[37006] in Kerberos

home help back first fref pref prev next nref lref last post

Differentiate the ServiceTicket issued from Kinit vs PKinit

daemon@ATHENA.MIT.EDU (Aravind Jerubandi)
Fri May 22 15:14:29 2015

MIME-Version: 1.0
Date: Fri, 22 May 2015 11:03:46 -0700
Message-ID: <CAFiFpn=RZGwzVphSyn7WtKwhepAYUUQg1AihOn2HaOz4Dc2_uA@mail.gmail.com>
From: Aravind Jerubandi <aravind.jerubandi@gmail.com>
To: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Hello,

Today we use password based authentication (kinit). And we want to
introduce PKinit. But while validating ServiceTicket we would like to know
if the service ticket issued through Kinit to PKinit

Is there a way to find this?

If not, the other solution is to use different realms for Kinit and Pkinit.
But then we will have duplicate all the user and service principals for the
two realms. Is there any other easier solution?

Any help would be much appreciated.


-- 
Thanks,
Aravind
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post