need project review
Nicolas.Williams at sun.com
Fri Apr 4 16:18:57 EDT 2008
On Fri, Apr 04, 2008 at 03:00:41PM -0500, Nicolas Williams wrote:
> IMO we should deprecate stash files altogether. That should make this
> issue go away -- what's the point of having a stash file if nothing will
> read it?
I should clarify. I think that the only thing that reads stash files
should be the tool that migrates them to keytab file entries. That
could be built-in to krb5kdc and kadmind, or it could be a standalone
tool. Either way the stash file should be read once, migrated, and
removed or ignored thereafter.
More information about the krbdev