Re: documentation vs specification

Russ Allbery <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Organization The Eyrie
Message-ID <[email protected]>
Jeffrey Hutzelman <[email protected]> writes:

> The original point of this thread was to discuss a deficiency in kstart,
> which does not avoid a situation in which applications using a ccache
> may see an _empty_ cache.  The best solution for that problem is for
> kstart to obtain new initial credentials into, say, a MEMORY cache, then
> truncate the managed ccache and copy the new credentials in, all under
> the same lock.

> Unfortunately, the current API doesn't seem to provide a way to do that.
> This is a failing in the API, not a flaw in the established access
> pattern for file ccaches.  The right fix is to fix the API.  Failing
> that, it would be appropriate for a program like kstart to write the new
> credentials into a new file cache, then move it into place.

Oh, good, thank you for the sanity check.  That was the same conclusion I
reached, but I wasn't positive.

-- 
Russ Allbery ([email protected])             <http://www.eyrie.org/~eagle/>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.