/2007
- RE: Shibboleth and Kerberos Tickets, Scott Cantor, 07/12/2007
- Re: Shibboleth and Kerberos Tickets, RL 'Bob' Morgan, 07/12/2007
- RE: Shibboleth and Kerberos Tickets, Scott Cantor, 07/12/2007
- RE: Shibboleth and Kerberos Tickets, RL 'Bob' Morgan, 07/12/2007
- RE: Shibboleth and Kerberos Tickets, Scott Cantor, 07/12/2007
- RE: Shibboleth and Kerberos Tickets, RL 'Bob' Morgan, 07/12/2007
- RE: Source attributes from LDAP, Lisa Tan, 07/12/2007
- Re: Source attributes from LDAP, Nate Klingenstein, 07/12/2007
- RE: Source attributes from LDAP, Lisa Tan, 07/12/2007
- Re: Source attributes from LDAP, Nate Klingenstein, 07/12/2007
- Re: Source attributes from LDAP, Nate Klingenstein, 07/12/2007
- RE: Source attributes from LDAP, Lisa Tan, 07/12/2007
- RE: Shibboleth and Kerberos Tickets, RL 'Bob' Morgan, 07/12/2007
- RE: Shibboleth and Kerberos Tickets, Scott Cantor, 07/12/2007
- RE: Shibboleth and Kerberos Tickets, RL 'Bob' Morgan, 07/12/2007
- Re: Shibboleth and Kerberos Tickets, Chad La Joie, 07/11/2007
- Message not available
- Re: Shibboleth and Kerberos Tickets, Chad La Joie, 07/12/2007
- Re: Shibboleth and Kerberos Tickets, Shilen Patel, 07/13/2007
Archive powered by MHonArc 2.6.16.