Concealing user principal names for realm crossover

Rick van Rein rick at openfortress.nl
Wed Mar 18 04:26:29 EDT 2015


Hi Greg,

Thanks once more for an extensive answer!  It really helps that you point out the
paths, and even already balance pros and cons.

I also don’t know if Kitten will be interested, but we’re willing to help out if this is
the case.  Since we’re doing this for other credential types, it would mark Kerberos
as bad when we left it behind; and since it is a “local” matter (client-side only) I
think we’re going to design and build it first.  Then we’ll be sharing here and on Kitten
to see what people think of the result, and if an interest exists we can proceed to an
I-D — after making the local code.

Thanks a lot!
 -Rick


More information about the Kerberos mailing list