Bluehost.com Web Hosting $6.95

Re: OpenSSH PKCS#11merge

This is a discussion on Re: OpenSSH PKCS#11merge within the OpenSSH Development forums, part of the Networking and Network Related category; Alon Bar-Lev wrote: > Kerberos is a single point of failure in term of availability and security. Ummm... how? ...


Go Back   Usenet Forums > Networking and Network Related > OpenSSH Development

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 09-27-2007
Carson Gaspar
 
Posts: n/a
Default Re: OpenSSH PKCS#11merge

Alon Bar-Lev wrote:

> Kerberos is a single point of failure in term of availability and security.


Ummm... how? If you have 50 KDCs, what single point of availability
failure is there? Yes, a compromised KDC key store is bad, but then so
is a compromised CA. Actually, I'd say the compromised CA is worse (or
has revocation actually been deployed in the real world yet? Oh wait, it
hasn't been.)

> Even if Kerberos is a good solution for one domain network, how can
> you access foreign networks?


Cross-realm trust

> And even if you Kerberos the whole world... How can you securely
> access the Kerberos KDC when the KDC is down?


Have more than one... duh.

> Just like OpenSSH can access file based keys it should be able to use
> smarcard based keys and PKCS#11 is the common interface to access
> smartcards.


I'm not against smartcard support. But Kerberos bashing is not the way
to get it. Especially underinformed (if I'm being charitable) bashing.

PKI, solving yesterday's problems, tomorrow, for over a decade...

--
Carson
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
https://lists.mindrot.org/mailman/li...enssh-unix-dev
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 04:49 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0