Bug#626509: libpam-krb5: Automatically create FAST armor cache by using anonymous user

2011-05-16 Thread Russ Allbery
Sam Hartman writes: > I don't have time to review the patch but I can talk about anonymous and > fast. [...] Thanks for the information, Sam! Given this, I'll queue this up to look at in pam-krb5. Yair, it may be a little bit before you see progress on this because pam-krb5 is nearly the last

Bug#626509: libpam-krb5: Automatically create FAST armor cache by using anonymous user

2011-05-12 Thread Sam Hartman
I don't have time to review the patch but I can talk about anonymous and fast. Remember that for 1.9, anonymous requires you have a trust anchor and can verify the KDC's certificate. RFc 6112 does talk about a mode where neither side has a key, but that's not implemented yet and will require expl

Bug#626509: libpam-krb5: Automatically create FAST armor cache by using anonymous user

2011-05-12 Thread Russ Allbery
Yair Yarom writes: > When using FAST a ticket cache should be available beforehand. On some > situations there is no such cache or it is not readable. > Is it possible to add an option to automatically create this ticket > cache by using the anonymous user? i.e. like calling 'kinit -n' before >

Bug#626509: libpam-krb5: Automatically create FAST armor cache by using anonymous user

2011-05-12 Thread Yair Yarom
Package: libpam-krb5 Version: 4.4-1 Severity: wishlist Tags: upstream patch When using FAST a ticket cache should be available beforehand. On some situations there is no such cache or it is not readable. Is it possible to add an option to automatically create this ticket cache by using the anon