|
|
|
|
|
by charlieok
5409 days ago
|
|
Kerberos fits your description ("protocols designed for enterprise desktops") exactly. The hardest thing I've found about running it across a hostile internet is dealing with NAT issues. The (latest version of the) protocol itself is pretty decent from a security perspective. Then again, the original version of it, when it was designed for enterprise desktops, would not be particularly effective. |
|
It may work acceptably for VPN-like applications, but how does it work for actual internet applications? E.g., how do you enroll new clients into the authentication realm over the internet?