[1144] in Kerberos_V5_Development
Re: motivation for multiple keys per principal
daemon@ATHENA.MIT.EDU (Theodore Ts'o)
Thu May 9 11:19:30 1996
Date: Thu, 9 May 1996 11:18:43 -0400
From: Theodore Ts'o <tytso@MIT.EDU>
To: Bill Sommerfeld <sommerfeld@orchard.medford.ma.us>
Cc: "Richard Basch" <basch@lehman.com>, "Barry Jaspan"
<bjaspan@MIT.EDU>,
krbdev@MIT.EDU
In-Reply-To: Bill Sommerfeld's message of Thu, 09 May 1996 09:13:17 -0400,
<199605091313.NAA01899@orchard.medford.ma.us>
Date: Thu, 09 May 1996 09:13:17 -0400
From: Bill Sommerfeld <sommerfeld@orchard.medford.ma.us>
Well, here's one which isn't implemented, but should be:
Smooth migration from one krbtgt/* key version number to the next.
The goal's actually generalizable --- smooth migration of a service key
from one version number to the next. I believe most of the
infrastructure is implemented already; what's missing is administration
programs that will do the right thing w.r.t. to the Kerberos database
and the srvtab file.
- Ted