[18785] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Automatic FAST via Anonymous PKINIT

daemon@ATHENA.MIT.EDU (Nico Williams)
Fri May 30 11:08:58 2014

MIME-Version: 1.0
In-Reply-To: <5387815B.9040504@mit.edu>
Date: Fri, 30 May 2014 09:16:07 -0500
Message-ID: <CAK3OfOi9sZmWEQsF0JB2_i7vsELQvjSEsdSV8-9j5e_wgLJ1QQ@mail.gmail.com>
From: Nico Williams <nico@sparkhere.com>
To: Greg Hudson <ghudson@mit.edu>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

Greg's #1 works, just inefficiently.  It's a lot better than nothing and a
no-brainer.  #2 doesn't help much.  #3 might be more useful than you think,
but I'd store the FAST armor ticket (it's constrained, isn't it?) in the
normal ccache, with a link to it from a ccconfig entry.  #4 is clearly
desirable from a systems pov, though i would prefer an IPC protocol so as
to be better able to apply least privilege principles.  Still, #4 looks
very nice, so it gets my +1.

Nico
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post