Re: documentation vs specification
Russ Allbery <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | The Eyrie |
| Message-ID | <[email protected]> |
Jeffrey Hutzelman <[email protected]> writes: > The original point of this thread was to discuss a deficiency in kstart, > which does not avoid a situation in which applications using a ccache > may see an _empty_ cache. The best solution for that problem is for > kstart to obtain new initial credentials into, say, a MEMORY cache, then > truncate the managed ccache and copy the new credentials in, all under > the same lock. > Unfortunately, the current API doesn't seem to provide a way to do that. > This is a failing in the API, not a flaw in the established access > pattern for file ccaches. The right fix is to fix the API. Failing > that, it would be appropriate for a program like kstart to write the new > credentials into a new file cache, then move it into place. Oh, good, thank you for the sanity check. That was the same conclusion I reached, but I wasn't positive. -- Russ Allbery ([email protected]) <http://www.eyrie.org/~eagle/>