GNU Shishi


Introduction

This page contains information about Shishi, a free implementation of the Kerberos 5 network security system.

If you do not know what Kerberos 5 is, I suggest to read the Kerberos V5 standard. Also see the page with related research papers that may be of interest.

The goals of this project are:

  • Full standards compliance.
  • Thread safe library.
  • Internationalization, both for client messages but also for non-ASCII username and passwords.
  • Integrate with existing password management systems (/etc/passwd, PAM, SASL).
  • Support authentication using OpenPGP and X.509 through TLS, including smart card support.
  • Clean room implementation with clear copyright and license.

Shishi is licensed under the GPLv3, and the Shishi manual is licensed under the GFDL.

Table of Contents


Documentation and Status

Refer to the Shishi Manual web page for links to the manual in all formats; however, quick links to the most popular formats:

Shishi has received some real-world testing and should be considered stable, although it is still a fairly young implementation. Basic support for acquiring and managing tickets are working, as well as serving requests in a Key Distribution Center daemon. DES, 3DES and AES cipher suites are supported. A PAM module for host security is included, as well as a Shishi port of a rsh/rlogin client.

A telnet client and server with Kerberos authentication is supported via GNU InetUtils. A SSH client and server with Kerberos authentication is supported via GSS and GSS-LSH. A IMAP server with Kerberos authentication (GSSAPI SASL mechanism) is supported via GNU MailUtils. A IMAP command line client with Kerberos authentication (GSSAPI SASL mechanism) is supported via GNU SASL, which also provide authentication (including Kerberos 5 via GSSAPI) via the SASL API for any application.

Shishi is developed for the GNU/Linux system, but runs on over 20 platforms including most major Unix platforms and Windows, and many kind of devices including iPAQ handhelds and S/390 mainframes.

Shishi requires GNU Libtasn1, which is included in the package, so you do not need to install it separately.

Shishi can optionally use GnuTLS (for OpenPGP and X.509 authentication), GNU Libidn (recommended for non-ASCII support), and GNU libgcrypt.

News

Note that new releases are only mentioned here if they introduce a major feature or is significant in some other way. Read the info-gnu mailing list if you seek more frequent announcements.

  • 2010年05月20日: Version 1.0.0 released, takes Shishi out of alpha testing.
  • 2007年06月29日: Version 0.0.32 released under the GPLv3.
  • 2006年03月25日: Version 0.0.23 released, mainly as a foundation to build official Debian packages.
  • 2006年01月17日: Experimental Shishi packages for Debian are available.
  • 2004年11月12日: The experimental STARTTLS support is now documented in an Internet draft.
  • 2004年06月13日: The InetUtils work has its own home page now, and will be a playground for new features (even non-Shishi related) in GNU InetUtils.
  • 2004年01月22日: New releases are no longer announced here, and hasn't been for a while. Instead, read info-gnu or check the release directory from time to time. By the way, Shishi 0.0.14 was just released.
  • 2004年01月13日: A new snapshot of GNU InetUtils with Shishi support was released. Build it as usual for Kerberos support, i.e., with --enable-encryption --enable-authentication. It includes telnet(d), rsh(d) and rlogin(d) with Shishi support.
  • 2004年01月01日: Savannah had problems last month, and still isn't operating fully. CVS has been moved to a private machine, a read-only mirror of it will hopefully be available via Savannah in the future.
  • 2003年10月16日: Shishi 0.0.8 released. STARTTLS upgrade of TCP connections (only anonymous DH for now). Password processing via SASLprep instead of KRBprep. Authorization and documentation improvements.
  • 2003年10月11日: Snapshot of Shishi-port of GNU InetUtils released, contains telnet(d) and rsh(d) with Kerberos 5 support via Shishi. Developed by Nicolas Pouvesle.
  • 2003年10月01日: Shishi-port of GNOME Ticket Applet added, see below.
  • 2003年09月21日: Shishi 0.0.7 released. DES-CBC-CRC and ARCFOUR works. Short-hand aliases for encryption type names are supported.
  • 2003年09月14日: Shishi 0.0.6 released. Proxiable, proxy, forwardable and forwarded tickets supported. Man pages for all public functions are included. The internal crypto interface now fully modularized.
  • 2003年09月07日: Shishi 0.0.5 released. SAFE and PRIV fixes. Server name to realm mapping via DNS. Reference manual.
  • 2003年08月31日: Shishi 0.0.4 released. KDC works. Shishi port of rsh/rlogin client, contributed by Nicolas Pouvesle, included. Accompanies GSSLib 0.0.5.
  • 2003年08月25日: Shishi becomes a GNU project.
  • 2003年08月22日: Shishi 0.0.3 released.
  • 2003年08月17日: Shishi 0.0.2 released.
  • 2003年08月10日: Shishi 0.0.1 released. Few new features, but improved internally. Accompanies GSSLib 0.0.4.
  • 2003年06月23日: A patch for telnet(d) in GNU InetUtils that implement Kerberos 5 authentication via Shishi is published.
  • 2003年06月02日: Shishi 0.0.0 released. No major changes compared to last snapshot, but used by Generic Security Services API (GSS-API) 0.0.0.
  • 2003年02月11日: Another snapshot release. Used by GNU SASL.
  • 2002年12月26日: Moved project to savannah.
  • 2002年12月14日: Second snapshot released.
  • 2002年12月13日: PAM works.
  • 2002年12月08日: Telnetd works.
  • 2002年12月01日: Web page opened and a snapshot released.
  • 2002年11月25日: Telnet works.
  • 2002年10月26日: Code moved into CVS.
  • 2002年09月30日: Started coding.

Support

A mailing list where Shishi users may help each other exists, and you can reach it by sending e-mail to help-shishi@gnu.org. Archives of the mailing list discussions, and an interface to manage subscriptions, is available through the World Wide Web at http://lists.gnu.org/mailman/listinfo/help-shishi.

If you are interested in paid support of Shishi, or sponsor the development, please contact me. If you provide paid services for Shishi, and would like to be mentioned here, also contact me.

The following organizations provide paid support for Shishi:

Downloading

The stable releases are distributed from https://ftp.gnu.org/gnu/shishi/.

The latest release is signed with OpenPGP key with fingerprint F8C4 D73C F638 C53C 06BE. Earlier releases were signed with an OpenPGP key with fingerprint B565716F or OpenPGP key with fingerprint 5A33 0664 A769 5426 5E8C.

Development

There is a Savannah Shishi project page. You can check out the sources by using git as follows:

$ git clone https://git.savannah.gnu.org/git/shishi.git

The online git interface is available.

See the file README-alpha on how to bootstrap and build the package from version controlled sources.

We publish cyclomatic code complexity charts, self-test code coverage charts, and Clang code analysis

Screenshot

Since Shishi is a library, there isn't much in the way of graphical user interfaces to show. However, the GNOME 2 port of Ticket Applet support Shishi, so we can at least show how it looks.

Screenshot

There is a snapshot release of Ticket Applet available from https://alpha.gnu.org/pub/gnu/shishi/ticket-applet-shishi-*.tar.gz.