From owner-freebsd-security@FreeBSD.ORG Sun Sep 7 11:55:31 2008 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id F1522106567B for ; Sun, 7 Sep 2008 11:55:31 +0000 (UTC) (envelope-from mike@sentex.net) Received: from smarthost1.sentex.ca (smarthost1.sentex.ca [64.7.153.18]) by mx1.freebsd.org (Postfix) with ESMTP id B3FCD8FC1A for ; Sun, 7 Sep 2008 11:55:31 +0000 (UTC) (envelope-from mike@sentex.net) Received: from lava.sentex.ca (pyroxene.sentex.ca [199.212.134.18]) by smarthost1.sentex.ca (8.14.2/8.14.2) with ESMTP id m87BtSt3040098 for ; Sun, 7 Sep 2008 07:55:29 -0400 (EDT) (envelope-from mike@sentex.net) Received: from mdt-xp.sentex.net (simeon.sentex.ca [192.168.43.27]) by lava.sentex.ca (8.13.8/8.13.3) with ESMTP id m87BtS2H082832 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Sun, 7 Sep 2008 07:55:28 -0400 (EDT) (envelope-from mike@sentex.net) Message-Id: <200809071155.m87BtS2H082832@lava.sentex.ca> X-Mailer: QUALCOMM Windows Eudora Version 7.1.0.9 Date: Sun, 07 Sep 2008 07:55:26 -0400 To: freebsd-security@freebsd.org From: Mike Tancsa Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii"; format=flowed X-Scanned-By: MIMEDefang 2.64 on 64.7.153.18 Subject: Heimdal or MIT for kerberos? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 07 Sep 2008 11:55:32 -0000 We are looking at deploying Kerberos for better user management (SSO) and 2 factor authentication via pkcs#11 etokens. The servers are all FreeBSD and the machines principals will login from a mix of FreeBSD, Windows and MAC OSX using ssh and openvpn. As part of our compliance project, access must be 2 factor. The Heimdal in RELENG_7 is a rather old version and doesnt seem to have all the bits needed for x509 pre-auth so I would probably need to install from the ports anyways. Does anyone have any suggestions as to which implementation to use ? We are in Canada so it doesnt matter regulation wise. Is one better maintained than the other ? There are no legacy v4 apps Thanks, ---Mike -------------------------------------------------------------------- Mike Tancsa, tel +1 519 651 3400 Sentex Communications, mike@sentex.net Providing Internet since 1994 www.sentex.net Cambridge, Ontario Canada www.sentex.net/mike