[15505] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: pkinit prompting behavior issue

daemon@ATHENA.MIT.EDU (Sam Hartman)
Mon Feb 22 21:07:09 2010

From: Sam Hartman <hartmans@mit.edu>
To: MIT Kerberos Dev List <krbdev@mit.edu>
Date: Mon, 22 Feb 2010 21:07:04 -0500
In-Reply-To: <20100222224639.GM14762@sun.com> (Will Fiveash's message of "Mon, 
	22 Feb 2010 16:46:39 -0600")
Message-ID: <tsl635o4sdz.fsf@mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

>>>>> "Will" == Will Fiveash <William.Fiveash@sun.com> writes:

    Will> What I observe when the pkinit preauth plugin is configured to
    Will> use PKCS11 and it doesn't find a PKCS11 token is that it
    Will> doesn't prompt the user to insert a token and instead just
    Will> returns failure.  As people have pointed out this is a problem
    Will> for apps like pam_krb5 which is relying on the pkinit plugin
    Will> to prompt for it's auth needs.  What I'd like to see is the
    Will> pkinit plugin (when configured for PKCS11) prompt the user to
    Will> insert/provide a token if it doesn't find one (using a
    Will> localized string).  This would be default behavior but if
    Will> needed could be controlled by a new pkinit config parameter to
    Will> prevent such a prompt (in which case the pkinit plugin would
    Will> behave as it does now).

I think this sounds good.  At first, I was wondering whether you should
still prompt if you can't even find a reader.  However I'm not sure it's
easy to determine that at the PKCS11 level.  Also, if you have a USB
token, that's the wrong approach.

--Sam
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post