[3703] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

Re: [krbdev.mit.edu #1278] No prompter interface for krb5_get_init_creds_keytab

daemon@ATHENA.MIT.EDU (via RT)
Tue Dec 17 13:07:13 2002

Message-Id: <rt-1278-3779.11.983450054931@krbdev.mit.edu>
In-Reply-To: <rt-1278@krbdev.mit.edu>
From: " via RT" <rt-comment@krbdev.mit.edu>
Reply-To: rt-comment@krbdev.mit.edu
To: krb5-prs@mit.edu
Errors-To: krb5-bugs-admin@mit.edu
Date: Tue, 17 Dec 2002 13:06:12 -0500 (EST)


"Ken Hornstein via RT" <rt-comment@krbdev.mit.edu> writes:

>> I discovered recently that the API krb5_get_init_creds_keytab doesn't
>> take a prompter argument.  This makes it difficult to do things like
>> hardware preauthentication using a key stored in a keytab.
>> 
>> Any comments?

Why do you think you need this?  The idea of getting initial creds
from a keytab is that a daemon or other automated task can act as a
kerberos client without user interaction.  If you require user
interaction, why aren't you just using a password?

                Marc
_______________________________________________
krb5-bugs mailing list
krb5-bugs@mit.edu
http://mailman.mit.edu/mailman/listinfo/krb5-bugs

home help back first fref pref prev next nref lref last post