<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Opening the Development Process</title>
	<atom:link href="http://www.painless-security.com/blog/2007/10/01/krb5-open/feed" rel="self" type="application/rss+xml" />
	<link>http://www.painless-security.com/blog/2007/10/01/krb5-open</link>
	<description>Sam Hartman on Security for Real-World Users</description>
	<lastBuildDate>Tue, 15 Mar 2011 10:50:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
	<item>
		<title>By: http://the-olo.livejournal.com/</title>
		<link>http://www.painless-security.com/blog/2007/10/01/krb5-open/comment-page-1#comment-5</link>
		<dc:creator>http://the-olo.livejournal.com/</dc:creator>
		<pubDate>Fri, 09 Nov 2007 18:16:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.painless-security.com/blog/2007/10/krb5-open/#comment-5</guid>
		<description>Hi!

I have a thought about general future direction for Kerberos and I&#039;d like to share it. IMO Kerberos protocol should be merged into LDAP protocol (using LDAP extended operations or even devising a new revision of the LDAP protocol itself).

Currently lots of people get confused by the separation of those two, and use them improperly (e.g. the widespread use of LDAP for authentication using LDAP simple bind operation).
The present implementations should also be to blame - it&#039;s quite complex to e.g. get OpenLDAP and MIT Kerberos to work together, while there should be a solution that practically works out of the box.

You can read my detailed thoughts on this subject on my blog:
http://olo.org.pl/dr/node/27</description>
		<content:encoded><![CDATA[<p>Hi!</p>
<p>I have a thought about general future direction for Kerberos and I&#8217;d like to share it. IMO Kerberos protocol should be merged into LDAP protocol (using LDAP extended operations or even devising a new revision of the LDAP protocol itself).</p>
<p>Currently lots of people get confused by the separation of those two, and use them improperly (e.g. the widespread use of LDAP for authentication using LDAP simple bind operation).<br />
The present implementations should also be to blame &#8211; it&#8217;s quite complex to e.g. get OpenLDAP and MIT Kerberos to work together, while there should be a solution that practically works out of the box.</p>
<p>You can read my detailed thoughts on this subject on my blog:<br />
<a href="http://olo.org.pl/dr/node/27">http://olo.org.pl/dr/node/27</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

