[15557] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: config file verification tool

daemon@ATHENA.MIT.EDU (Mark Phalan)
Fri Mar 5 06:26:16 2010

MIME-version: 1.0
Date: Fri, 05 Mar 2010 12:25:44 +0100
From: Mark Phalan <Mark.Phalan@sun.com>
In-reply-to: <8DD7AD829AB61E499A433D6E558110A31B653C94@EXPO7.exchange.mit.edu>
To: krbdev@mit.edu
Message-id: <4B90EA38.7010605@Sun.COM>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On 02/24/10 02:44 PM, Zhanna Tsitkova wrote:
> Hello, A new kerberos configuration file validation tool is now
> checked-in under src/util/confvalidator/validator.py.
>
> First, the configuration file is parsed (confparser.py) and validated
> against formating errors (such as mismatching brackets) Then the list
> of the allowed configuration attributes is compiled from k5-int.h (
> based on KRB5_CONF_xxx macros in 1.8 ) and rules.yml ("Attributes:"
> section) Finally, the kerberos configuration file is validated
> against this list of the allowed strings. If the error, or something
> that validator does not understand, is found then the warning is
> issued in the tree-like form indicating the layer where the problem
> has occurred.
>
> Your comments/feedback will be very much appreciated.

Sounds great. It would be nice if some of this functionality could be 
included in libkrb5 itself so that a more detailed error message could 
be generated on a krb5.conf parse error.
Any plans to do that?

Thanks,

-M
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post