[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Proposal: remove krb5-appl (rlogin, rsh, telnet, ftp with krb5 support)



On Mon, Jan 27, 2014 at 11:27:52AM +0100, Simon Toedt wrote:
> Hint: Before further claiming the obsolesce of krb-rsh/rlogin vs ssh
> please try ssh on an ARM box (e.g gumstix) vs krb-rsh. ssh takes
> almost 2.6 seconds to complete (even with tuning and using arcfour),
> krb-rsh executes the same in less than 0.07 seconds.

It's certainly slower on ARM boxes but I'd argue that the specific
case where this is really painful - large farms - is either not
applicable to low power ARM or is sufficiently niche that those folks
could reasonably be expected to build their own rsh.

> If courses there is another issue: What still left as "use case" of
> Kerberos5 if krb-rsh and krb-rlogin are no longer available? Typical
> university setup is krb-NFSv3/krb-NFSv4 plus krb-rlogin internally and
> ssh only for external access. What do you wish to sell them as
> krb-rsh/rlogin replacement? ssh? Seriously?

We use krb/ssh, my last University did the same. I've never seen one
still using rsh, but I'm prepared to believe they exist. More data
needed to assume that's the norm, though.


Reply to: