[20116] in Kerberos_V5_Development
Re: Alternative proxy-creds API for constrained-delegation
daemon@ATHENA.MIT.EDU (Isaac Boukris)
Wed Jun 3 13:16:05 2020
MIME-Version: 1.0
In-Reply-To: <20200603160058.GY7856@localhost>
From: Isaac Boukris <iboukris@gmail.com>
Date: Wed, 3 Jun 2020 19:15:23 +0200
Message-ID: <CAC-fF8RXgwjj2SSQRA0pshV88KnTiF+-=ZhH8fJ73SyUgnUU3A@mail.gmail.com>
To: Nico Williams <nico@cryptonector.com>
Cc: Simo Sorce <simo@redhat.com>, "krbdev@mit.edu Dev List" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On Wed, Jun 3, 2020 at 6:01 PM Nico Williams <nico@cryptonector.com> wrote:
>
> On Wed, Jun 03, 2020 at 04:11:08PM +0200, Isaac Boukris wrote:
> > To me, gss-proxy sounds like a big requirement, I was hoping for a
> > simpler plugable client helper mechanism, that simply talks to a
> > daemon when needed and puts the ticket in cache for the client to use.
>
> That's still a proxy. We talked about this on the call. Love had
> wanted all of these proxies back in 2012, and I agree with that:
>
> - krb5_get_credentials() proxy
>
> - krb5_mk/rd_req*() proxy
>
> - gss proxy
>
> All of these can be in the same or different programs -- it doesn't
> matter much.
Proxy is fine, as long as we define its requirements for *this* feature.
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev