Talking with Kerberized services using GSS-API

Steve Langasek vorlon at dodds.net
Fri Oct 18 14:18:50 EDT 2002


On Fri, Oct 18, 2002 at 02:12:34PM -0400, Frank Balluffi wrote:

> To the best of my knowledge, SASL supports authentication, but not 
> (application-level) encryption, whereas the GSS-API supports 
> authentication and encryption (e.g., via the gss_wrap and gss_unwrap 
> functions).

SASL does support encryption.  I'm using SASL-enabled LDAP with GSSAPI
authentication, and the data stream is automatically encrypted with
certain LDAP clients.

Steve Langasek
postmodern programmer



More information about the Kerberos mailing list