Re: LibreOffice driver 2: MIT Kerberos vs Microsoft Kerberos - Mailing list pgsql-hackers

From Stephen Frost
Subject Re: LibreOffice driver 2: MIT Kerberos vs Microsoft Kerberos
Date
Msg-id 20111213141822.GS24234@tamriel.snowman.net
Whole thread Raw
In response to LibreOffice driver 2: MIT Kerberos vs Microsoft Kerberos  (Lionel Elie Mamane <lionel@mamane.lu>)
Responses Re: LibreOffice driver 2: MIT Kerberos vs Microsoft Kerberos  (Greg Smith <greg@2ndQuadrant.com>)
List pgsql-hackers
* Lionel Elie Mamane (lionel@mamane.lu) wrote:
> The "gsslib" parameter in the connection string won't work, but will
> that keep users from authenticating to some Kerberos domains, and/or
> are there other (interoperability?) issues that make it strongly
> desirable to link libpq with *both* SSPI *and* MIT krb5 (and its
> gssapi_krb5 library)?

The MIT KRB5 library on Windows is more-or-less defunct now, as I
understand it.  pgAdmin3 hasn't been linking against it due to unfixed
security bugs (that don't seem likely to ever be fixed) and because it's
horribly painful to maintain.

The gist of the limitation is this- if you need to support decent
encryption in a cross-realm environment on Windows XP-age systems, you
need MIT KRB5.  If you're on Windows 7 or something else recent, the
built-in Windows stuff w/ AES works fine.
Thanks,
    Stephen

pgsql-hackers by date:

Previous
From: Greg Smith
Date:
Subject: Re: JSON for PG 9.2
Next
From: Merlin Moncure
Date:
Subject: Re: JSON for PG 9.2