Re: [Freeipa-users] Understanding role of the certificate in client - server communication.

2014-03-28 Thread Genadi Postrilko
Thank you for the answer. Is the communication between IPA Client and Server HTTPS based? not just SSL over TCP? So is Kerberos? Does it have to be over HTTP? or its purely over TCP/UDP? 2014-03-19 10:56 GMT+02:00 Alexander Bokovoy aboko...@redhat.com: On Wed, 19 Mar 2014, Genadi Postrilko

Re: [Freeipa-users] Understanding role of the certificate in client - server communication.

2014-03-28 Thread Alexander Bokovoy
On Fri, 28 Mar 2014, Genadi Postrilko wrote: Thank you for the answer. Is the communication between IPA Client and Server HTTPS based? not just SSL over TCP? Depends on the protocol being used. You really need to go and look per protocol. For example: HTTPS is used only when you are using

Re: [Freeipa-users] Understanding role of the certificate in client - server communication.

2014-03-19 Thread Genadi Postrilko
Thank you for the answer. Sory if i lack the knowledge, but why SSL is needed when using kerberos? Kerberos is based on 3th party that is trusted, why there is a need for public key encryption? On Mar 19, 2014 12:24 AM, Rob Crittenden rcrit...@redhat.com wrote: Genadi Postrilko wrote: Hello

Re: [Freeipa-users] Understanding role of the certificate in client - server communication.

2014-03-19 Thread Alexander Bokovoy
On Wed, 19 Mar 2014, Genadi Postrilko wrote: Thank you for the answer. Sory if i lack the knowledge, but why SSL is needed when using kerberos? Kerberos is based on 3th party that is trusted, why there is a need for public key encryption? Using Kerberos only, without asking for integrity and

Re: [Freeipa-users] Understanding role of the certificate in client - server communication.

2014-03-19 Thread Simo Sorce
On Wed, 2014-03-19 at 10:56 +0200, Alexander Bokovoy wrote: On Wed, 19 Mar 2014, Genadi Postrilko wrote: Thank you for the answer. Sory if i lack the knowledge, but why SSL is needed when using kerberos? Kerberos is based on 3th party that is trusted, why there is a need for public key

Re: [Freeipa-users] Understanding role of the certificate in client - server communication.

2014-03-18 Thread Rob Crittenden
Genadi Postrilko wrote: Hello all. I'm trying to understand the use of the certificates in the communication between an IPA client and server. The documentation describes the retrieval of CA certificate while client setup: Retrieve the CA certificate for the IdM CA And retrieval of SSL server