Patch for Simons openssh gssapi patch for multihomed systems

Sam Hartman hartmans at MIT.EDU
Wed Sep 24 15:23:20 EDT 2003


>>>>> "Jacques" == Jacques A Vidrine <nectar at celabo.org> writes:

    Jacques> On Tue, Sep 23, 2003 at 07:31:49PM +0100, Markus Moeller wrote:
    >> Here is a patch on top of Simons gssapi patch for openssh 3.6.1p2 to
    >> support multihomed systems.

    Jacques> A simpler approach is to pass GSS_C_NO_NAME to gss_acquire_cred.  This
    Jacques> will allow any name present in the keytab.

Yes, and I'd like to see that as a configurable option.  That would
even be a reasonable default if you gss_display_name the name and make
sure it starts with host.



More information about the Kerberos mailing list