Re: [OT] Re: GGF's extensions to GSS in Public Comment

Jeffrey Altman <[email protected]> Tue, 06 Apr 2004 01:19:08 -0400
Newsgroups gmane.ietf.cat
Organization No Longer Affiliated with Columbia University in the City of New York
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------020708030003050406070506
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit

Nicolas Williams wrote:

>[Off topic]
>
>On Mon, Apr 05, 2004 at 10:12:03PM -0400, Jeffrey Altman wrote:
>
>>Nicolas Williams wrote:
>>
>>
>>>(Doesn't the new Kfw MLSA ccache type pretty much mean that Kfw has a
>>>single credential store peruser on Windows?  Yes, it can still use
>>>KRB5CCNAME for other ccache types, but those aren't shared with the
>>>LSA...)
>>>
>>>
>>MIT krb5_ccache API provides access to multiple
>>ccache types.  These include "FILE:", "API:",
>>"MEMORY:", and "MSLSA:" at the current time.
>>On Windows and Macintosh, the default krb5_ccache type
>>is "API:" (aka CCAPI).  The "MSLSA:" krb5_ccache type
>>provides shared access to the LSA cache allowing the
>>same credentials to be used by both MIT Krb5 API clients
>>and Kerberos SSP clients.
>>
>
>This was my understanding.  Is there only one LSA cache per-user?  This
>is interesting here because where there's one cache per-user the
>environment variable thing makes no sense at all.
>
There is one cache associated with the LSA session.
A process or thread can create a new cache which is not
associated with the session.  However, it would be
inappropriate to use an environment variable in this case. 

Within the context of a logon session a krb5_ccache name is unique.
There is no guarantee that the krb5_ccache name will be unique across
the entire system.   Using an environment variable would certainly
fail in any situation in which you either had a single process (a 
multi-threaded
server) in which each thread must maintain its own cache reference
or where the processes exist in different logon session spaces.  For example
a user process communicating with a daemon process.

Jeffrey Altman


--------------020708030003050406070506
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type">
  <title></title>
</head>
<body bgcolor="#ffffff" text="#000000">
<font face="Bitstream Cyberbit">Nicolas Williams wrote:</font>
<blockquote cite="[email protected]"
 type="cite">
  <pre wrap=""><font face="Bitstream Cyberbit">[Off topic]

On Mon, Apr 05, 2004 at 10:12:03PM -0400, Jeffrey Altman wrote:
</font></pre>
  <blockquote type="cite">
    <pre wrap=""><font face="Bitstream Cyberbit">Nicolas Williams wrote:

</font></pre>
    <blockquote type="cite">
      <pre wrap=""><font face="Bitstream Cyberbit">(Doesn't the new Kfw MLSA ccache type pretty much mean that Kfw has a
single credential store peruser on Windows?  Yes, it can still use
KRB5CCNAME for other ccache types, but those aren't shared with the
LSA...)

</font></pre>
    </blockquote>
    <pre wrap=""><font face="Bitstream Cyberbit">MIT krb5_ccache API provides access to multiple
ccache types.  These include "FILE:", "API:",
"MEMORY:", and "MSLSA:" at the current time.
On Windows and Macintosh, the default krb5_ccache type
is "API:" (aka CCAPI).  The "MSLSA:" krb5_ccache type
provides shared access to the LSA cache allowing the
same credentials to be used by both MIT Krb5 API clients
and Kerberos SSP clients.
</font></pre>
  </blockquote>
  <pre wrap=""><!----><font face="Bitstream Cyberbit">
This was my understanding.  Is there only one LSA cache per-user?  This
is interesting here because where there's one cache per-user the
environment variable thing makes no sense at all.
</font></pre>
</blockquote>
There is one cache associated with the LSA session.<br>
A process or thread can create a new cache which is not <br>
associated with the session.&nbsp; However, it would be <br>
inappropriate to use an environment variable in this case.&nbsp; <br>
<font face="Bitstream Cyberbit"><br>
Within the context of a logon session a krb5_ccache name is unique.<br>
There is no guarantee that the krb5_ccache name will be unique across<br>
the entire system.&nbsp;&nbsp; Using an environment variable would certainly<br>
fail in any situation in which you either had a single process (a
multi-threaded<br>
server) in which each thread must maintain its own cache reference<br>
or where the processes exist in different logon session spaces.&nbsp; For
example<br>
a user process communicating with a daemon process. <br>
<br>
Jeffrey Altman<br>
<br>
</font>
</body>
</html>

--------------020708030003050406070506--
-++**==--++**==--++**==--++**==--++**==--++**==--++**==
This message was posted through the Stanford campus mailing list
server.  If you wish to unsubscribe from this mailing list, send the
message body of "unsubscribe ietf-cat-wg" to [email protected]