Release 1.11

== Protocol evolution ==
* Authorization data -- conditional on IETF consensus
** Authorization data container with multiple verifiers (CAMMAC)
** POSIX directory info in authorization data (PAD)
** Level of Assurance in authorization data
** Site-defined string-keyed claims in authorization data
** X.509 attributes in authorization data
* FAST preauth sets (e.g. OTP + long-term password)

This is only an approximate timeline. Dates are subject to change.

  • Oct. 2012 -- make release branch
  • Dec. 2012 -- final release

Code quality

Developer experience

End-user experience

Administrator experience


  • Improve (or eliminate) KDC lookaside cache (done)

Protocol evolution

