Subject: Re: krb5 for ssh2
To: Gabriel Kihlman <gk@abc.se>
From: Roland Dowdeswell <elric@imrryr.org>
List: tech-security
Date: 05/16/2003 10:26:52
On 1053066735 seconds since the Beginning of the UNIX epoch
Gabriel Kihlman wrote:
>

>One good reason is mentioned by Damien Miller here:
>http://www.mindrot.org/pipermail/openssh-unix-dev/2003-May/018257.html
>
>Following that thread would probably be fruitful if you want to
>decide on which direction you want to go.

From a quick perusal of that thread it seems that the big reason
stated for not incorporating the code is that it is large.  I do
not see this as a good reason for not including proper GSSAPI
support.  There are many advantages of the GSSAPI code over any of
the kerberos methods that are supported of course, and you don't
ever get something for nothing.

I think that the features make a serious consideration of importing
the code into our copy of openssh a worthwhile project.

--
    Roland Dowdeswell                      http://www.Imrryr.ORG/~elric/