gss_acquire_cred with GSS_C_BOTH usage option

Sam Hartman hartmans at MIT.EDU
Tue Oct 4 17:14:48 EDT 2005

>>>>> "Moore," == Moore, Patrick <pcmoore at> writes:

    Moore,> My reading of RFC1964, where it says . . .

    Moore,>    "However, when the Kerberos 5 mechanism attempts to
    Moore,> obtain initiating credentials for a service principal
    Moore,> which are not available in a credentials cache, and the
    Moore,> key for that service principal is available in a Kerberos
    Moore,> 5 key table, the mechanism should use the service key to
    Moore,> obtain initiating credentials for that service."

    Moore,> ... implies that Heimdal has the right approach.

You're completely right.  Would you mind opening a bug by describing
the problem in mail to krb5-bugs at  Please include a RFC 1964


