[25194] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Common keytab file for all the application servers - Is

daemon@ATHENA.MIT.EDU (Nikhil Mulley)
Tue Jan 3 02:44:07 2006

Message-ID: <1e7c46190601022343r30d50832o1822e14e40d8d99@mail.gmail.com>
Date: Tue, 3 Jan 2006 13:13:21 +0530
From: Nikhil Mulley <mnikhil@gmail.com>
To: Viswa <viswanatha.shankaranarayana@gmail.com>
In-Reply-To: <1136265868.149009.203000@z14g2000cwz.googlegroups.com>
MIME-Version: 1.0
Content-Disposition: inline
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

On 2 Jan 2006 21:24:28 -0800, Viswa <viswanatha.shankaranarayana@gmail.com>
wrote:
>
> I have a proposal. Let me know if this is a good idea to go about!
>
> 1. Generate seperate keytab file for each target.
> 2. Merge the keytabs into a common keytab file.
> 3. While configuring the target make sure they will use only the part
> of the keytab ment for them.
>
> This way the security is also not compromised.
>
> Group,
> Are there any other similar approaches?
>
> Regards
> Viswa
>

I mean.. I had similar thoughts on this..  earlier, but not sure how would
one implement the same.
I mean I do not understand by Merging - in the sense, how would they be
merged and what would be the priority of the keytabs in the merged keytab
file, how would one can use the part of the keytabs in the merged copy ?

Regards..
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post