ccache using linux Keyrings

Wachdorf, Daniel R drwachd at sandia.gov
Wed Apr 12 15:11:15 EDT 2006


I think there might be a little bit different idea that works just as
well.  Have the ability to specify the active cache on a
thread/process/session level (keyring), then leave all the credentials
in the session keyring.  This would make the requirements:

* Ability to specify, in different keyrings, which cache is used.
* Ability to specify full name of the cache
* Ability to search from most specific to least specific.
* All this needs to fit into the ccache name


-----Original Message-----
From: Sam Hartman [mailto:hartmans at mit.edu] 
Sent: Wednesday, April 12, 2006 12:00 PM
To: Wachdorf, Daniel R
Cc: Kevin Coffman; Andy Adamson; Machin, Glenn D; krbdev at mit.edu
Subject: Re: ccache using linux Keyrings

>>>>> "Wachdorf," == Wachdorf, Daniel R <drwachd at sandia.gov> writes:

    Wachdorf,> It might be desirable that an application (or the
    Wachdorf,> kernel) which did not have access to the ENV search the
    Wachdorf,> keyrings in order of presence (thread
    -> session) (ie GSSD).  If I went through the trouble of creating
    -> a
    Wachdorf,> thread specific keyring - I want that one used.


Yes.
Agreed.

OK, so requirements are:

* Ability to specify which keyring a new ccache gets created in
* Ability to specify full name of the cache
* Ability to search from most specific to least specific
* All this needs to fit into the ccache name

--Sam






More information about the krbdev mailing list