Re: Design Considerations for New Authentication Methods

Поиск
Список
Период
Сортировка
От Magnus Hagander
Тема Re: Design Considerations for New Authentication Methods
Дата
Msg-id 6BCB9D8A16AC4241919521715F4D8BCEA0FCF0@algol.sollentuna.se
обсуждение исходный текст
Ответ на Re: Design Considerations for New Authentication Methods  (mark@mark.mielke.cc)
Ответы Re: Design Considerations for New Authentication Methods
Список pgsql-hackers
> > To be honest, I have often wondered *why* we support
> kerberos outside
> > of the uber l33t geek factor. I have not once in a commercial
> > deployment had a business requirement for the beast. LDAP?
> Now that is
> > a whole other issue :)
>
> Isn't NFSv4 a big application that uses Kerberos? I seem to
> recall that AFS may have been a large user as well.

AFS definitly used it.

But if you're looking for a "big application" that uses Kerberos,
there's that pesky thing called Windows. Every single Windows machine in
an active directory domain environment is a Kerberos client, and uses
Kerberos for authentication to all network services.

So Kerberos is definitly big. And more and more apps do support GSSAPI
for authentication. Not that many apps support "raw kerberos" as pgsql
does, probably because it does have some compatibility issues and such
things.

//Magnus


В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Magnus Hagander"
Дата:
Сообщение: Re: Design Considerations for New Authentication Methods
Следующее
От: mark@mark.mielke.cc
Дата:
Сообщение: Re: Design Considerations for New Authentication Methods