advice on kerberizing products

Jeffrey Altman jaltman at secure-endpoints.com
Thu Apr 24 00:23:35 EDT 2008


Another reason for dynamically loading the libraries with dlopen() is 
that your
application is not purely dependent upon Kerberos for authentication.  If
Kerberos or GSSAPI is not available, should your application refuse to
execute?

If the application functionality is useful without network authentication,
then dlopen() is definitely the way to go.

Jeffrey Altman

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3355 bytes
Desc: S/MIME Cryptographic Signature
Url : http://mailman.mit.edu/pipermail/kerberos/attachments/20080424/afb86d71/attachment.bin


More information about the Kerberos mailing list