the use of Kerberos

> From: ashar@osmosys.incog.com (Ashar Aziz)
> Are you saying, e.g. that Kerberos cannot be
> used with IPSP because it doesn't provide perfect forward
> secrecy?
There is no proposal for using Kerberos for IPSP key management.  One of
the (many) reasons is the lack of perfect forward secrecy.

Kerberos is, however, under serious consideration for providing
KDC signatures used as a service by key management in establishing and
authenticating session keys.