Re: [Broken test case] Cryptic error message, fallback handling issue
Stephane LAPIE <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <[email protected]> |
Just making sure it will be using the proper keytab entry, as otherwise Windows/IE "might" throw a fit over the Kerberos principal not being the same as the entered URL. I basically coerce every access to be redirected to http://application.domain/, at which stage I proceed with Kerberos authentication. Also, given I generate & deploy my Apache configuration files, using the application vhost name or Any is not a big change either way. It's just I thought it would be "cleaner" to use key A for application A, and ensure it can only ever be that way. So, no real specific reason, besides having clearly defined things everywhere, which is especially important in a hybrid environment. :) On 01/12/2012 10:31 AM, Henry B. Hotz wrote: > How about "Any"? Is there an actual reason to restrict functionality that way? (I'm not saying it ought to blow up of course.) > > On Dec 29, 2011, at 11:09 PM, Stephane LAPIE wrote: > >> -> KrbServiceName set as HTTP/[email protected] (to >> ensure the queried URL matches the used SPN) > > ------------------------------------------------------ > The opinions expressed in this message are mine, > not those of Caltech, JPL, NASA, or the US Government. > [email protected], or [email protected] > > > -- Stephane LAPIE, EPITA SRS, Promo 2005 "Even when they have digital readouts, I can't understand them." --MegaTokyo
signature.asc
(application/pgp-signature, 262 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAk8OQDsACgkQ24Ql8u6TF2OrIQCeN97FSn5sd9js4pNX6I2zx2Ev 1VIAoJ19+Blp+efx1zeYzZ4i7wJ2J6W8 =Ir6v -----END PGP SIGNATURE-----