If you use kerberos/ssl

2014-08-12 Thread Salz, Rich
Can you take a look at http://rt.openssl.org/Ticket/Display.html?id=549 And let us know what you think? -- Principal Security Engineer Akamai Technologies, Cambridge MA IM: rs...@jabber.memailto:rs...@jabber.me Twitter: RichSalz

Re: If you use kerberos/ssl

2014-08-12 Thread Jeffrey Altman
On 8/12/2014 6:06 PM, Viktor Dukhovni wrote: On Tue, Aug 12, 2014 at 04:22:21PM -0400, Salz, Rich wrote: Can you take a look at http://rt.openssl.org/Ticket/Display.html?id=549 And let us know what you think? I contribute bits of code to MIT and Heimdal Kerberos and maintain a Kerberos

Re: If you use kerberos/ssl

2014-08-12 Thread Viktor Dukhovni
On Tue, Aug 12, 2014 at 11:17:36PM -0400, Jeffrey Altman wrote: The modern way to combine Kerberos with TLS is GSSAPI with channel binding. The old crufty Kerberos support should be deleted from master. No new features should be added to this code. RFC 2712 is a Proposed Standard. I