[27668] in Kerberos

home help back first fref pref prev next nref lref last post

Re: GSS-API routine for renewing credentials

daemon@ATHENA.MIT.EDU (Nicolas Williams)
Wed Apr 18 16:25:07 2007

Date: Wed, 18 Apr 2007 15:23:46 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: Robert <rob_krb@xs4all.nl>
Message-ID: <20070418202346.GM4375@Sun.COM>
Mail-Followup-To: Robert <rob_krb@xs4all.nl>, kerberos@mit.edu
Mime-Version: 1.0
Content-Disposition: inline
In-Reply-To: <000e01c781e6$f7604090$8ff5fea9@rapido>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

On Wed, Apr 18, 2007 at 08:25:39PM +0200, Robert wrote:
> Does anyone know whether there is a routine in GSS-API to renew (forwarded)
> client credentials? I'm unable to locate such a routine in GSS-API, but 
> maybe
> I'm overlooking it.

There's no such thing.

In SSHv2 we deal with this by re-keying the SSHv2 session and, in the
process, establishing a new GSS-API security context, which is an
opportunity to delegate a new credential.

I.e., you have to establish a new security context.

Nico
-- 
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post