Re: [Freeipa-users] Is GSSAPI secure without TLS?

2013-07-15 Thread Simo Sorce
On Fri, 2013-07-12 at 17:46 -0400, Dmitri Pal wrote: > On 07/12/2013 05:36 PM, Erinn Looney-Triggs wrote: > > On 07/12/2013 05:03 PM, Dmitri Pal wrote: > > > On 07/12/2013 11:33 AM, Erinn Looney-Triggs wrote: > > > > GSSAPI inside of a TLS channel apparently isn't secure unless the > > > > channel

Re: [Freeipa-users] Is GSSAPI secure without TLS?

2013-07-12 Thread Dmitri Pal
On 07/12/2013 05:36 PM, Erinn Looney-Triggs wrote: > On 07/12/2013 05:03 PM, Dmitri Pal wrote: >> On 07/12/2013 11:33 AM, Erinn Looney-Triggs wrote: >>> GSSAPI inside of a TLS channel apparently isn't secure unless the >>> channel is secure and verified. The irony being that GSSAPI auth outside >>>

Re: [Freeipa-users] Is GSSAPI secure without TLS?

2013-07-12 Thread Erinn Looney-Triggs
On 07/12/2013 05:03 PM, Dmitri Pal wrote: > On 07/12/2013 11:33 AM, Erinn Looney-Triggs wrote: >> GSSAPI inside of a TLS channel apparently isn't secure unless the >> channel is secure and verified. The irony being that GSSAPI auth outside >> of a TLS connection is just fine for postfix. > > Is th

[Freeipa-users] Is GSSAPI secure without TLS?

2013-07-12 Thread Dmitri Pal
On 07/12/2013 11:33 AM, Erinn Looney-Triggs wrote: > GSSAPI inside of a TLS channel apparently isn't secure unless the > channel is secure and verified. The irony being that GSSAPI auth outside > of a TLS connection is just fine for postfix. Is this really the case? I am under the impression that