[29893] in Kerberos

home help back first fref pref prev next nref lref last post

Re: krb5-sync 1.2 released

daemon@ATHENA.MIT.EDU (Russ Allbery)
Wed May 28 16:48:59 2008

To: kerberos@mit.edu
In-Reply-To: <483DBE35.9050807@slackers.net> (Matthew Andrews's message of
	"Wed\, 28 May 2008 13\:19\:01 -0700")
From: Russ Allbery <rra@stanford.edu>
Date: Wed, 28 May 2008 13:47:18 -0700
Message-ID: <877ideyx49.fsf@windlord.stanford.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Matthew Andrews <matt@slackers.net> writes:

> has anyone attempted to use the patch included in this with newer MIT
> kerberos releases? I'm particularly interested in 1.6.1 with RHEL5
> patches, but if someone has tried this with a similar vintage krb5 I'd
> expect it to be helpful.

I personally haven't looked at it at all.  I'm not sure when I'll get a
chance to do so; we're fairly happy with 1.4, and haven't yet seen a lot
of reason to upgrade to 1.6 (and have seen some issues with 1.6 around
changes related to referrals that make us want to carefully plan
upgrades).  I expect we'll upgrade to 1.6 as part of upgrading our KDCs
from etch to lenny, sometime after the Debian lenny release.

The long-term goal is to add a plugin system to MIT kadmind using the new
plugin support code in 1.6 and later, allowing krb5-sync to just provide a
plugin and not provide a patch.  I put together a proposal for this, but
it has a bunch of unanswered questions and I haven't had time to work on
it further.

-- 
Russ Allbery (rra@stanford.edu)             <http://www.eyrie.org/~eagle/>
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post