[OT] Re: GGF's extensions to GSS in Public Comment

Nicolas Williams <[email protected]> Mon, 5 Apr 2004 23:59:13 -0500
Newsgroups gmane.ietf.cat
Message-ID <[email protected]>
[Off topic]

On Mon, Apr 05, 2004 at 10:12:03PM -0400, Jeffrey Altman wrote:
> Nicolas Williams wrote:
> 
> >(Doesn't the new Kfw MLSA ccache type pretty much mean that Kfw has a
> >single credential store peruser on Windows?  Yes, it can still use
> >KRB5CCNAME for other ccache types, but those aren't shared with the
> >LSA...)
> >
> MIT krb5_ccache API provides access to multiple
> ccache types.  These include "FILE:", "API:",
> "MEMORY:", and "MSLSA:" at the current time.
> On Windows and Macintosh, the default krb5_ccache type
> is "API:" (aka CCAPI).  The "MSLSA:" krb5_ccache type
> provides shared access to the LSA cache allowing the
> same credentials to be used by both MIT Krb5 API clients
> and Kerberos SSP clients.

This was my understanding.  Is there only one LSA cache per-user?  This
is interesting here because where there's one cache per-user the
environment variable thing makes no sense at all.

> >[1]  AFS uses Kerberos IV, though it seems possible to use it with
> >    Kerberos V and, in any case, with krb524 it's possible to use
> >    GSS-API initiator credentials for the Kerberos V mechanism with
> >    AFS.
> >
> OpenAFS and Arla support both Kerberos IV and Kerberos 5 tickets
> types.  krb524d is not required when an appropriate aklog is
> provided.  MIT KfW 2.6.1 will provide such an aklog.

Sure, but that's not interesting here.  What's interesting is the need
to share a credential store with another entity (the kernel, gssd, the
LSA, whatever) -- putenv(3) hardly fits the bill for that.

Nico
-- 
-++**==--++**==--++**==--++**==--++**==--++**==--++**==
This message was posted through the Stanford campus mailing list
server.  If you wish to unsubscribe from this mailing list, send the
message body of "unsubscribe ietf-cat-wg" to [email protected]