[Kdc-info] prelim draft of kdc information model

Sam Hartman hartmans at MIT.EDU
Mon Jul 14 04:03:35 EDT 2003


Two things that seem to be missing from this model are:

1) The information describing how principals are created.  This is a
   deficiency in current admin servers.  I probably want to be able to
   specify that a principal belongs to some principal type like user
   or -service when it is created and have that influence what is
   created for the principal.  For users I probably want to disallow
   use of the long-term key as a service.  At the current time, I
   might want to use AES for user principals but not for service
   principals.

2) Don't I want to be able to configure the enctypes and salttypes
    that future password changes will use per principal as well?

Both these points can probably be solved using the same mechanism.



More information about the kdc-info mailing list