[15505] in Kerberos_V5_Development
Re: pkinit prompting behavior issue
daemon@ATHENA.MIT.EDU (Sam Hartman)
Mon Feb 22 21:07:09 2010
From: Sam Hartman <hartmans@mit.edu>
To: MIT Kerberos Dev List <krbdev@mit.edu>
Date: Mon, 22 Feb 2010 21:07:04 -0500
In-Reply-To: <20100222224639.GM14762@sun.com> (Will Fiveash's message of "Mon,
22 Feb 2010 16:46:39 -0600")
Message-ID: <tsl635o4sdz.fsf@mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
>>>>> "Will" == Will Fiveash <William.Fiveash@sun.com> writes:
Will> What I observe when the pkinit preauth plugin is configured to
Will> use PKCS11 and it doesn't find a PKCS11 token is that it
Will> doesn't prompt the user to insert a token and instead just
Will> returns failure. As people have pointed out this is a problem
Will> for apps like pam_krb5 which is relying on the pkinit plugin
Will> to prompt for it's auth needs. What I'd like to see is the
Will> pkinit plugin (when configured for PKCS11) prompt the user to
Will> insert/provide a token if it doesn't find one (using a
Will> localized string). This would be default behavior but if
Will> needed could be controlled by a new pkinit config parameter to
Will> prevent such a prompt (in which case the pkinit plugin would
Will> behave as it does now).
I think this sounds good. At first, I was wondering whether you should
still prompt if you can't even find a reader. However I'm not sure it's
easy to determine that at the PKCS11 level. Also, if you have a USB
token, that's the wrong approach.
--Sam
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev