Re: Alternative proxy-creds API for constrained-delegation
Isaac Boukris <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.devel |
|---|---|
| Message-ID | <CAC-fF8SvRqc89NwXf27av5vvtJhuYAO+Hw+y24OYc+2zt5W4Ug@mail.gmail.com> |
On Wed, Jun 3, 2020 at 6:01 PM Nico Williams <[email protected]> wrote: > > On Wed, Jun 03, 2020 at 04:11:08PM +0200, Isaac Boukris wrote: > > To me, gss-proxy sounds like a big requirement, I was hoping for a > > simpler plugable client helper mechanism, that simply talks to a > > daemon when needed and puts the ticket in cache for the client to use. > > That's still a proxy. We talked about this on the call. Love had > wanted all of these proxies back in 2012, and I agree with that: > > - krb5_get_credentials() proxy > > - krb5_mk/rd_req*() proxy > > - gss proxy Yes, it would be nice to make this tgt-less creds work for krb5_get_credentials() callers, and not only gss_init_sec_context() callers. _______________________________________________ krbdev mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/krbdev