[15576] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Creating GSSAPI initiate credential using keytab entry--how

daemon@ATHENA.MIT.EDU (Sam Hartman)
Wed Mar 10 14:18:24 2010

From: Sam Hartman <hartmans@mit.edu>
To: Greg Hudson <ghudson@mit.edu>
Date: Wed, 10 Mar 2010 14:18:17 -0500
In-Reply-To: <1268247844.18898.445.camel@ray> (Greg Hudson's message of "Wed, 
	10 Mar 2010 14:04:04 -0500")
Message-ID: <tslsk88f0jq.fsf@mit.edu>
MIME-Version: 1.0
Cc: "krbdev@MIT.EDU" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

>>>>> "Greg" == Greg Hudson <ghudson@MIT.EDU> writes:

    Greg> On Wed, 2010-03-10 at 12:36 -0500, Sam Hartman wrote:
    >> Would it be a good idea to wrap all this logic into
    >> gss_acquire_credential so that if you have a keytab you can just
    >> use it as an initiator?  I.E. would that be a good improvement
    >> for the future?

    Greg> Possibly.  Or we could do the
    Greg> credentials-cache-backed-by-a-keytab idea.

    Greg> I think it requires at least some thought, though.  Currently
    Greg> our GSSAPI library only does TGS requests, not AS requests.
    Greg> If it start doing AS requests, then it becomes a consumer of
    Greg> the gic_opt framework and the preauth framework, and there are
    Greg> some (probably manageable) implications there.

We already will have to deal with this for  iakerb.
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post