> From: tech-boun...@lists.lopsa.org [mailto:tech-boun...@lists.lopsa.org] > On Behalf Of Jonathan Billings > > Wouldn’t it be better to push for proven technology like Kerberos, GSSAPI, > and SPNEGO rather than a unimplemented (and, frankly, untested) concept > solution? BTW, Chrome and Firefox both support SPNEGO.
Kerberos sends passwords to KDC's. You'd have to be more specific about what authentication mechanism is chosen in GSSAPI or SPNEGO, to really be able to respond to those questions. The phrase unimplemented and untested is inaccurate, assuming you're talking about cbcrypt. _______________________________________________ Tech mailing list Tech@lists.lopsa.org https://lists.lopsa.org/cgi-bin/mailman/listinfo/tech This list provided by the League of Professional System Administrators http://lopsa.org/