Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 12 Nov 2005 11:06:26 +0000 (GMT)
From:      Robert Watson <rwatson@FreeBSD.org>
To:        Doug Rabson <dfr@nlsystems.com>
Cc:        arch@freebsd.org
Subject:   Re: New extensible GSSAPI implementation
Message-ID:  <20051112110504.X33260@fledge.watson.org>
In-Reply-To: <200511121042.42425.dfr@nlsystems.com>
References:  <200511121042.42425.dfr@nlsystems.com>

next in thread | previous in thread | raw e-mail | index | archive | help

On Sat, 12 Nov 2005, Doug Rabson wrote:

> For quite a while now (far too long in fact), I've been slowly working 
> on an extension framework for GSS-API. This was partly prompted by an 
> interest in NFSv4 which requires both LIPKEY [RFC2847] as well as 
> Kerberosv5 as security providers. The existing FreeBSD GSS-API library 
> comes from Heimdal and only provides Kerberosv5. It is also a necessary 
> pre-requisite for an implementation of RPCSEC_GSS which I'm not quite 
> ready to commit.

This is great news!  Have you taken a look at the Solaris inclusion of 
gssapi parts in their kernel:

   http://fxr.watson.org/fxr/source/common/gssapi/?v=OPENSOLARIS

I assume this is associated with NFSv4 support, but haven't dug around at 
all yet other than noticing it there the other day.  Most other discussion 
of GSSAPI I've seen assumes that the crypto takes place in user space, but 
having it in kernel has some significant advantages (especially if you 
have a fully preemptive kernel, which we now have).

Robert N M Watson



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20051112110504.X33260>