GSSAPI s4u2proxy with client keytab initiation and Heimdal KDC

Alan Braggins alan.braggins at riverbed.com
Thu Dec 5 12:12:41 EST 2013


On 05/12/13 12:33, Alan Braggins wrote:
> I want to use 1.11, because I want to use client keytab initiation.

And a followup question on client keytab initiation - it appears that
if I have no cached credential, then it works. But if I have a cached
credential that has expired, then gss_acquire_cred is returning me an
expired credential, not renewing it. This seems to contradict
http://web.mit.edu/kerberos/krb5-current/doc/appdev/gssapi.html and
http://k5wiki.kerberos.org/wiki/Projects/Keytab_initiation



More information about the Kerberos mailing list