[14668] in Kerberos
Re: using Kerberos V5 with network address translation firewall?
daemon@ATHENA.MIT.EDU (Johan Danielsson)
Fri Jul 13 06:07:19 2001
To: jaltman@watsun.cc.columbia.edu (Jeffrey Altman)
Cc: kerberos@mit.edu
From: joda@pdc.kth.se (Johan Danielsson)
Date: 13 Jul 2001 12:01:12 +0200
In-Reply-To: jaltman@watsun.cc.columbia.edu's message of "12 Jul 2001 09:25:09 GMT"
Message-ID: <xof1ynl87x3.fsf@blubb.pdc.kth.se>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
jaltman@watsun.cc.columbia.edu (Jeffrey Altman) writes:
> If you can describe a good way to write the rule that says, replace
> address FOO with address NAT we can certainly make the change in the code.
> The problem in most cases is that there is no good way to know what
> the NAT address is in the first place.
I sometimes long for a "dear prof. kdc, please give me my correct
address, since I have no clue" option to the kdc, much like it worked
in v4.
/Johan