Skip to Content.
Sympa Menu

shibboleth-dev - RE: Shibboleth and Kerberos Tickets

Subject: Shibboleth Developers

List archive

RE: Shibboleth and Kerberos Tickets


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Subject: RE: Shibboleth and Kerberos Tickets
  • Date: Fri, 13 Jul 2007 20:07:08 -0400

> The applications that receive the proxy token treat the proxy token just
> like a password. The applications just pass it to the backend servers,
> which have a PAM module to support it. Does that answer your question?

If it's treated like a password, then what's the significance of Kerberos to
this use case? Couldn't any attribute be used like this already?

It seems odd to overcomplicate the code with Kerberos if you're bypassing
the cryptographic parts. Or maybe I'm still not getting it.

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page