Re: Alternative proxy-creds API for constrained-delegation

Isaac Boukris <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.devel
Message-ID <CAC-fF8SvRqc89NwXf27av5vvtJhuYAO+Hw+y24OYc+2zt5W4Ug@mail.gmail.com>
On Wed, Jun 3, 2020 at 6:01 PM Nico Williams <[email protected]> wrote:
>
> On Wed, Jun 03, 2020 at 04:11:08PM +0200, Isaac Boukris wrote:
> > To me, gss-proxy sounds like a big requirement, I was hoping for a
> > simpler plugable client helper mechanism, that simply talks to a
> > daemon when needed and puts the ticket in cache for the client to use.
>
> That's still a proxy.  We talked about this on the call.  Love had
> wanted all of these proxies back in 2012, and I agree with that:
>
>  - krb5_get_credentials() proxy
>
>  - krb5_mk/rd_req*() proxy
>
>  - gss proxy

Yes, it would be nice to make this tgt-less creds work for
krb5_get_credentials() callers, and not only gss_init_sec_context()
callers.
_______________________________________________
krbdev mailing list             [email protected]
https://mailman.mit.edu/mailman/listinfo/krbdev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.