Since Fedora is not aimed at enterpise/business ..

Chris Ricker kaboom at gatech.edu
Thu Oct 2 15:36:43 UTC 2003


On Thu, 2 Oct 2003, Bill Anderson wrote:

> Kerberos does not do X11-forwarding, for example. Nor does Kerberos
> provide remote file copying (such as sftp and scp). Kerberos is
> authentication. SSH while possessing strong authentication is more than
> an authentication architecture. Thus, they are *different* and serve
> *different* purposes.

Not exactly. You're right that Kerberos is an authentication protocol, but
MIT Kerberos also includes encrypted replacements for many common
applications:

telnet
ftp
r* protocols

If you're in a Kerberized environment, you can safely use Kerberos rcp, rsh, 
etc., be encrypted and securely authenticated, and not need SSH at all....

About all that SSH offers that the Kerberized apps don't are the "weird 
things" Dax mentioned, like port forwarding.

later,
chris





More information about the fedora-devel-list mailing list