|
From: Jonathan Kamens <jik@kamens.brookline.ma.us> In brief, the question seems to be, "What does Kerberos give me that SSL doesn't?" That question is specific case of the general question, "What are the advantages and disadvantages of a private-key, trusted-third-party authentication system vs. a public-key, certificate-based authentication system?" As I see it, SSL has two major advantages over Kerberos: (1) It doesn't require an accessible trusted third party; (2) it can be used to establish a secure connection even when one end of the connection doesn't have a "secret" (a.k.a. "key" or "password"). These two advantages make it ideal for secured Web communication and for similar applications where there is a large user base which is not known in advance. [ Here are some disadvantages of SSL: ] 1) Key revocation. If a Verisign certificate issued to a user is compromised and must be revoked, how will all the servers with whom that user interacts know that the certificate is no ...
more
|
|
In brief, the question seems to be, "What does Kerberos give me that SSL doesn't?" That question is specific case of the general question, "What are the advantages and disadvantages of a private-key, trusted-third-party authentication system vs. a public-key, certificate-based authentication system?" As I see it, SSL has two major advantages over Kerberos: (1) It doesn't require an accessible trusted third party; (2) it can be used to establish a secure connection even when one end of the connection doesn't have a "secret" (a.k.a. "key" or "password"). These two advantages make it ideal for secured Web communication and for similar applications where there is a large user base which is not known in advance. [ Here are some disadvantages of SSL: ] 1) Key revocation. If a Verisign certificate issued to a user is compromised and must be revoked, how will all the servers with whom that user interacts know that the certificate is no longer valid?
more
|
What are the advantages/disadvantages of Kerberos vs. SSL?
Related Questions
- Jonathan Creek has been shown in the following countries abroad (i.e. outside the UK). Alas I don't know ...
- No, the Duke and Randall weren't lovers, though the Duke certainly understood Randall's psychology, and no ...
- Yes it is! Please see the merchandise page for details of what is available.
- Besides buying the music or donating, you can help by spreading the word. This means putting me on mix CDs ...
- Most recording is done on a Digi 002 with Pro Tools LE on a Mac G4 desktop. I also use Ableton Live, Apple ...