Disclaimer: I am not a lawyer and you should not take this as legal advice. No, it is not illegal to export Kerberos *binaries* that are used for authentication-only purposes. Currently, authentication is exempted from the need to obtain an export license. Some of the encryption options for telnet or rlogin clients that make use of Kerberos would not be exportable except in certain specific cases (for a foreign office of a wholy-owned U.S. subsidiary, certain banking uses, etc) unless an export license was obtained. It is illegal to export Kerberos *sources* that include encryption algorithms (or even the "hooks" to permit encryption algorithms to be easily added) without first obtaining an export license. This is because the source to the algorithms (in electronic form) are considered to be munitions (although the normal printed form are not). > Since Microsoft has kept their radius in beta, does anyone know if they > plan to Kerberos as opposed to RADIUS and will Ascends support Kerberos? Ascend Access Control [the non-free RADIUS server from Ascend] already has support for Kerberos V4 on platforms which support Kerberos V4 (Solaris) and the commerce department has agreed Access Control can be exported without a license. Kerberos V4 and Kerberos V5 are not by default interoperable. It is likely that, if Microsoft does release Windows NT 5.0 with Kerberos V5 support, then shortly [2-6 months] after the release of Windows NT 5.0 [which may be after Q2 1998], Access Control will add support for Kerberos V5. This is the most likely option for adding Kerberos support with an Ascend box. Kevin ++ Ascend Users Mailing List ++ To unsubscribe: send unsubscribe to ascend-users-request@bungi.com To get FAQ'd: <<A HREF="http://www.nealis.net/ascend/faq">http://www.nealis.net/ascend/faq</A>> </PRE> <!--X-MsgBody-End--> <!--X-Follow-Ups--> <!--X-Follow-Ups-End--> <!--X-References--> <HR> <STRONG>References</STRONG>: <UL> <LI><STRONG><A HREF="msg09112.html">(ASCEND) Kerberos / NT's Auth. and MAX</A></STRONG></LI> <UL> <LI><EM>From</EM>: Mike Adams <madams@orca.net></LI> </UL> <LI><STRONG><A HREF="msg09114.html">Re: (ASCEND) Kerberos / NT's Auth. and MAX</A></STRONG></LI> <UL> <LI><EM>From</EM>: Matt Holdrege <matt@ascend.com></LI> </UL> </UL> <!--X-References-End--> <!--X-BotPNI--> <HR> <UL> <LI>Prev by Date: <STRONG><A HREF="msg09168.html">Re: (ASCEND) Pipeline 400</A></STRONG> </LI> <LI>Next by Date: <STRONG><A HREF="msg09167.html">Re: (ASCEND) 5.0ap27????</A></STRONG> </LI> <LI>Prev by thread: <STRONG><A HREF="msg09123.html">Re: (ASCEND) Kerberos / NT's Auth. and MAX</A></STRONG> </LI> <LI>Next by thread: <STRONG><A HREF="msg09711.html">Re: (ASCEND) Kerberos / NT's Auth. and MAX</A></STRONG> </LI> <LI>Index(es): <UL> <LI><A HREF="mail34.html#09169"><STRONG>Main</STRONG></A></LI> <LI><A HREF="thrd182.html#09169"><STRONG>Thread</STRONG></A></LI> </UL> </LI> </UL> <!--X-BotPNI-End--> <!--X-User-Footer--> <!--X-User-Footer-End--> </BODY> </HTML>