[OT] Re: GGF's extensions to GSS in Public Comment
Nicolas Williams <[email protected]> Mon, 5 Apr 2004 23:59:13 -0500
| Newsgroups | gmane.ietf.cat |
|---|---|
| Message-ID | <[email protected]> |
[Off topic] On Mon, Apr 05, 2004 at 10:12:03PM -0400, Jeffrey Altman wrote: > Nicolas Williams wrote: > > >(Doesn't the new Kfw MLSA ccache type pretty much mean that Kfw has a > >single credential store peruser on Windows? Yes, it can still use > >KRB5CCNAME for other ccache types, but those aren't shared with the > >LSA...) > > > MIT krb5_ccache API provides access to multiple > ccache types. These include "FILE:", "API:", > "MEMORY:", and "MSLSA:" at the current time. > On Windows and Macintosh, the default krb5_ccache type > is "API:" (aka CCAPI). The "MSLSA:" krb5_ccache type > provides shared access to the LSA cache allowing the > same credentials to be used by both MIT Krb5 API clients > and Kerberos SSP clients. This was my understanding. Is there only one LSA cache per-user? This is interesting here because where there's one cache per-user the environment variable thing makes no sense at all. > >[1] AFS uses Kerberos IV, though it seems possible to use it with > > Kerberos V and, in any case, with krb524 it's possible to use > > GSS-API initiator credentials for the Kerberos V mechanism with > > AFS. > > > OpenAFS and Arla support both Kerberos IV and Kerberos 5 tickets > types. krb524d is not required when an appropriate aklog is > provided. MIT KfW 2.6.1 will provide such an aklog. Sure, but that's not interesting here. What's interesting is the need to share a credential store with another entity (the kernel, gssd, the LSA, whatever) -- putenv(3) hardly fits the bill for that. Nico -- -++**==--++**==--++**==--++**==--++**==--++**==--++**== This message was posted through the Stanford campus mailing list server. If you wish to unsubscribe from this mailing list, send the message body of "unsubscribe ietf-cat-wg" to [email protected]