[30291] in CVS-changelog-for-Kerberos-V5

home help back first fref pref prev next nref lref last post

krb5 commit: Clarify documentation on pkinit_identities

daemon@ATHENA.MIT.EDU (Greg Hudson)
Wed Sep 26 15:21:03 2018

Date: Wed, 26 Sep 2018 15:20:52 -0400
From: Greg Hudson <ghudson@mit.edu>
Message-Id: <201809261920.w8QJKqx3027239@drugstore.mit.edu>
To: cvs-krb5@mit.edu
Reply-To: krbdev@mit.edu
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: cvs-krb5-bounces@mit.edu

https://github.com/krb5/krb5/commit/e095b436d92d9aa30106509b5ccf76719e1668b3
commit e095b436d92d9aa30106509b5ccf76719e1668b3
Author: Greg Hudson <ghudson@mit.edu>
Date:   Thu Sep 6 13:20:56 2018 -0400

    Clarify documentation on pkinit_identities
    
    The documentation for pkinit_identities implies that we try harder to
    use each value before ignoring the rest, when in fact we only go as
    far as the first successful parse.  Soften the language and describe
    the most likely use case for multiple values under the current
    semantics.
    
    ticket: 8733
    tags: pullup
    target_version: 1.16-next

 doc/admin/conf_files/krb5_conf.rst |   10 +++++-----
 1 files changed, 5 insertions(+), 5 deletions(-)

diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst
index 68c69df..42c117a 100644
--- a/doc/admin/conf_files/krb5_conf.rst
+++ b/doc/admin/conf_files/krb5_conf.rst
@@ -1134,11 +1134,11 @@ PKINIT krb5.conf options
 
 **pkinit_identities**
     Specifies the location(s) to be used to find the user's X.509
-    identity information.  This option may be specified multiple
-    times.  Each value is attempted in order until identity
-    information is found and authentication is attempted.  Note that
-    these values are not used if the user specifies
-    **X509_user_identity** on the command line.
+    identity information.  If this option is specified multiple times,
+    the first valid value is used; this can be used to specify an
+    environment variable (with **ENV:**\ *envvar*) followed by a
+    default value.  Note that these values are not used if the user
+    specifies **X509_user_identity** on the command line.
 
 **pkinit_kdc_hostname**
     The presense of this option indicates that the client is willing
_______________________________________________
cvs-krb5 mailing list
cvs-krb5@mit.edu
https://mailman.mit.edu/mailman/listinfo/cvs-krb5

home help back first fref pref prev next nref lref last post