logo_kerberos.gif

Release 1.12

From K5Wiki
Revision as of 13:26, 2 May 2013 by TomYu (talk | contribs)

Jump to: navigation, search

Timeline

This is only an approximate timeline. Dates are subject to change.

  • Oct. 2013 -- make release branch
  • Dec. 2013 -- final release

Code quality

  • Additional KDC refactoring

Developer experience

End-user experience

  • Reduce DNS-related difficulties with service principal names
    • Config to disable client service principal canonicalization

Administrator experience

Performance

  • AES-NI support for built-in crypto back end

Protocol evolution

  • Ticket flag to signal KDC support for resolving aliases
  • Authorization data -- conditional on IETF consensus
    • Authorization data container with multiple verifiers (CAMMAC)
    • POSIX directory info in authorization data (PAD)
    • Level of Assurance in authorization data
    • Site-defined string-keyed claims in authorization data
    • X.509 attributes in authorization data
  • FAST preauth sets (e.g. OTP + long-term password)