Mutual authentication and delegation

Ken Hornstein kenh at cmf.nrl.navy.mil
Fri Mar 8 17:15:10 EST 2002


>Put simply, delegating to a server is a dangerous business.  We require
>MUTUAL_AUTH to ensure that you're really delegating to the correct,
>intended entity.  

And to further follow up to the original message ....

Is there any reason to _NOT_ do mutual authentication?

--Ken



More information about the Kerberos mailing list