AFS and Kerberos 5

Russ Allbery rra at stanford.edu
Tue Jul 22 18:44:10 EDT 2003


Sam Hartman <hartmans at mit.edu> writes:
>>>>>> "MattW" == MattW  <mbw at u.washington.edu> writes:

>     MattW> Can I leave my Kerberos 5 KDC in pure Kerb 5 mode or do I
>     MattW> have to run some kind of Kerb 5-to-4 daemon to issue kerb 4
>     MattW> tickets to the AFS server - I'd like to be pure kerb 5 if
>     MattW> possible.

> You could in theory use a special aklog, but you are probably better
> off running a krb524d.

Out of curiosity, why would you say that?  The native Kerberos v5 support
in OpenAFS looks a lot nicer and means that there's no Kerberos v4
exposure at all.

-- 
Russ Allbery (rra at stanford.edu)             <http://www.eyrie.org/~eagle/>


More information about the Kerberos mailing list