Re: [OT] Re: GGF's extensions to GSS in Public Comment
Jeffrey Altman <[email protected]> Tue, 06 Apr 2004 01:19:08 -0400
| Newsgroups | gmane.ietf.cat |
|---|---|
| Organization | No Longer Affiliated with Columbia University in the City of New York |
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --------------020708030003050406070506 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Nicolas Williams wrote: >[Off topic] > >On Mon, Apr 05, 2004 at 10:12:03PM -0400, Jeffrey Altman wrote: > >>Nicolas Williams wrote: >> >> >>>(Doesn't the new Kfw MLSA ccache type pretty much mean that Kfw has a >>>single credential store peruser on Windows? Yes, it can still use >>>KRB5CCNAME for other ccache types, but those aren't shared with the >>>LSA...) >>> >>> >>MIT krb5_ccache API provides access to multiple >>ccache types. These include "FILE:", "API:", >>"MEMORY:", and "MSLSA:" at the current time. >>On Windows and Macintosh, the default krb5_ccache type >>is "API:" (aka CCAPI). The "MSLSA:" krb5_ccache type >>provides shared access to the LSA cache allowing the >>same credentials to be used by both MIT Krb5 API clients >>and Kerberos SSP clients. >> > >This was my understanding. Is there only one LSA cache per-user? This >is interesting here because where there's one cache per-user the >environment variable thing makes no sense at all. > There is one cache associated with the LSA session. A process or thread can create a new cache which is not associated with the session. However, it would be inappropriate to use an environment variable in this case. Within the context of a logon session a krb5_ccache name is unique. There is no guarantee that the krb5_ccache name will be unique across the entire system. Using an environment variable would certainly fail in any situation in which you either had a single process (a multi-threaded server) in which each thread must maintain its own cache reference or where the processes exist in different logon session spaces. For example a user process communicating with a daemon process. Jeffrey Altman --------------020708030003050406070506 Content-Type: text/html; charset=us-ascii Content-Transfer-Encoding: 7bit <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type"> <title></title> </head> <body bgcolor="#ffffff" text="#000000"> <font face="Bitstream Cyberbit">Nicolas Williams wrote:</font> <blockquote cite="[email protected]" type="cite"> <pre wrap=""><font face="Bitstream Cyberbit">[Off topic] On Mon, Apr 05, 2004 at 10:12:03PM -0400, Jeffrey Altman wrote: </font></pre> <blockquote type="cite"> <pre wrap=""><font face="Bitstream Cyberbit">Nicolas Williams wrote: </font></pre> <blockquote type="cite"> <pre wrap=""><font face="Bitstream Cyberbit">(Doesn't the new Kfw MLSA ccache type pretty much mean that Kfw has a single credential store peruser on Windows? Yes, it can still use KRB5CCNAME for other ccache types, but those aren't shared with the LSA...) </font></pre> </blockquote> <pre wrap=""><font face="Bitstream Cyberbit">MIT krb5_ccache API provides access to multiple ccache types. These include "FILE:", "API:", "MEMORY:", and "MSLSA:" at the current time. On Windows and Macintosh, the default krb5_ccache type is "API:" (aka CCAPI). The "MSLSA:" krb5_ccache type provides shared access to the LSA cache allowing the same credentials to be used by both MIT Krb5 API clients and Kerberos SSP clients. </font></pre> </blockquote> <pre wrap=""><!----><font face="Bitstream Cyberbit"> This was my understanding. Is there only one LSA cache per-user? This is interesting here because where there's one cache per-user the environment variable thing makes no sense at all. </font></pre> </blockquote> There is one cache associated with the LSA session.<br> A process or thread can create a new cache which is not <br> associated with the session. However, it would be <br> inappropriate to use an environment variable in this case. <br> <font face="Bitstream Cyberbit"><br> Within the context of a logon session a krb5_ccache name is unique.<br> There is no guarantee that the krb5_ccache name will be unique across<br> the entire system. Using an environment variable would certainly<br> fail in any situation in which you either had a single process (a multi-threaded<br> server) in which each thread must maintain its own cache reference<br> or where the processes exist in different logon session spaces. For example<br> a user process communicating with a daemon process. <br> <br> Jeffrey Altman<br> <br> </font> </body> </html> --------------020708030003050406070506-- -++**==--++**==--++**==--++**==--++**==--++**==--++**== This message was posted through the Stanford campus mailing list server. If you wish to unsubscribe from this mailing list, send the message body of "unsubscribe ietf-cat-wg" to [email protected]