AW: kcpytkt to copy a service ticket for client principal not matching the default principal

Josef Petermann <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.devel
Message-ID <AM0PR0402MB3780EE668A0724FFE9615690FB9D0@AM0PR0402MB3780.eurprd04.prod.outlook.com>
Hi Greg,

thanks for the hint regarding Heimdal's implementation, 
we managed to use kgetcred to extract the service credential.

    # kinit -k -t /etc/httpd/rstudio-server.keytab [email protected]
    # kvno -k /etc/httpd/rstudio-server.keytab -U jpetermann -P HTTP/[email protected]
    # kgetcred -n --out-cache=/home/jpetermann\@lab.biz/cache45 HTTP/[email protected]

> I have been thinking of adding some options from Heimdal's kgetcred to
> kvno, including --out-ccache, which initializes a ccache and stores the
> retrieved credential into it.  Would that be adequate here?

It would be really helpful for us to have that functionality in krb5 as well, yes. 
Note that we also needed to use the -n flag to create a cache in the name of the "foreign" client principal.

Thanks,
Josef
_______________________________________________
krbdev mailing list             [email protected]
https://mailman.mit.edu/mailman/listinfo/krbdev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.