[28697] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Solaris 10 sshd + GSSAPI = where's my cred cache?

daemon@ATHENA.MIT.EDU (Danny Mayer)
Thu Nov 8 23:07:22 2007

Message-ID: <4733DC3B.5090105@ntp.isc.org>
Date: Thu, 08 Nov 2007 23:04:11 -0500
From: Danny Mayer <mayer@ntp.isc.org>
MIME-Version: 1.0
To: Jeff Blaine <jblaine@kickflop.net>, kerberos@mit.edu
In-Reply-To: <20071105210141.GJ11498@Sun.COM>
X-kostecke.net-MailScanner-From: mayer@ntp.isc.org
Reply-To: mayer@ntp.isc.org
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Nicolas Williams wrote:
> On Mon, Nov 05, 2007 at 12:06:14PM -0500, Jeff Blaine wrote:
>> Solved.
>>
>> Had to force client-side "-o GSSAPIStoreDelegatedCredentials yes"
>> even though it was not defined anywhere as "no" (although probably
>> a default for some reason).
> 
> The manpage (ssh_config(4)) says:
> 
>      GSSAPIDelegateCredentials
> 
>          Enables/disables  GSS-API  credential  forwarding.   The
>          default is no.
>          ^^^^^^^^^^^^^
That makes no sense. The default is no? The default should be "Enabled"
or "Disabled". "No" has no meaning here.

Danny
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post