[krbdev.mit.edu #7190] Try harder to make keytab-based AS requests work

Greg Hudson via RT rt-comment at krbdev.mit.edu
Mon Jul 2 12:52:09 EDT 2012


Nico also suggests making gic_keytab use encrypted timestamp preauth 
(http://mailman.mit.edu/pipermail/krbdev/2012-July/010999.html), and 
making the KDC use the encrypted timestamp key as the reply key.  These 
are both reasonable ideas, but the former may have some edge cases.


More information about the krb5-bugs mailing list