[Bug 2775] Improve kerberos credential forwarding support

bugzilla-daemon at bugzilla.mindrot.org bugzilla-daemon at bugzilla.mindrot.org
Thu Nov 8 02:02:43 AEDT 2018


https://bugzilla.mindrot.org/show_bug.cgi?id=2775

--- Comment #13 from Charles Hedrick <hedrick at rutgers.edu> ---
I think you're going to find that the sssd team is stuck. They're
implementing an existing API from Heimdal. The MIT implementation of
KCM is based on Heimdal's spec. The MIT libraries are designed so you
can use an MIT-based application on a system where Heimdal is the
primary version of Kerberos. An example would be a Mac, where we want
to be able to use Macports applications based on MIT Kerberos, but the
system (including the service that supports KCM) is based on Heimdal.

I agree with your opinion of the design, but I think the sssd team is
stuck. I don't think they can make the change you propose.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.


More information about the openssh-bugs mailing list