« I will be presenting at JavaOne 2007 on ehcache | Main | Glassfish does not support SPNEGO and Kerberos - Yet »

February 27, 2007

Kerberos is cool

The last few weeks I have been working on a single sign on/Kerberos project.

For anyone for whom either of those term is new, here is some food for thought. Windoze, Linux, Mac OS X (10.4), Firefox, IE, Apache, ssh... has, in the past 10 years been Kerberised. Rather than Microsoft's Embrace Extend Annihilate being the death knell for Kerberos, their endorsement legitimised it.

Add in SPNEGO, another M$ innocation, which added browsers into single sign on, and here we are. Much of everything we need is Kerberised. An overnight success which took a decade. It is a very good time to adopt Kerberos.

Over the next little while I intend creating a Kerberos/Glassfish HOWTO, showing how to add a Glassfish security realm to a Kerberos realm. If you look in your JAVA_HOME/bin directory, you will see kinit and klist, Yes Java was Kerberised in 1.4.2. There is a Kerberos Login Config: com.sun.security.auth.module.Krb5LoginModule

Posted by gluck at February 27, 2007 06:59 PM

Comments